Information
You should review non-global administrator role group assignments at least every week.
Rationale:
While these roles are less powerful than a global admin, they do grant special privileges that can be used illicitly. If you see something unusual, contact the user to confirm it is a legitimate need.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To review non-global administrator role group assignments, use the Microsoft 365 Admin Center:
Go to Compliance.
Select Audit under Solutions.
Set Start Date and End Date (probably default).
Click on pull-down under Activities; enter Added member to Role in search box; checkassociated box; erase search box and enter 'Removed a user from a directory role'; and check associated box.
Click Search.
Review.