In the Azure Portal, navigate back to the Azure AD Privileged Identity Management blade and click Azure AD roles.
On the AdatumLab500-04 | Quick start blade, in the Manage section, click Roles.
On the AdatumLab500-04 | Roles blade, click the Global reader role entry.
On the Global Reader | Assignments blade, click Settings icon in the toolbar of the blade and review configuration settings for the role, including Azure Multi-Factor Authentication requirements.
Click Edit.
On the Activation tab, enable the Require approval to activate check box.
Click Select approvers(s), on the Select a member blade, click aaduser3, and then click Select.
Click Next:Assignment.
Clear the Allow permanent eligible assignment check box, leaving all other settings with their default values.
Click Next:Notification.
On the Edit role setting - Global Reader blade, review the settings and click Update.
Note: Anyone trying to use the Global Reader role will now need approval from aaduser3.
On the Global Reader | Assignments blade, click + Add assignments.
On the Add assignments blade, click No member selected, on the Select a member blade, click aaduser2, and then click Select.
Click Next.
Ensure the Assignment type is Eligible and review the eligible duration settings.
Click Assign.
Note: User aaduser2 is eligible for the Global Reader role.