Entra Security Administrator: Review role by end of September

Microsoft is expanding the built-in Security Administrator role in Microsoft Entra. In the September edition of the Entra blog, Microsoft announced additional response actions for non-privileged users: disabling and enabling accounts, revoking active sessions, and forcing password resets. The rollout is expected to be completed by the end of September 2026. For smaller IT teams, that can shorten response times during an identity incident. At the same time, an existing role assignment becomes more powerful and should be reviewed before the rollout reaches the tenant.

What Microsoft is changing by the end of September

Microsoft describes the update as an enhancement to the built-in Security Administrator role. The Microsoft Learn role reference already identifies this role as privileged and lists security tasks across several Microsoft portals. The new point in the Entra blog is that identity response actions for non-privileged users are being added to the role.

  • Security Administrators can disable and re-enable non-privileged user accounts.
  • They can revoke active sessions so affected users must sign in again.
  • They can force password resets when that is required for response.
  • Microsoft states that the rollout will be completed by the end of September 2026.

Why this matters for SMB environments

In organizations with 10 to 250 seats, administrative roles often sit with a small IT team or an external service provider, not with a separate identity operations group. A change to a built-in role therefore has immediate operational impact: anyone who already holds Security Administrator may receive additional user response capabilities after the rollout. That can help in an incident, but it should match the organization’s access model. This is especially important where the role is assigned permanently instead of being activated only when needed through Privileged Identity Management.

Tenants are affected when the Security Administrator role is assigned. Permanent assignments, shared administration models, and service provider access deserve the closest review. A tenant is practically unaffected only if nobody uses this role.

Existing permissions still matter

The Microsoft Learn reference describes Security Administrator as a role for security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and the Microsoft Purview portal. It includes areas such as security policies, threats and alerts, reports, endpoint roles and machine groups, and cross-tenant access settings. The September update is therefore not being added to a read-only role; it extends a role that Microsoft already treats as privileged.

That distinction is important for anyone running Microsoft Entra ID. The role name sounds focused, but according to Microsoft it spans several portals and security-sensitive settings. The new identity response actions make that privilege profile more visible.

Deadline: review before the rollout completes

Microsoft does not give a single switch-over day. Instead, it says the rollout will be completed by the end of September 2026. That makes September the right window for review, not the time to wait for a later cleanup. The goal is not to remove the role by default. The goal is to know who has it, why they need it, and whether the assignment should be permanent or activated only when required.

One boundary matters: Microsoft says the new response actions apply to non-privileged users. This does not replace clear separation for Global Administrator, Privileged Role Administrator, and other highly privileged functions. For day-to-day security operations, however, it can determine whether a compromised standard account is blocked immediately or whether another administrator must first take over.

Concrete next steps

  • Export the current Security Administrator assignments and document owner, purpose, and assignment duration.
  • Check whether permanent assignments can be limited to justified individuals or moved to just-in-time activation.
  • Align the incident response procedure: disable the account, revoke sessions, reset the password, then document the action.
  • After Microsoft completes the rollout, review audit logs and role assignments again so unintended expansion is not missed.

As part of a Microsoft Security Assessment, this review can be combined with Conditional Access, MFA methods, and administrator role design. If related controls in Microsoft Defender or Purview are affected, the role review belongs in the same action plan.

Official Microsoft sources

If you want to clarify which administrator roles your tenant really needs before the rollout is completed, we can support that in a short introductory call.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment