Forum Discussion
Expected exactly one role management policy assignment but 0 were found
Title: Experiencing the same PIM policy error with a custom LAPS role
Hi everyone,
I am running into this exact same backend sync issue in our tenant and wanted to share our scenario in case it helps pinpoint the trigger.
Our Scenario:
- Goal: We are deploying Windows LAPS and created a custom Entra ID role (named "LAPS Password Viewer") specifically so our local IT can view LAPS passwords.
- Permission: The role contains only one permission: microsoft.directory/deviceLocalCredentials/password/read
- Environment: M365 E5 tenant (PIM is active).
- The Issue: When trying to assign this new custom role to a test user, we immediately hit the "Expected exactly one role management policy assignment but 0 were found" error.
- Troubleshooting: We tried assigning the role directly through Identity > Roles & admins to bypass the main PIM interface, but the PIM engine still intercepts it and throws the exact same policy error. We also tried forcing a backend sync, but the hidden PIM policy for this custom role refuses to generate.
Has anyone found a reliable way to force PIM to generate the missing policy for newly created custom roles, or does this strictly require a Microsoft Support ticket to fix on the backend?