The ARS Web Interface reports group membership add/remove operations as successful in conditions where the underlying Microsoft Graph call has either been rejected (e.g. Authorization_RequestDenied) or merely not yet visible due to Microsoft Entra ID's eventual-consistency model. The administrator is misled into believing a privileged change has been applied when it has not.
The behavior is currently constrained by the underlying product and Microsoft Graph architecture, which limits possible immediate mitigation options.
STATUS
Enhancement Request 706632 has been submitted to Development for consideration in a future release of Active Roles.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center