Management Role Error – User Not Assigned Roles

Modified on Mon, 14 Apr at 12:18 AM

Error: The user isn't assigned to any management roles

This error means the delegated admin account does not have the required directory roles assigned within the customer tenant — typically via the GDAP security group.


Cause: The delegated admin account is either not part of the GDAP group, or the GDAP group is missing required roles like Global Reader or Application Administrator.

Resolution

To resolve this, validate and update the GDAP permissions for the affected tenant:

  1. Go to your partner tenant’s Microsoft Partner Center
  2. Open the customer’s GDAP configuration
  3. Ensure that:
    • The correct security group is linked to the GDAP relationship
    • The group includes your delegated admin account
    • The group has at least:
      • Application Administrator
      • Global Reader

Refer to the full guide: Checking your GDAP relationship

After updating, allow up to 30 minutes for permissions to propagate.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article