On September 11, 2026, three separately authenticated users exercised these operations through delegated Microsoft Graph v1.0 using the same temporary client application. Each token identified the intended actor, carried the same delegated scopes, and declared the expected test role plus the default directory-user role. A later active-assignment snapshot showed one expected direct role per operator. The initial directory-role eligibility read failed (403); a later read-only audit resolved that coverage gap and returned zero directory-role eligibility instances. PIM eligibility for group membership or ownership remains outside coverage.
| Target and operation | Security Administrator | Entra SOC Identity Responder | Security Operator |
|---|---|---|---|
| Ordinary user: disable | State change verified | State change verified | State change verified |
| Ordinary user: enable | State change verified | State change verified | State change verified |
| Ordinary user: revoke sessions | API accepted; timestamp advanced | API accepted; timestamp advanced | API accepted; timestamp advanced |
| Ordinary user: reset password | API accepted; audit success | API accepted; audit success | API accepted; audit success |
| Global Reader: disable | Denied (403) | Denied (403) | Denied (403) |
| Global Reader: enable from disabled | Denied (403) | Effect unverified (204) | Denied (403) |
| Global Reader: revoke sessions | Denied (403) | Denied (403) | Denied (403) |
| Global Reader: reset password | Denied (403) | Denied (403) | Denied (403) |
βAPI acceptedβ is deliberately narrower than an end-to-end outcome. Revocation returned HTTP 200 with true, and the session-valid-from timestamp advanced. No active browser session or refresh-token rejection was tested. Password resets returned HTTP 204 and had successful password-reset audit records; nobody signed in using the new passwords.
Why the Global Reader enable result stays unresolved
An initial enable request returned 204 for all three roles while the target was already enabled. Those no-op responses are not authority evidence.
The follow-up started with the disposable Global Reader account disabled. Security Administrator and Security Operator received 403. SOC Identity Responder received 204, but the account remained disabled. A repeat established three disabled-state precondition reads, then eleven subsequent reads that all remained false over 21.483 seconds from first to last observation. The provisioning administrator restored the account after that observation window. This does not establish a role-boundary bypass or a successful enable operation.
Independent audit attribution
The final audit snapshot was collected at 23:43:48 UTC and contained 85 fixture-related records. None of the audit correlationId values matched the recorded client or service request IDs. Corroboration therefore uses the initiating user, target user, and recorded operation time window; it is not exact request-ID correlation.
All three operators’ ordinary-user disable, enable, revocation, and reset requests had corresponding successful actor/target/time-matched audit events in the final snapshot. Security Operator’s successful Enable account event at 23:38:17.4640339 UTC records false to true, corroborating the earlier state reads.
The earlier 23:39:59 UTC, 75-record snapshot did not yet contain that Security Operator enable event; the final snapshot did. The earlier absence was a snapshot limitation, not evidence that the observed state change failed.
For the longer SOC Identity Responder follow-up, the audit records show the provisioning administrator disabled the Global Reader target at 23:36:55.3338545 UTC and enabled it at 23:37:20.2595818 UTC. The eleven false-state observations occurred between 23:36:58.4657037 and 23:37:19.9491599 UTC. No SOC-attributed event for that target appeared in either follow-up window. Audit ingestion can lag, so a follow-up query of the directory audit log on September 12, 2026 at 14:45 UTC, about fifteen hours later, rechecked the same window: it returned every record from the final snapshot plus the later cleanup events, and still no SOC Identity Responder event for the Global Reader target.
Scope of the conclusion
These observations support a comparison of three roles against an ordinary user and a Global Reader administrator in this tenant. They do not establish behavior for all privileged roles, every tenant, or the Defender portal. Assignment and eligibility results are point-in-time observations, not a complete historical privilege inventory.
The later read-only audit, with run timestamp September 12, 2026 at 00:07:46 UTC (September 11 locally), completed all eight Graph collection scans and all five principal checks. It returned zero directory-role eligibility instances; the five principals’ transitive active-role, group-membership, user-state, and directory-eligibility checks completed. Only the administrative reader received additional read permissions; the operator action scopes were unchanged. This does not extend coverage to PIM eligibility for group membership or ownership.
No passwords, TAPs, access tokens, user names, tenant IDs, app IDs, target IDs, or request identifiers are included here. The companion JSON preserves sanitized observations, evidence limits, source filenames, and source-file checksums.
