> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/admin-role-assigned-to-user.md).

# Admin Role Assigned to User

Detects when a user is assigned an administrator role. It can indicate malicious activity and elevated privileges if this is not legitimate.

**Recommended Actions**

Ensure this assignment was legitimate. If the target should not be an administrator or should not be assigned that role, please start an investigation and create a ticket.

**Compatibility**

[Duo](/integrations/duo-security-integration.md)

[Okta](/integrations/okta-data-integration.md)

[GitHub](/integrations/github.md)

[Microsoft EntraID](/integrations/azure-active-directory-integration.md)

<figure><img src="/files/VP1dkZ8kQoEhfxdMq73z" alt=""><figcaption></figcaption></figure>

<br>
