> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/admin-role-assigned-to-user.md).

# Admin Role Assigned to User

Detects when a user is assigned an administrator role. It can indicate malicious activity and elevated privileges if this is not legitimate.

**Recommended Actions**

Ensure this assignment was legitimate. If the target should not be an administrator or should not be assigned that role, please start an investigation and create a ticket.

**Compatibility**

[Duo](/integrations/duo-security-integration.md)

[Okta](/integrations/okta-data-integration.md)

[GitHub](/integrations/github.md)

[Microsoft EntraID](/integrations/azure-active-directory-integration.md)

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FuGgLXoh3otIAM7iMQZW0%2FAdmin%20Role%20Assigned%20to%20User.png?alt=media&amp;token=97659960-43fc-4b0a-af6f-be40007be9c2" alt=""><figcaption></figcaption></figure>

<br>
