Edit

Microsoft Entra built-in roles

In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.

This article lists the Microsoft Entra built-in roles you can assign to allow management of Microsoft Entra resources. For information about how to assign roles, see Assign Microsoft Entra roles. If you are looking for roles to manage Azure resources, see Azure built-in roles.

This article lists the permissions used by built-in roles. Only a subset of these permissions is currently available for use in custom roles. For more information about creating a custom role, see Create a custom role in Microsoft Entra ID.

All roles

Role Description Template ID
Agent ID Administrator Manage all aspects of agents in a tenant including identity lifecycle operations for agent blueprints, agent identity blueprint principals, agent identities, and agentic users.
Privileged label icon.
db506228-d27e-4b7d-95e5-295956d6615f
Agent ID Developer Create an agent identity blueprint and its agent identity blueprint principal in a tenant. User will be added as an owner of the created agent identity blueprint and its agent identity blueprint principal. adb2368d-a9be-41b5-8667-d96778e081b0
Agent Registry Administrator Manage all aspects of the Agent Registry service in Microsoft Entra ID 6b942400-691f-4bf0-9d12-d8a254a2baf5
AI Administrator Manage all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365.
Privileged label icon.
d2562ede-74db-457e-a7b6-544e236ebb61
AI Reader Read all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365.
Privileged label icon.
1fe13547-53f6-408d-ac04-7f8eed167b38
Application Administrator Can create and manage all aspects of app registrations and enterprise apps.
Privileged label icon.
9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3
Application Developer Can create application registrations independent of the 'Users can register applications' setting.
Privileged label icon.
cf1c38e5-3621-4004-a7cb-879624dced7c
Attack Payload Author Can create attack payloads that an administrator can initiate later. 9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f
Attack Simulation Administrator Can create and manage all aspects of attack simulation campaigns. c430b396-e693-46cc-96f3-db01bf8bb62a
Attribute Assignment Administrator Assign custom security attribute keys and values to supported Microsoft Entra objects. 58a13ea3-c632-46ae-9ee0-9c0d43cd7f3d
Attribute Assignment Reader Read custom security attribute keys and values for supported Microsoft Entra objects. ffd52fa5-98dc-465c-991d-fc073eb59f8f
Attribute Definition Administrator Define and manage the definition of custom security attributes. 8424c6f0-a189-499e-bbd0-26c1753c96d4
Attribute Definition Reader Read the definition of custom security attributes. 1d336d2c-4ae8-42ef-9711-b3604ce3fc2c
Attribute Log Administrator Read audit logs and configure diagnostic settings for events related to custom security attributes. 5b784334-f94b-471a-a387-e7219fc49ca2
Attribute Log Reader Read audit logs related to custom security attributes. 9c99539d-8186-4804-835f-fd51ef9e2dcd
Attribute Provisioning Administrator Read and edit the provisioning configuration of all active custom security attributes for an application.
Privileged label icon.
ecb2c6bf-0ab6-418e-bd87-7986f8d63bbe
Attribute Provisioning Reader Read the provisioning configuration of all active custom security attributes for an application.
Privileged label icon.
422218e4-db15-4ef9-bbe0-8afb41546d79
Authentication Administrator Can access to view, set and reset authentication method information for any non-admin user.
Privileged label icon.
c4e39bd9-1100-46d3-8c65-fb160da0071f
Authentication Extensibility Administrator Customize sign in and sign up experiences for users by creating and managing custom authentication extensions.
Privileged label icon.
25a516ed-2fa0-40ea-a2d0-12923a21473a
Authentication Extensibility Password Administrator Trigger a password submit event for custom authentication.
Privileged label icon.
0b00bede-4072-4d22-b441-e7df02a1ef63
Authentication Policy Administrator Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials. 0526716b-113d-4c15-b2c8-68e3c22b9f80
Azure DevOps Administrator Manage Azure DevOps policies and settings. e3973bdf-4987-49ae-837a-ba8e231c7286
Azure Information Protection Administrator Can manage all aspects of the Azure Information Protection product. 7495fdc4-34c4-4d15-a289-98788ce399fd
B2C IEF Keyset Administrator Can manage secrets for federation and encryption in the Identity Experience Framework (IEF).
Privileged label icon.
aaf43236-0c0d-4d5f-883a-6955382ac081
B2C IEF Policy Administrator Can create and manage trust framework policies in the Identity Experience Framework (IEF). 3edaf663-341e-4475-9f94-5c398ef6c070
Billing Administrator Can perform common billing related tasks like updating payment information. b0f54661-2d74-4c50-afa3-1ec803f12efe
Cloud App Security Administrator Manage all aspects of the Defender for Cloud Apps product. 892c5842-a9a6-463a-8041-72aa08ca3cf6
Cloud Application Administrator Can create and manage all aspects of app registrations and enterprise apps except App Proxy.
Privileged label icon.
158c047a-c907-4556-b7ef-446551a6b5f7
Cloud Device Administrator Limited access to manage devices in Microsoft Entra ID.
Privileged label icon.
7698a772-787b-4ac8-901f-60d6b08affd2
Compliance Administrator Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. 17315797-102d-40b4-93e0-432062caca18
Compliance Data Administrator Creates and manages compliance content. e6d1a23a-da11-4be4-9570-befc86d067a7
Conditional Access Administrator Can manage Conditional Access capabilities.
Privileged label icon.
b1be1c3e-b65d-4f19-8427-f6fa0d97feb9
Customer Delegated Admin Relationship Administrator Manage all aspects of granular delegated admin privileges (GDAP) relationships in a customer tenant. fc8ad4e2-40e4-4724-8317-bcda7503ecbf
Customer Lockbox Access Approver Can approve Microsoft support requests to access customer organizational data. 5c4f9dcd-47dc-4cf7-8c9a-9e4207cbfc91
Desktop Analytics Administrator Can access and manage Desktop management tools and services. 38a96431-2bdf-4b4c-8b6e-5d3d8abac1a4
Directory Readers Can read basic directory information. Commonly used to grant directory read access to applications and guests. 88d8e3e3-8f55-4a1e-953a-9b9898b8876b
Directory Synchronization Accounts Only used by Microsoft Entra Connect service. d29b2b05-8046-44ba-8758-1e26182fcf32
Directory Writers Can read and write basic directory information. For granting access to applications, not intended for users.
Privileged label icon.
9360feb5-f418-4baa-8175-e2a00bac4301
Domain Name Administrator Can manage domain names in cloud and on-premises.
Privileged label icon.
8329153b-31d0-4727-b945-745eb3bc5f31
Dragon Administrator Manage all aspects of the Microsoft Dragon admin center. e93e3737-fa85-474a-aee4-7d3fb86510f3
Dynamics 365 Administrator Can manage all aspects of the Dynamics 365 product. 44367163-eba1-44c3-98af-f5787879f96a
Dynamics 365 Business Central Administrator Access and perform all administrative tasks on Dynamics 365 Business Central environments. 963797fb-eb3b-4cde-8ce3-5878b3f32a3f
Edge Administrator Manage all aspects of Microsoft Edge. 3f1acade-1e04-4fbc-9b69-f0302cd84aef
Entra Backup Administrator Manage all aspects of Microsoft Entra Backup, such as create recovery jobs and manage backup snapshots. b6a27b2b-f905-4b2e-81b5-0d90e0ef1fdb
Entra Backup Reader Read all aspects of Microsoft Entra Backup, such as list all preview jobs, recovery jobs, backup snapshots, and create preview jobs. f42252d9-5400-4d7b-b9ef-cc582dbb8577
Exchange Administrator Can manage all aspects of the Exchange product. 29232cdf-9323-42fd-ade2-1d097af3e4de
Exchange Backup Administrator Back up and restore content (including granular restore) for Exchange in Microsoft 365 Backup 49eb8f75-97e9-4e37-9b2b-6c3ebfcffa31
Exchange Recipient Administrator Can create or update Exchange Online recipients within the Exchange Online organization. 31392ffb-586c-42d1-9346-e59415a2cc4e
Extended Directory User Administrator Manage all aspects of external user profiles in the extended directory for Teams. dd13091a-6207-4fc0-82ba-3641e056ab95
External ID User Flow Administrator Can create and manage all aspects of user flows. 6e591065-9bad-43ed-90f3-e9424366d2f0
External ID User Flow Attribute Administrator Can create and manage the attribute schema available to all user flows. 0f971eea-41eb-4569-a71e-57bb8a3eff1e
External Identity Provider Administrator Can configure identity providers for use in direct federation.
Privileged label icon.
be2f45a1-457d-42af-a067-6ec1fa63bc45
Fabric Administrator Manage all aspects of the Fabric and Power BI products. a9ea8996-122f-4c74-9520-8edcd192826c
Global Administrator Can manage all aspects of Microsoft Entra ID and Microsoft services that use Microsoft Entra identities.
Privileged label icon.
62e90394-69f5-4237-9190-012177145e10
Global Reader Can read everything that a Global Administrator can, but not update anything.
Privileged label icon.
f2ef992c-3afb-46b9-b7cf-a126ee74c451
Global Secure Access Administrator Create and manage all aspects of Global Secure Internet Access and Microsoft Global Secure Private Access, including managing access to public and private endpoints. ac434307-12b9-4fa1-a708-88bf58caabc1
Global Secure Access Log Reader Provides designated security personnel with read-only access to network traffic logs in Microsoft Entra Internet Access and Microsoft Entra Private Access for detailed analysis. 843318fb-79a6-4168-9e6f-aa9a07481cc4
Groups Administrator Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports. fdd7a751-b60b-444a-984c-02652fe8fa1c
Guest Inviter Can invite guest users independent of the 'members can invite guests' setting. 95e79109-95c0-4d8e-aee3-d01accf2d47b
Helpdesk Administrator Can reset passwords for non-administrators and Helpdesk Administrators.
Privileged label icon.
729827e3-9c14-49f7-bb1b-9608f156bbb8
Hybrid Identity Administrator Manage Active Directory to Microsoft Entra cloud provisioning, Microsoft Entra Connect, pass-through authentication (PTA), password hash synchronization (PHS), seamless single sign-on (seamless SSO), and federation settings. Does not have access to manage Microsoft Entra Connect Health.
Privileged label icon.
8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2
Identity Governance Administrator Manage access using Microsoft Entra ID for identity governance scenarios.
Privileged label icon.
45d8d3c5-c802-45c6-b32a-1d70b5e1e86e
Insights Administrator Has administrative access in the Microsoft 365 Insights app. eb1f4a8d-243a-41f0-9fbd-c7cdf6c5ef7c
Insights Analyst Access the analytical capabilities in Microsoft Viva Insights and run custom queries. 25df335f-86eb-4119-b717-0ff02de207e9
Insights Business Leader View and share dashboards and insights via the Microsoft Viva Insights app. 31e939ad-9672-4796-9c2e-873181342d2d
Intune Administrator Can manage all aspects of the Intune product.
Privileged label icon.
3a2c62db-5318-420d-8d74-23affee5d9d5
IoT Device Administrator Provision new IoT devices, manage their lifecycle, configure certificates, and manage device templates. 2ea5ce4c-b2d8-4668-bd81-3680bd2d227a
Kaizala Administrator Can manage settings for Microsoft Kaizala. 74ef975b-6605-40af-a5d2-b9539d836353
Knowledge Administrator Can configure knowledge, learning, and other intelligent features. b5a8dcf3-09d5-43a9-a639-8e29ef291470
Knowledge Manager Organize, create, manage, and promote topics and knowledge. 744ec460-397e-42ad-a462-8b3f9747a02c
License Administrator Can manage product licenses on users and groups. 4d6ac14f-3453-41d0-bef9-a3e0c569773a
Lifecycle Workflows Administrator Create and manage all aspects of workflows and tasks associated with Lifecycle Workflows in Microsoft Entra ID.
Privileged label icon.
59d46f88-662b-457b-bceb-5c3809e5908f
Message Center Privacy Reader Can read security messages and updates in Office 365 Message Center only. ac16e43d-7b2d-40e0-ac05-243ff356ab5b
Message Center Reader Can read messages and updates for their organization in Office 365 Message Center only. 790c1fb9-7f7d-4f88-86a1-ef1f95c05c1b
Microsoft 365 Backup Administrator Back up and restore content across supported services (SharePoint, OneDrive, and Exchange Online) in Microsoft 365 Backup 1707125e-0aa2-4d4d-8655-a7c786c76a25
Microsoft 365 Migration Administrator Perform all migration functionality to migrate content to Microsoft 365 using Migration Manager. 8c8b803f-96e1-4129-9349-20738d9f9652
Microsoft Entra Joined Device Local Administrator Users assigned to this role are added to the local administrators group on Microsoft Entra joined devices. 9f06204d-73c1-4d4c-880a-6edb90606fd8
Microsoft Graph Data Connect Administrator Manage aspects of Microsoft Graph Data Connect service in a tenant. ee67aa9c-e510-4759-b906-227085a7fd4d
Microsoft Hardware Warranty Administrator Create and manage all aspects warranty claims and entitlements for Microsoft manufactured hardware, like Surface and HoloLens. 1501b917-7653-4ff9-a4b5-203eaf33784f
Microsoft Hardware Warranty Specialist Create and read warranty claims for Microsoft manufactured hardware, like Surface and HoloLens. 281fe777-fb20-4fbb-b7a3-ccebce5b0d96
Network Administrator Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications. d37c8bed-0711-4417-ba38-b4abe66ce4c2
Office Apps Administrator Can manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish 'what's new' feature content to end-user's devices. 2b745bdf-0803-4d80-aa65-822c4493daac
Organizational Branding Administrator Manage all aspects of organizational branding in a tenant. 92ed04bf-c94a-4b82-9729-b799a7a4c178
Organizational Data Source Administrator Set up and manage the ingestion of organizational data into Microsoft 365. 9d70768a-0cbc-4b4c-aea3-2e124b2477f4
Organizational Messages Approver Review, approve, or reject new organizational messages for delivery in the Microsoft 365 admin center before they are sent to users. e48398e2-f4bb-4074-8f31-4586725e205b
Organizational Messages Writer Write, publish, manage, and review the organizational messages for end-users through Microsoft product surfaces. 507f53e4-4e52-4077-abd3-d2e1558b6ea2
Partner Tier1 Support Do not use - not intended for general use.
Privileged label icon.
4ba39ca4-527c-499a-b93d-d9b492c50246
Partner Tier2 Support Do not use - not intended for general use.
Privileged label icon.
e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8
Password Administrator Can reset passwords for non-administrators and Password Administrators.
Privileged label icon.
966707d0-3269-4727-9be2-8c3a10f19b9d
People Administrator Manage profile photos of users and people settings for all users in the organization. 024906de-61e5-49c8-8572-40335f1e0e10
Permissions Management Administrator Manage all aspects of Microsoft Entra Permissions Management. af78dc32-cf4d-46f9-ba4e-4428526346b5
Places Administrator Manage all aspects of the Microsoft Places service. 78b0ccd1-afc2-4f92-9116-b41aedd09592
Power Platform Administrator Manage all aspects of Microsoft Dynamics 365, Power Apps and Power Automate. 11648597-926c-4cf3-9c36-bcebb0ba8dcc
Printer Administrator Can manage all aspects of printers and printer connectors. 644ef478-e28f-4e28-b9dc-3fdde9aa0b1f
Printer Technician Can register and unregister printers and update printer status. e8cef6f1-e4bd-4ea8-bc07-4b8d950f4477
Privileged Authentication Administrator Can access to view, set and reset authentication method information for any user (admin or non-admin).
Privileged label icon.
7be44c8a-adaf-4e2a-84d6-ab2649e08a13
Privileged Role Administrator Can manage role assignments in Microsoft Entra ID, and all aspects of Privileged Identity Management.
Privileged label icon.
e8611ab8-c189-46e8-94e1-60213ab1f814
Purview Workload Content Administrator Manage or purge data from Microsoft 365 when accessing from the Microsoft Purview portal. 3f04f91a-4ad7-4bd3-bcfa-49882ea1a88a
Purview Workload Content Reader Read data from Microsoft 365 when accessing from the Microsoft Purview portal. e07494ad-1654-4dd2-922e-6f81a71bf00f
Purview Workload Content Writer Read and edit data from Microsoft 365 when accessing from the Microsoft Purview portal. 02d5655b-c1cf-4e5f-98da-5fb919085bf6
Reports Reader Can read sign-in and audit reports. 4a5d8f65-41da-4de4-8968-e035b65339cf
Search Administrator Can create and manage all aspects of Microsoft Search settings. 0964bb5e-9bdb-4d7b-ac29-58e794862a40
Search Editor Can create and manage the editorial content such as bookmarks, Q and As, locations, floorplan. 8835291a-918c-4fd7-a9ce-faa49f0cf7d9
Security Administrator Can read security information and reports, and manage configuration in Microsoft Entra ID and Office 365.
Privileged label icon.
194ae4cb-b126-40b2-bd5b-6091b380977d
Security Operator Creates and manages security events and performs identity containment actions during security incidents.
Privileged label icon.
5f2222b1-57c3-48ba-8ad5-d4759f1fde6f
Security Reader Can read security information and reports in Microsoft Entra ID and Office 365.
Privileged label icon.
5d6b6bb7-de71-4623-b4af-96380a352509
Service Support Administrator Can read service health information and manage support tickets. f023fd81-a637-4b56-95fd-791ac0226033
SharePoint Administrator Can manage all aspects of the SharePoint service. f28a1f50-f6e7-4571-818b-6a12f2af6b6c
SharePoint Advanced Management Administrator Manage all aspects of SharePoint Advanced Management. 99009c4a-3b3f-4957-82a9-9d35e12db77e
SharePoint Backup Administrator Back up and restore content (including granular restore) for SharePoint and OneDrive in Microsoft 365 Backup 9d3e04ba-3ee4-4d1b-a3a7-9aef423a09be
SharePoint Embedded Administrator Manage all aspects of SharePoint Embedded containers. 1a7d78b6-429f-476b-b8eb-35fb715fffd4
Skype for Business Administrator Can manage all aspects of the Skype for Business product. 75941009-915a-4869-abe7-691bff18279e
Teams Administrator Can manage the Microsoft Teams service. 69091246-20e8-4a56-aa4d-066075b2a7a8
Teams Communications Administrator Can manage calling and meetings features within the Microsoft Teams service. baf37b3a-610e-45da-9e62-d9d1e5e8914b
Teams Communications Support Engineer Can troubleshoot communications issues within Teams using advanced tools. f70938a0-fc10-4177-9e90-2178f8765737
Teams Communications Support Specialist Can troubleshoot communications issues within Teams using basic tools. fcf91098-03e3-41a9-b5ba-6f0ec8188a12
Teams Devices Administrator Can perform management related tasks on Teams certified devices. 3d762c5a-1b6c-493f-843e-55a3b42923d4
Teams External Collaboration Administrator Manage external collaboration policies and settings for Teams, including configuring external domains and controlling which groups and users can interact with the organization. 2fe872fb-daa8-4afc-8f6c-53c4565cfef4
Teams Reader Read everything in the Teams admin center, but not update anything. 1076ac91-f3d9-41a7-a339-dcdf5f480acc
Teams Telephony Administrator Manage voice and telephony features and troubleshoot communication issues within the Microsoft Teams service. aa38014f-0993-46e9-9b45-30501a20909d
Tenant Creator Create new Microsoft Entra or Azure AD B2C tenants. 112ca1a2-15ad-4102-995e-45b0bc479a6a
Tenant Governance Administrator Manage all capabilities in the Microsoft Entra Tenant Governance service.
Privileged label icon.
1981f584-96e9-4a6f-95b0-f522373f8fae
Tenant Governance Reader Can read all tenant governance data. e0a4caa6-fe82-443f-b92f-d87341d17b2e
Tenant Governance Relationship Administrator Can initiate governance relationships and terminate them. b8e31d83-1534-480f-9b10-0338ded51b7e
Tenant Governance Relationship Reader Can read tenant governance relationships and relevant objects. 124577f8-48ed-456a-839f-13b419002e33
Usage Summary Reports Reader Read Usage reports and Adoption Score, but can't access user details. 75934031-6c7e-415a-99d7-48dbd49e875e
User Administrator Can manage all aspects of users and groups, including resetting passwords for limited admins.
Privileged label icon.
fe930be7-5e62-47db-91af-98c3a49a38b1
User Experience Success Manager View product feedback, survey results, and reports to find training and communication opportunities. 27460883-1df1-4691-b032-3b79643e5e63
Virtual Visits Administrator Manage and share Virtual Visits information and metrics from admin centers or the Virtual Visits app. e300d9e7-4a2b-4295-9eff-f1c78b36cc98
Viva Glint Tenant Administrator Manage and configure Microsoft Viva Glint settings in the Microsoft 365 admin center. 0ec3f692-38d6-4d14-9e69-0377ca7797ad
Viva Goals Administrator Manage and configure all aspects of Microsoft Viva Goals. 92b086b3-e367-4ef2-b869-1de128fb986e
Viva Pulse Administrator Can manage all settings for Microsoft Viva Pulse app. 87761b17-1ed2-4af3-9acd-92a150038160
Windows 365 Administrator Can provision and manage all aspects of Cloud PCs. 11451d60-acb2-45eb-a7d6-43d0f0125c13
Windows Update Deployment Administrator Can create and manage all aspects of Windows Update deployments through the Windows Update for Business deployment service. 32696413-001a-46ae-978c-ce0f6b3620d2
Yammer Administrator Manage all aspects of the Yammer service. 810a2642-a034-447f-a5e8-41beaa378541

Agent ID Administrator

Privileged label icon.

Assign the Agent ID Administrator role to users who need to do the following:

  • Manage the full lifecycle of agent identities, agent identity blueprint principals, agent identity blueprints, and agent users in a tenant
  • Permanently delete and restore deleted agent identities, agent identity blueprint principals, agent identity blueprints, and agent users
  • Manage licenses, invalidate refresh tokens, and revoke sign-in sessions for agent users
  • Read all properties of audit logs and sign-in reports
  • Read standard properties of organization, policies, external user profiles, hidden group members, and bulk jobs for users
  • Create Microsoft 365 groups as owner
  • Read and configure Azure and Microsoft 365 service health and support tickets
  • Create and manage Azure and Microsoft 365 service health and support tickets
Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/agentIdentities/appRoleAssignedTo/update Update agent identity role assignments
microsoft.directory/agentIdentities/authentication/update Update authentication on agent identities
microsoft.directory/agentIdentities/basic/update Update basic properties on agent identities
microsoft.directory/agentIdentities/create Create agent identities
microsoft.directory/agentIdentities/delete Delete agent identities
microsoft.directory/agentIdentities/disable Disable agent identities
microsoft.directory/agentIdentities/enable Enable agent identities
microsoft.directory/agentIdentities/owners/update Update owners on agent identities
microsoft.directory/agentIdentities/tag/update Update tags of agent identities
microsoft.directory/agentIdentityBlueprintPrincipals/appRoleAssignedTo/update Update agent identity blueprint principal role assignments
microsoft.directory/agentIdentityBlueprintPrincipals/authentication/update Update authentication on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/basic/update Update basic properties on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/create Create agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/delete Delete agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/disable Disable agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/enable Enable agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/owners/update Update owners on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/tag/update Update tags of agent identity blueprint principals
microsoft.directory/agentIdentityBlueprints/allProperties/read Read all properties of agent identity blueprints
microsoft.directory/agentIdentityBlueprints/allProperties/update Update all properties of agent identity blueprints
Privileged label icon.
microsoft.directory/agentIdentityBlueprints/appRoles/update Update appRoles on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/audience/update Update audience on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/authentication/update Update authentication on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/basic/update Update basic properties on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/create Create agent identity blueprints
microsoft.directory/agentIdentityBlueprints/credentials/update Update credentials on agent identity blueprints
Privileged label icon.
microsoft.directory/agentIdentityBlueprints/delete Delete agent identity blueprints
microsoft.directory/agentIdentityBlueprints/owners/update Update owners on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/permissions/update Update exposed permissions and required permissions on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/tag/update Update tags of agent identity blueprints
microsoft.directory/agentUsers/assignLicense Assign product licenses for agent users
microsoft.directory/agentUsers/basic/update Update basic properties on agent users, such display name, user type, and mail nickname
microsoft.directory/agentUsers/create Create agent users
Privileged label icon.
microsoft.directory/agentUsers/delete Delete agent users
Privileged label icon.
microsoft.directory/agentUsers/disable Disable agent users
Privileged label icon.
microsoft.directory/agentUsers/enable Enable agent users
Privileged label icon.
microsoft.directory/agentUsers/invalidateAllRefreshTokens Force sign-out by invalidating agent user refresh tokens
Privileged label icon.
microsoft.directory/agentUsers/lifeCycleInfo/read Read lifecycle information of agent users, such as employeeLeaveDateTime
Privileged label icon.
microsoft.directory/agentUsers/lifeCycleInfo/update Update lifecycle information of agent users, such as employeeLeaveDateTime
Privileged label icon.
microsoft.directory/agentUsers/manager/update Update manager for agent users
microsoft.directory/agentUsers/photo/update Update photo of agent users
microsoft.directory/agentUsers/reprocessLicenseAssignment Reprocess license assignments for agent users
microsoft.directory/agentUsers/restore Restore deleted agent users
microsoft.directory/agentUsers/revokeSignInSessions Revoke sign-in sessions for agent users
microsoft.directory/agentUsers/sponsors/update Update sponsors of agent users
microsoft.directory/agentUsers/usageLocation/update Update usage location of agent users
microsoft.directory/agentUsers/userPrincipalName/update Update the user principal name of agent users
Privileged label icon.
microsoft.directory/auditLogs/allProperties/read Read all properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/deletedItems.agentIdentities/delete Permanently delete agent identities, which can no longer be restored
microsoft.directory/deletedItems.agentIdentities/restore Restore soft-deleted agent identities to original state
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/delete Permanently delete agent identity blueprint principals, which can no longer be restored
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/restore Restore soft-deleted agent identity blueprint principals to original state
microsoft.directory/deletedItems.agentIdentityBlueprints/delete Permanently delete agent identity blueprints, which can no longer be restored
microsoft.directory/deletedItems.agentIdentityBlueprints/restore Restore soft-deleted agent identity blueprints to original state
microsoft.directory/externalUserProfiles/standard/read Read standard properties of external user profiles in the extended directory for Teams
microsoft.directory/groups.unified/createAsOwner Create Microsoft 365 groups, excluding role-assignable groups. Creator is added as the first owner.
microsoft.directory/groups/hiddenMembers/read Read hidden members of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/organization/standard/read Read basic properties on an organization
microsoft.directory/policies/standard/read Read basic properties on policies
microsoft.directory/signInReports/allProperties/read Read all properties on sign-in reports, including privileged properties
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests

Agent ID Developer

Assign the Agent ID Developer role to users who need to do the following:

  • Create an agent identity blueprint and its agent identity blueprint principal in a tenant. User will be added as an owner of the created agent identity blueprint and its agent identity blueprint principal.
Actions Description
microsoft.directory/agentIdentityBlueprints/createAsOwner Create agent identity blueprints, and creator is added as the first owner
microsoft.directory/servicePrincipals/standard/read Read basic properties of service principals

Agent Registry Administrator

Assign the Agent Registry Administrator role to users who need to do the following tasks:

  • Manage metadata for AI agents in Microsoft Entra ID
  • Manage collections and visibility of agents
  • Assign Agent Registry-specific roles to other users or agents to access the registry
Actions Description
microsoft.agentRegistry/allEntities/allProperties/allTasks Manage all aspects of Agent Registry in Microsoft Entra ID

AI Administrator

Privileged label icon.

This is a privileged role. Assign the AI Administrator role to users who need to do the following tasks:

  • Manage all aspects of Microsoft 365 Copilot
  • Manage AI-related enterprise services, extensibility, and copilot agents from the Integrated apps page in the Microsoft 365 admin center
  • Manage admin consent request policies in Microsoft Entra ID
  • Approve and publish line-of-business copilot agents
  • Allow users to install an app or install an app for users in the organization if the app does not require permission
  • Read and configure Azure and Microsoft 365 service health dashboards
  • View usage reports, adoption insights, and organizational insight
  • Create and manage support tickets in Azure and the Microsoft 365 admin center
  • Manage the full lifecycle of agent identities, agent identity blueprints, agent identity blueprint principals, and agent users including restoration of deleted items
Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks Manage admin consent request policies in Microsoft Entra ID
microsoft.directory/agentIdentities/allProperties/read Read all properties of agent identities
microsoft.directory/agentIdentities/appRoleAssignedTo/update Update agent identity role assignments
microsoft.directory/agentIdentities/authentication/update Update authentication on agent identities
microsoft.directory/agentIdentities/basic/update Update basic properties on agent identities
microsoft.directory/agentIdentities/create Create agent identities
microsoft.directory/agentIdentities/delete Delete agent identities
microsoft.directory/agentIdentities/disable Disable agent identities
microsoft.directory/agentIdentities/enable Enable agent identities
microsoft.directory/agentIdentities/owners/update Update owners on agent identities
microsoft.directory/agentIdentities/tag/update Update tags of agent identities
microsoft.directory/agentIdentityBlueprintPrincipals/allProperties/read Read all properties of agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/appRoleAssignedTo/update Update agent identity blueprint principal role assignments
microsoft.directory/agentIdentityBlueprintPrincipals/authentication/update Update authentication on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/basic/update Update basic properties on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/create Create agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/delete Delete agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/disable Disable agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/enable Enable agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/owners/update Update owners on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/tag/update Update tags of agent identity blueprint principals
microsoft.directory/agentIdentityBlueprints/allProperties/read Read all properties of agent identity blueprints
microsoft.directory/agentIdentityBlueprints/allProperties/update Update all properties of agent identity blueprints
Privileged label icon.
microsoft.directory/agentIdentityBlueprints/appRoles/update Update appRoles on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/audience/update Update audience on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/authentication/update Update authentication on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/basic/update Update basic properties on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/create Create agent identity blueprints
microsoft.directory/agentIdentityBlueprints/credentials/update Update credentials on agent identity blueprints
Privileged label icon.
microsoft.directory/agentIdentityBlueprints/delete Delete agent identity blueprints
microsoft.directory/agentIdentityBlueprints/owners/update Update owners on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/permissions/update Update exposed permissions and required permissions on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/tag/update Update tags of agent identity blueprints
microsoft.directory/agentIdentityBlueprints/verification/update Update verification on agent identity blueprints
microsoft.directory/agentUsers/assignLicense Assign product licenses for agent users
microsoft.directory/agentUsers/basic/update Update basic properties on agent users, such display name, user type, and mail nickname
microsoft.directory/agentUsers/create Create agent users
Privileged label icon.
microsoft.directory/agentUsers/delete Delete agent users
Privileged label icon.
microsoft.directory/agentUsers/disable Disable agent users
Privileged label icon.
microsoft.directory/agentUsers/enable Enable agent users
Privileged label icon.
microsoft.directory/agentUsers/invalidateAllRefreshTokens Force sign-out by invalidating agent user refresh tokens
Privileged label icon.
microsoft.directory/agentUsers/lifeCycleInfo/read Read lifecycle information of agent users, such as employeeLeaveDateTime
Privileged label icon.
microsoft.directory/agentUsers/lifeCycleInfo/update Update lifecycle information of agent users, such as employeeLeaveDateTime
Privileged label icon.
microsoft.directory/agentUsers/manager/update Update manager for agent users
microsoft.directory/agentUsers/photo/update Update photo of agent users
microsoft.directory/agentUsers/reprocessLicenseAssignment Reprocess license assignments for agent users
microsoft.directory/agentUsers/restore Restore deleted agent users
microsoft.directory/agentUsers/revokeSignInSessions Revoke sign-in sessions for agent users
microsoft.directory/agentUsers/sponsors/update Update sponsors of agent users
microsoft.directory/agentUsers/usageLocation/update Update usage location of agent users
microsoft.directory/agentUsers/userPrincipalName/update Update the user principal name of agent users
Privileged label icon.
microsoft.directory/deletedItems.agentIdentities/delete Permanently delete agent identities, which can no longer be restored
microsoft.directory/deletedItems.agentIdentities/restore Restore soft-deleted agent identities to original state
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/delete Permanently delete agent identity blueprint principals, which can no longer be restored
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/restore Restore soft-deleted agent identity blueprint principals to original state
microsoft.directory/deletedItems.agentIdentityBlueprints/delete Permanently delete agent identity blueprints, which can no longer be restored
microsoft.directory/deletedItems.agentIdentityBlueprints/restore Restore soft-deleted agent identity blueprints to original state
microsoft.directory/entitlementManagement/allProperties/read Read all properties in Microsoft Entra entitlement management
microsoft.directory/subscribedSkus/standard/read Read basic properties on subscriptions
microsoft.directory/users/allProperties/read Read all properties of users
Privileged label icon.
microsoft.office365.copilot/allEntities/allProperties/allTasks Create and manage all settings for Microsoft 365 Copilot
microsoft.office365.messageCenter/messages/read Read messages in Message Center in the Microsoft 365 admin center, excluding security messages
microsoft.office365.network/performance/allProperties/read Read all network performance properties in the Microsoft 365 admin center
microsoft.office365.search/content/manage Create and delete content, and read and update all properties in Microsoft Search
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.usageReports/allEntities/allProperties/read Read Office 365 usage reports
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

AI Reader

Privileged label icon.

This is a privileged role. Assign the AI Reader role to users who need to do the following tasks:

  • Read all aspects of Microsoft 365 Copilot
  • Read AI-related enterprise services, extensibility, and copilot agents
  • Read information for directory objects including applications, users, groups, agent identities, agent identity blueprints, agent identity blueprint principals, and agent users
  • Read and configure Azure and Microsoft 365 service health dashboards
Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.directory/administrativeUnits/members/read Read members of administrative units
microsoft.directory/administrativeUnits/standard/read Read basic properties on administrative units
microsoft.directory/adminConsentRequestPolicy/allProperties/read Read all properties of admin consent request policies in Microsoft Entra ID
microsoft.directory/agentIdentities/allProperties/read Read all properties of agent identities
microsoft.directory/agentIdentityBlueprintPrincipals/allProperties/read Read all properties of agent identity blueprint principals
microsoft.directory/agentIdentityBlueprints/allProperties/read Read all properties of agent identity blueprints
microsoft.directory/agentUsers/lifeCycleInfo/read Read lifecycle information of agent users, such as employeeLeaveDateTime
Privileged label icon.
microsoft.directory/applicationPolicies/standard/read Read standard properties of application policies
microsoft.directory/applications/owners/read Read owners of applications
microsoft.directory/applications/policies/read Read policies of applications
microsoft.directory/applications/standard/read Read standard properties of applications
microsoft.directory/contacts/memberOf/read Read the group membership for all contacts in Microsoft Entra ID
microsoft.directory/contacts/standard/read Read basic properties on contacts in Microsoft Entra ID
microsoft.directory/contracts/standard/read Read basic properties on partner contracts
microsoft.directory/domains/standard/read Read basic properties on domains
microsoft.directory/entitlementManagement/allProperties/read Read all properties in Microsoft Entra entitlement management
microsoft.directory/groups/appRoleAssignments/read Read application role assignments of groups
microsoft.directory/groups/memberOf/read Read the memberOf property on Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groups/members/read Read members of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groups/owners/read Read owners of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groups/settings/read Read settings of groups
microsoft.directory/groups/standard/read Read standard properties of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groupSettings/standard/read Read basic properties on group settings
microsoft.directory/groupSettingTemplates/standard/read Read basic properties on group setting templates
microsoft.directory/oAuth2PermissionGrants/standard/read Read basic properties on OAuth 2.0 permission grants
microsoft.directory/organization/standard/read Read basic properties on an organization
microsoft.directory/organization/trustedCAsForPasswordlessAuth/read Read trusted certificate authorities for passwordless authentication
microsoft.directory/roleAssignments/standard/read Read basic properties on role assignments
microsoft.directory/roleDefinitions/standard/read Read basic properties on role definitions
microsoft.directory/servicePrincipals/appRoleAssignedTo/read Read service principal role assignments
microsoft.directory/servicePrincipals/appRoleAssignments/read Read role assignments assigned to service principals
microsoft.directory/servicePrincipals/memberOf/read Read the group memberships on service principals
microsoft.directory/servicePrincipals/oAuth2PermissionGrants/read Read delegated permission grants on service principals
microsoft.directory/servicePrincipals/ownedObjects/read Read owned objects of service principals
microsoft.directory/servicePrincipals/owners/read Read owners of service principals
microsoft.directory/servicePrincipals/policies/read Read policies of service principals
microsoft.directory/servicePrincipals/standard/read Read basic properties of service principals
microsoft.directory/subscribedSkus/standard/read Read basic properties on subscriptions
microsoft.directory/users/allProperties/read Read all properties of users
Privileged label icon.
microsoft.office365.copilot/allEntities/allProperties/read Read all settings for Microsoft 365 Copilot
microsoft.office365.messageCenter/messages/read Read messages in Message Center in the Microsoft 365 admin center, excluding security messages
microsoft.office365.network/performance/allProperties/read Read all network performance properties in the Microsoft 365 admin center
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Application Administrator

Privileged label icon.

This is a privileged role. Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.

This role also grants the ability to consent for delegated permissions and application permissions, with the exception of application permissions for Azure AD Graph and Microsoft Graph.

Important

This exception means that you can still consent to application permissions for other apps (for example, other Microsoft apps, 3rd-party apps, or apps that you have registered). You can still request these permissions as part of the app registration, but granting (that is, consenting to) these permissions requires a more privileged administrator, such as Privileged Role Administrator.

This role grants the ability to manage application credentials. Users assigned this role can add credentials to an application, and use those credentials to impersonate the application's identity. If the application's identity has been granted access to a resource, such as the ability to create or update User or other objects, then a user assigned to this role could perform those actions while impersonating the application. This ability to impersonate the application's identity may be an elevation of privilege over what the user can do via their role assignments. It is important to understand that assigning a user to the Application Administrator role gives them the ability to impersonate an application's identity.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks Manage admin consent request policies in Microsoft Entra ID
microsoft.directory/appConsent/appConsentRequests/allProperties/read Read all properties of consent requests for applications registered with Microsoft Entra ID
microsoft.directory/applicationPolicies/basic/update Update standard properties of application policies
microsoft.directory/applicationPolicies/create Create application policies
microsoft.directory/applicationPolicies/delete Delete application policies
microsoft.directory/applicationPolicies/owners/read Read owners on application policies
microsoft.directory/applicationPolicies/owners/update Update the owner property of application policies
microsoft.directory/applicationPolicies/policyAppliedTo/read Read application policies applied to objects list
microsoft.directory/applicationPolicies/standard/read Read standard properties of application policies
microsoft.directory/applications/applicationProxy/read Read all application proxy properties
microsoft.directory/applications/applicationProxy/update Update all application proxy properties
microsoft.directory/applications/applicationProxyAuthentication/update Update authentication on all types of applications
microsoft.directory/applications/applicationProxySslCertificate/update Update SSL certificate settings for application proxy
microsoft.directory/applications/applicationProxyUrlSettings/update Update URL settings for application proxy
microsoft.directory/applications/appRoles/update Update the appRoles property on all types of applications
microsoft.directory/applications/audience/update Update the audience property for applications
microsoft.directory/applications/authentication/update Update authentication on all types of applications
microsoft.directory/applications/basic/update Update basic properties for applications
microsoft.directory/applications/create Create all types of applications
microsoft.directory/applications/credentials/update Update application credentials
Privileged label icon.
microsoft.directory/applications/delete Delete all types of applications
microsoft.directory/applications/disablement/update Update whether an application is enabled for users to sign in
microsoft.directory/applications/extensionProperties/update Update extension properties on applications
microsoft.directory/applications/notes/update Update notes of applications
microsoft.directory/applications/owners/update Update owners of applications
microsoft.directory/applications/permissions/update Update exposed permissions and required permissions on all types of applications
microsoft.directory/applications/policies/update Update policies of applications
microsoft.directory/applications/synchronization/standard/read Read provisioning settings associated with the application object
microsoft.directory/applications/tag/update Update tags of applications
microsoft.directory/applications/verification/update Update applicationsverification property
microsoft.directory/applicationTemplates/instantiate Instantiate gallery applications from application templates
microsoft.directory/auditLogs/allProperties/read Read all properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/connectorGroups/allProperties/read Read all properties of application proxy connector groups
microsoft.directory/connectorGroups/allProperties/update Update all properties of application proxy connector groups
microsoft.directory/connectorGroups/create Create application proxy connector groups
microsoft.directory/connectorGroups/delete Delete application proxy connector groups
microsoft.directory/connectors/allProperties/read Read all properties of application proxy connectors
microsoft.directory/connectors/create Create application proxy connectors
microsoft.directory/customAuthenticationExtensions/allProperties/allTasks Create and manage custom authentication extensions
Privileged label icon.
microsoft.directory/deletedItems.applications/delete Permanently delete applications, which can no longer be restored
microsoft.directory/deletedItems.applications/restore Restore soft deleted applications to original state
microsoft.directory/oAuth2PermissionGrants/allProperties/allTasks Create and delete OAuth 2.0 permission grants, and read and update all properties
Privileged label icon.
microsoft.directory/provisioningLogs/allProperties/read Read all properties of provisioning logs
microsoft.directory/servicePrincipals/appRoleAssignedTo/update Update service principal role assignments
microsoft.directory/servicePrincipals/audience/update Update audience properties on service principals
microsoft.directory/servicePrincipals/authentication/update Update authentication properties on service principals
microsoft.directory/servicePrincipals/basic/update Update basic properties on service principals
microsoft.directory/servicePrincipals/create Create service principals
microsoft.directory/servicePrincipals/credentials/update Update credentials of service principals
Privileged label icon.
microsoft.directory/servicePrincipals/delete Delete service principals
microsoft.directory/servicePrincipals/disable Disable service principals
microsoft.directory/servicePrincipals/enable Enable service principals
microsoft.directory/servicePrincipals/getPasswordSingleSignOnCredentials Manage password single sign-on credentials on service principals
microsoft.directory/servicePrincipals/managePasswordSingleSignOnCredentials Read password single sign-on credentials on service principals
microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-application-admin Grant consent for application permissions and delegated permissions on behalf of any user or all users, except for application permissions for Microsoft Graph and Azure AD Graph
microsoft.directory/servicePrincipals/notes/update Update notes of service principals
microsoft.directory/servicePrincipals/owners/update Update owners of service principals
microsoft.directory/servicePrincipals/permissions/update Update permissions of service principals
microsoft.directory/servicePrincipals/policies/update Update policies of service principals
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/credentials/manage Manage application provisioning secrets and credentials.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/jobs/manage Start, restart, and pause application provisioning synchronization jobs.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/schema/manage Create and manage application provisioning synchronization jobs and schema.
microsoft.directory/servicePrincipals/synchronization/standard/read Read provisioning settings associated with your service principal
microsoft.directory/servicePrincipals/synchronizationCredentials/manage Manage application provisioning secrets and credentials
microsoft.directory/servicePrincipals/synchronizationJobs/manage Start, restart, and pause application provisioning synchronization jobs
microsoft.directory/servicePrincipals/synchronizationSchema/manage Create and manage application provisioning synchronization jobs and schema
microsoft.directory/servicePrincipals/tag/update Update the tag property for service principals
microsoft.directory/signInReports/allProperties/read Read all properties on sign-in reports, including privileged properties
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Application Developer

Privileged label icon.

This is a privileged role. Users in this role can create application registrations when the "Users can register applications" setting is set to No. This role also grants permission to consent on one's own behalf when the "Users can consent to apps accessing company data on their behalf" setting is set to No. Users assigned to this role are added as owners when creating new application registrations.

Actions Description
microsoft.directory/applications/createAsOwner Create all types of applications, and creator is added as the first owner
microsoft.directory/oAuth2PermissionGrants/createAsOwner Create OAuth 2.0 permission grants, with creator as the first owner
Privileged label icon.
microsoft.directory/servicePrincipals/createAsOwner Create service principals, with creator as the first owner

Attack Payload Author

Users in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation. Access to reports is limited to simulations executed by the user, and this role doesn't grant access to aggregate reports such as Training efficacy, Repeat offenders, Training completion, or User coverage.

For more information, see these articles:

Actions Description
microsoft.office365.protectionCenter/attackSimulator/payload/allProperties/allTasks Create and manage attack payloads in Attack Simulator
microsoft.office365.protectionCenter/attackSimulator/reports/allProperties/read Read reports of attack simulation, responses, and associated training

Attack Simulation Administrator

Users in this role can create and manage all aspects of attack simulation creation, launch/scheduling of a simulation, and the review of simulation results. Members of this role have this access for all simulations in the tenant.

For more information, see these articles:

Actions Description
microsoft.office365.protectionCenter/attackSimulator/payload/allProperties/allTasks Create and manage attack payloads in Attack Simulator
microsoft.office365.protectionCenter/attackSimulator/reports/allProperties/read Read reports of attack simulation, responses, and associated training
microsoft.office365.protectionCenter/attackSimulator/simulation/allProperties/allTasks Create and manage attack simulation templates in Attack Simulator

Attribute Assignment Administrator

Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.

Important

By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.

For more information, see Manage access to custom security attributes in Microsoft Entra ID.

Actions Description
microsoft.directory/attributeSets/allProperties/read Read all properties of attribute sets
microsoft.directory/azureManagedIdentities/customSecurityAttributes/read Read custom security attribute values for Microsoft Entra managed identities
microsoft.directory/azureManagedIdentities/customSecurityAttributes/update Update custom security attribute values for Microsoft Entra managed identities
microsoft.directory/customSecurityAttributeDefinitions/allProperties/read Read all properties of custom security attribute definitions
microsoft.directory/devices/customSecurityAttributes/read Read custom security attribute values for devices
microsoft.directory/devices/customSecurityAttributes/update Update custom security attribute values for devices
microsoft.directory/servicePrincipals/customSecurityAttributes/read Read custom security attribute values for service principals
microsoft.directory/servicePrincipals/customSecurityAttributes/update Update custom security attribute values for service principals
microsoft.directory/users/customSecurityAttributes/read Read custom security attribute values for users
microsoft.directory/users/customSecurityAttributes/update Update custom security attribute values for users

Attribute Assignment Reader

Users with this role can read custom security attribute keys and values for supported Microsoft Entra objects.

Important

By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.

For more information, see Manage access to custom security attributes in Microsoft Entra ID.

Actions Description
microsoft.directory/attributeSets/allProperties/read Read all properties of attribute sets
microsoft.directory/azureManagedIdentities/customSecurityAttributes/read Read custom security attribute values for Microsoft Entra managed identities
microsoft.directory/customSecurityAttributeDefinitions/allProperties/read Read all properties of custom security attribute definitions
microsoft.directory/devices/customSecurityAttributes/read Read custom security attribute values for devices
microsoft.directory/servicePrincipals/customSecurityAttributes/read Read custom security attribute values for service principals
microsoft.directory/users/customSecurityAttributes/read Read custom security attribute values for users

Attribute Definition Administrator

Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.

Important

By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.

For more information, see Manage access to custom security attributes in Microsoft Entra ID.

Actions Description
microsoft.directory/attributeSets/allProperties/allTasks Manage all aspects of attribute sets
microsoft.directory/customSecurityAttributeDefinitions/allProperties/allTasks Manage all aspects of custom security attribute definitions

Attribute Definition Reader

Users with this role can read the definition of custom security attributes.

Important

By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.

For more information, see Manage access to custom security attributes in Microsoft Entra ID.

Actions Description
microsoft.directory/attributeSets/allProperties/read Read all properties of attribute sets
microsoft.directory/customSecurityAttributeDefinitions/allProperties/read Read all properties of custom security attribute definitions

Attribute Log Administrator

Assign the Attribute Log Reader role to users who need to do the following tasks:

  • Read audit logs for custom security attribute value changes
  • Read audit logs for custom security attribute definition changes and assignments
  • Configure diagnostic settings for custom security attributes

Users with this role cannot read audit logs for other events.

Important

By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.

For more information, see Manage access to custom security attributes in Microsoft Entra ID.

Actions Description
microsoft.azure.customSecurityAttributeDiagnosticSettings/allEntities/allProperties/allTasks Configure all aspects of custom security attributes diagnostic settings
microsoft.directory/customSecurityAttributeAuditLogs/allProperties/read Read audit logs related to custom secruity attributes

Attribute Log Reader

Assign the Attribute Log Reader role to users who need to do the following tasks:

  • Read audit logs for custom security attribute value changes
  • Read audit logs for custom security attribute definition changes and assignments

Users with this role cannot do the following tasks:

  • Configure diagnostic settings for custom security attributes
  • Read audit logs for other events

Important

By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.

For more information, see Manage access to custom security attributes in Microsoft Entra ID.

Actions Description
microsoft.directory/customSecurityAttributeAuditLogs/allProperties/read Read audit logs related to custom secruity attributes

Attribute Provisioning Administrator

Privileged label icon.

This is a privileged role. Assign the Attribute Provisioning Administrator role to users who need to do the following tasks:

  • Read and write attribute mappings for custom security attributes when provisioning in an application.
  • Read and write provisioning and auditing logs for custom security attributes when provisioning in an application.

Users with this role cannot read audit logs for other events. This role must be used in conjunction with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.

Important

This role does not have the ability to create custom security attribute sets or to directly assign or update custom security attribute values for the user object. This role can only configure the flow of the custom security attributes in the provisioning app.

Learn more

Actions Description
microsoft.directory/servicePrincipals/synchronization.customSecurityAttributes/schema/read Read all custom security attributes in the synchronization schema
Privileged label icon.
microsoft.directory/servicePrincipals/synchronization.customSecurityAttributes/schema/update Update custom security attribute mappings in the synchronization schema
Privileged label icon.

Attribute Provisioning Reader

Privileged label icon.

This is a privileged role. Assign the Attribute Provisioning Reader role to users who need to do the following tasks:

  • Read the attribute mappings for custom security attributes when provisioning in an application.
  • Read the provisioning and auditing logs for custom security attributes when provisioning in an application.

Users with this role can't read audit logs for other events. This role must be used with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.

Learn more

Actions Description
microsoft.directory/servicePrincipals/synchronization.customSecurityAttributes/schema/read Read all custom security attributes in the synchronization schema
Privileged label icon.

Authentication Administrator

Privileged label icon.

This is a privileged role. Assign the Authentication Administrator role to users who need to do the following:

  • Set or reset any authentication method (including passwords) for nonadministrators and some roles. For a list of the roles that an Authentication Administrator can read or update authentication methods, see Who can reset passwords.
  • Require users who are nonadministrators or assigned to some roles to re-register against existing nonpassword credentials (for example, MFA or FIDO), and can also revoke remember MFA on the device, which prompts for MFA on the next sign-in.
  • Manage MFA settings in the legacy MFA management portal.
  • Perform sensitive actions for some users. For more information, see Who can perform sensitive actions.
  • Create and manage support tickets in Azure and the Microsoft 365 admin center.

Users with this role cannot do the following:

  • Cannot change the credentials or reset MFA for members and owners of a role-assignable group.
  • Cannot manage Hardware OATH tokens.

The following table compares the capabilities of authentication-related roles.

Role Manage user's auth methods Manage per-user MFA Manage MFA settings Manage auth method policy Manage password protection policy Update sensitive properties Delete and restore users
Authentication Administrator Yes for some users No No No No Yes for some users Yes for some users
Privileged Authentication Administrator Yes for all users No No No No Yes for all users Yes for all users
Authentication Policy Administrator No Yes Yes Yes Yes No No
User Administrator No No No No No Yes for some users Yes for some users

Important

Users with this role can change credentials for people who may have access to sensitive or private information or critical configuration inside and outside of Microsoft Entra ID. Changing the credentials of a user may mean the ability to assume that user's identity and permissions. For example:

  • Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path, an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
  • Azure subscription owners, who may have access to sensitive or private information or critical configuration in Azure.
  • Security Group and Microsoft 365 group owners, who can manage group membership. Those groups may grant access to sensitive or private information or critical configuration in Microsoft Entra ID and elsewhere.
  • Administrators in other services outside of Microsoft Entra ID like Exchange Online, Microsoft Defender XDR portal, Microsoft Purview portal, and human resources systems.
  • Nonadministrators like executives, legal counsel, and human resources employees who may have access to sensitive or private information.
Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/deletedItems.users/restore Restore soft deleted users to original state
microsoft.directory/users/authenticationMethods/basic/update Update basic properties of authentication methods for users
Privileged label icon.
microsoft.directory/users/authenticationMethods/create Update authentication methods for users
Privileged label icon.
microsoft.directory/users/authenticationMethods/delete Delete authentication methods for users
Privileged label icon.
microsoft.directory/users/authenticationMethods/standard/restrictedRead Read standard properties of authentication methods that do not include personally identifiable information for users
microsoft.directory/users/basic/update Update basic properties on users
microsoft.directory/users/delete Delete users
Privileged label icon.
microsoft.directory/users/disable Disable users
Privileged label icon.
microsoft.directory/users/enable Enable users
Privileged label icon.
microsoft.directory/users/invalidateAllRefreshTokens Force sign-out by invalidating user refresh tokens
Privileged label icon.
microsoft.directory/users/manager/update Update manager for users
microsoft.directory/users/password/update Reset passwords for all users
Privileged label icon.
microsoft.directory/users/restore Restore deleted users
microsoft.directory/users/userPrincipalName/update Update User Principal Name of users
Privileged label icon.
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Authentication Extensibility Administrator

Privileged label icon.

This is a privileged role. Assign the Authentication Extensibility Administrator role to users who need to do the following tasks:

  • Create and manage all aspects of custom authentication extensions.

Users with this role can't do the following:

  • Can't assign custom authentication extensions to applications to modify the authentication experiences, and can't consent to application permissions or create app registrations associated with the custom authentication extension. Instead, you must use the Application Administrator, Application Developer, or Cloud Application Administrator roles.

A custom authentication extension is an API endpoint created by a developer for authentication events and is registered in Microsoft Entra ID. Application administrators and application owners can use custom authentication extensions to customize their application's authentication experiences, such as sign in and sign up, or password reset.

Learn more

Actions Description
microsoft.directory/customAuthenticationExtensions/allProperties/allTasks Create and manage custom authentication extensions
Privileged label icon.

Authentication Extensibility Password Administrator

Assign the Authentication Extensibility Password Administrator role to users who need to do the following tasks:

  • Trigger a password submit event for custom authentication to migrate user passwords from an external identity system to Microsoft Entra External ID.
Actions Description
microsoft.directory/onPasswordSubmitCustomAuthenticationExtension/allProperties/allTasks Create and manage custom authentication extensions for onPasswordSubmit events
Privileged label icon.

Authentication Policy Administrator

Assign the Authentication Policy Administrator role to users who need to do the following:

  • Configure the authentication methods policy, tenant-wide MFA settings, and password protection policy that determine which methods each user can register and use.
  • Manage Password Protection settings: smart lockout configurations and updating the custom banned passwords list.
  • Manage MFA settings in the legacy MFA management portal.
  • Create and manage verifiable credentials.
  • Create and manage Azure support tickets.

Users with this role cannot do the following:

The following table compares the capabilities of authentication-related roles.

Role Manage user's auth methods Manage per-user MFA Manage MFA settings Manage auth method policy Manage password protection policy Update sensitive properties Delete and restore users
Authentication Administrator Yes for some users No No No No Yes for some users Yes for some users
Privileged Authentication Administrator Yes for all users No No No No Yes for all users Yes for all users
Authentication Policy Administrator No Yes Yes Yes Yes No No
User Administrator No No No No No Yes for some users Yes for some users
Actions Description
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/organization/strongAuthentication/allTasks Manage all aspects of strong authentication properties of an organization
microsoft.directory/userCredentialPolicies/basic/update Update basic policies for users
microsoft.directory/userCredentialPolicies/create Create credential policies for users
microsoft.directory/userCredentialPolicies/delete Delete credential policies for users
microsoft.directory/userCredentialPolicies/owners/read Read owners of credential policies for users
microsoft.directory/userCredentialPolicies/owners/update Update owners of credential policies for users
microsoft.directory/userCredentialPolicies/policyAppliedTo/read Read policy.appliesTo navigation link
microsoft.directory/userCredentialPolicies/standard/read Read standard properties of credential policies for users
microsoft.directory/userCredentialPolicies/tenantDefault/update Update policy.isOrganizationDefault property
microsoft.directory/verifiableCredentials/configuration/allProperties/read Read configuration required to create and manage verifiable credentials
microsoft.directory/verifiableCredentials/configuration/allProperties/update Update configuration required to create and manage verifiable credentials
microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/read Read a verifiable credential contract
microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/update Update a verifiable credential contract
microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read Read a verifiable credential card
microsoft.directory/verifiableCredentials/configuration/contracts/cards/revoke Revoke a verifiable credential card
microsoft.directory/verifiableCredentials/configuration/contracts/create Create a verifiable credential contract
microsoft.directory/verifiableCredentials/configuration/create Create configuration required to create and manage verifiable credentials
microsoft.directory/verifiableCredentials/configuration/delete Delete configuration required to create and manage verifiable credentials and delete all of its verifiable credentials

Azure DevOps Administrator

Users with this role can manage all enterprise Azure DevOps policies, applicable to all Azure DevOps organizations backed by Microsoft Entra ID. Users in this role can manage these policies by navigating to any Azure DevOps organization that is backed by the company's Microsoft Entra ID. Additionally, users in this role can claim ownership of orphaned Azure DevOps organizations. This role grants no other Azure DevOps-specific permissions (for example, Project Collection Administrators) inside any of the Azure DevOps organizations backed by the company's Microsoft Entra organization.

Actions Description
microsoft.azure.devOps/allEntities/allTasks Read and configure Azure DevOps

Azure Information Protection Administrator

Users with this role have all permissions in the Azure Information Protection service. This role allows configuring labels for the Azure Information Protection policy, managing protection templates, and activating protection. This role doesn't grant any permissions in Microsoft Entra ID Protection, Privileged Identity Management, Monitor Microsoft 365 Service Health, Microsoft Defender XDR portal, or Microsoft Purview portal.

Actions Description
microsoft.azure.informationProtection/allEntities/allTasks Manage all aspects of Azure Information Protection
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/authorizationPolicy/standard/read Read standard properties of authorization policy
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

B2C IEF Keyset Administrator

Privileged label icon.

This is a privileged role. Users assigned to this role can create and manage policy keys and secrets used for token encryption, token signing, and claim encryption/decryption. They can add new keys to existing key containers, enabling secret rollover without affecting existing applications. Additionally, users in this role can view the complete details of these secrets, including their expiration dates, even after creation.

Important

This is a sensitive role. The keyset administrator role should be carefully audited and assigned with care during preproduction and production.

Actions Description
microsoft.directory/b2cTrustFrameworkKeySet/allProperties/allTasks Read and configure key sets in Azure Active Directory B2C
Privileged label icon.

B2C IEF Policy Administrator

Users in this role have the ability to create, read, update, and delete all custom policies in Azure AD B2C and therefore have full control over the Identity Experience Framework in the relevant Azure AD B2C organization. By editing policies, this user can establish direct federation with external identity providers, change the directory schema, change all user-facing content (HTML, CSS, JavaScript), change the requirements to complete an authentication, create new users, send user data to external systems including full migrations, and edit all user information including sensitive fields like passwords and phone numbers. Conversely, this role cannot change the encryption keys or edit the secrets used for federation in the organization.

Important

The B2 IEF Policy Administrator is a highly sensitive role that should be assigned on a very limited basis for organizations in production. Activities by these users should be closely audited, especially for organizations in production.

Actions Description
microsoft.directory/b2cTrustFrameworkPolicy/allProperties/allTasks Read and configure custom policies in Azure Active Directory B2C

Billing Administrator

Makes purchases, manages subscriptions, manages support tickets, and monitors service health.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.commerce.billing/allEntities/allProperties/allTasks Manage all aspects of Office 365 billing
microsoft.directory/organization/basic/update Update basic properties on organization
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Cloud App Security Administrator

Users with this role have full permissions in Defender for Cloud Apps. They can add administrators, add Microsoft Defender for Cloud Apps policies and settings, upload logs, and perform governance actions.

Actions Description
microsoft.directory/cloudAppSecurity/allProperties/allTasks Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Cloud Application Administrator

Privileged label icon.

This is a privileged role. Users in this role have the same permissions as the Application Administrator role, excluding the ability to manage application proxy. This role grants the ability to create and manage all aspects of enterprise applications and application registrations. Users assigned to this role are not added as owners when creating new application registrations or enterprise applications.

This role also grants the ability to consent for delegated permissions and application permissions, with the exception of application permissions for Azure AD Graph and Microsoft Graph.

Important

This exception means that you can still consent to application permissions for other apps (for example, other Microsoft apps, 3rd-party apps, or apps that you have registered). You can still request these permissions as part of the app registration, but granting (that is, consenting to) these permissions requires a more privileged administrator, such as Privileged Role Administrator.

This role grants the ability to manage application credentials. Users assigned this role can add credentials to an application, and use those credentials to impersonate the application's identity. If the application's identity has been granted access to a resource, such as the ability to create or update User or other objects, then a user assigned to this role could perform those actions while impersonating the application. This ability to impersonate the application's identity may be an elevation of privilege over what the user can do via their role assignments. It is important to understand that assigning a user to the Application Administrator role gives them the ability to impersonate an application's identity.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks Manage admin consent request policies in Microsoft Entra ID
microsoft.directory/appConsent/appConsentRequests/allProperties/read Read all properties of consent requests for applications registered with Microsoft Entra ID
microsoft.directory/applicationPolicies/basic/update Update standard properties of application policies
microsoft.directory/applicationPolicies/create Create application policies
microsoft.directory/applicationPolicies/delete Delete application policies
microsoft.directory/applicationPolicies/owners/read Read owners on application policies
microsoft.directory/applicationPolicies/owners/update Update the owner property of application policies
microsoft.directory/applicationPolicies/policyAppliedTo/read Read application policies applied to objects list
microsoft.directory/applicationPolicies/standard/read Read standard properties of application policies
microsoft.directory/applications/appRoles/update Update the appRoles property on all types of applications
microsoft.directory/applications/audience/update Update the audience property for applications
microsoft.directory/applications/authentication/update Update authentication on all types of applications
microsoft.directory/applications/basic/update Update basic properties for applications
microsoft.directory/applications/create Create all types of applications
microsoft.directory/applications/credentials/update Update application credentials
Privileged label icon.
microsoft.directory/applications/delete Delete all types of applications
microsoft.directory/applications/disablement/update Update whether an application is enabled for users to sign in
microsoft.directory/applications/extensionProperties/update Update extension properties on applications
microsoft.directory/applications/notes/update Update notes of applications
microsoft.directory/applications/owners/update Update owners of applications
microsoft.directory/applications/permissions/update Update exposed permissions and required permissions on all types of applications
microsoft.directory/applications/policies/update Update policies of applications
microsoft.directory/applications/synchronization/standard/read Read provisioning settings associated with the application object
microsoft.directory/applications/tag/update Update tags of applications
microsoft.directory/applications/verification/update Update applicationsverification property
microsoft.directory/applicationTemplates/instantiate Instantiate gallery applications from application templates
microsoft.directory/auditLogs/allProperties/read Read all properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/deletedItems.applications/delete Permanently delete applications, which can no longer be restored
microsoft.directory/deletedItems.applications/restore Restore soft deleted applications to original state
microsoft.directory/oAuth2PermissionGrants/allProperties/allTasks Create and delete OAuth 2.0 permission grants, and read and update all properties
Privileged label icon.
microsoft.directory/provisioningLogs/allProperties/read Read all properties of provisioning logs
microsoft.directory/servicePrincipals/appRoleAssignedTo/update Update service principal role assignments
microsoft.directory/servicePrincipals/audience/update Update audience properties on service principals
microsoft.directory/servicePrincipals/authentication/update Update authentication properties on service principals
microsoft.directory/servicePrincipals/basic/update Update basic properties on service principals
microsoft.directory/servicePrincipals/create Create service principals
microsoft.directory/servicePrincipals/credentials/update Update credentials of service principals
Privileged label icon.
microsoft.directory/servicePrincipals/delete Delete service principals
microsoft.directory/servicePrincipals/disable Disable service principals
microsoft.directory/servicePrincipals/enable Enable service principals
microsoft.directory/servicePrincipals/getPasswordSingleSignOnCredentials Manage password single sign-on credentials on service principals
microsoft.directory/servicePrincipals/managePasswordSingleSignOnCredentials Read password single sign-on credentials on service principals
microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-application-admin Grant consent for application permissions and delegated permissions on behalf of any user or all users, except for application permissions for Microsoft Graph and Azure AD Graph
microsoft.directory/servicePrincipals/notes/update Update notes of service principals
microsoft.directory/servicePrincipals/owners/update Update owners of service principals
microsoft.directory/servicePrincipals/permissions/update Update permissions of service principals
microsoft.directory/servicePrincipals/policies/update Update policies of service principals
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/credentials/manage Manage application provisioning secrets and credentials.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/jobs/manage Start, restart, and pause application provisioning synchronization jobs.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/schema/manage Create and manage application provisioning synchronization jobs and schema.
microsoft.directory/servicePrincipals/synchronization/standard/read Read provisioning settings associated with your service principal
microsoft.directory/servicePrincipals/synchronizationCredentials/manage Manage application provisioning secrets and credentials
microsoft.directory/servicePrincipals/synchronizationJobs/manage Start, restart, and pause application provisioning synchronization jobs
microsoft.directory/servicePrincipals/synchronizationSchema/manage Create and manage application provisioning synchronization jobs and schema
microsoft.directory/servicePrincipals/tag/update Update the tag property for service principals
microsoft.directory/signInReports/allProperties/read Read all properties on sign-in reports, including privileged properties
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Cloud Device Administrator

Privileged label icon.

This is a privileged role. Users in this role can enable, disable, and delete devices in Microsoft Entra ID and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.directory/auditLogs/allProperties/read Read all properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/authorizationPolicy/standard/read Read standard properties of authorization policy
microsoft.directory/bitlockerKeys/key/read Read bitlocker metadata and key on devices
Privileged label icon.
microsoft.directory/deletedItems.devices/delete Permanently delete devices, which can no longer be restored
microsoft.directory/deletedItems.devices/restore Restore soft deleted devices to original state
microsoft.directory/deviceLocalCredentials/password/read Read all properties of the backed up local administrator account credentials for Microsoft Entra joined devices, including the password
microsoft.directory/deviceManagementPolicies/basic/update Update basic properties on mobile device management and mobile app management policies
Privileged label icon.
microsoft.directory/deviceManagementPolicies/standard/read Read standard properties on mobile device management and mobile app management policies
microsoft.directory/deviceRegistrationPolicy/basic/update Update basic properties on device registration policies
Privileged label icon.
microsoft.directory/deviceRegistrationPolicy/standard/read Read standard properties on device registration policies
microsoft.directory/devices/delete Delete devices from Microsoft Entra ID
microsoft.directory/devices/disable Disable devices in Microsoft Entra ID
microsoft.directory/devices/enable Enable devices in Microsoft Entra ID
microsoft.directory/devices/permissions/update Update the alternative name property on an IoT device
microsoft.directory/deviceTemplates/owners/read Read owners on Internet of Things (IoT) device templates
microsoft.directory/deviceTemplates/owners/update Update owners on Internet of Things (IoT) device templates
microsoft.directory/signInReports/allProperties/read Read all properties on sign-in reports, including privileged properties
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center

Compliance Administrator

Users with this role have permissions to manage compliance-related features in the Microsoft Purview portal, Microsoft 365 admin center, Azure, and Microsoft Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview.

In Can do
Microsoft Purview portal Protect and manage your organization's data across Microsoft 365 services
Manage compliance alerts
Microsoft Purview Compliance Manager Track, assign, and verify your organization's regulatory compliance activities
Microsoft Defender portal Manage data governance
Perform legal and data investigation
Manage Data Subject Request

This role has the same permissions as the Compliance Administrator role group in Microsoft Defender portal role-based access control.
Intune View all Intune audit data
Microsoft Defender for Cloud Apps Has read-only permissions and can manage alerts
Can create and modify file policies and allow file governance actions
Can view all the built-in reports under Data Management
Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/entitlementManagement/allProperties/read Read all properties in Microsoft Entra entitlement management
microsoft.office365.complianceManager/allEntities/allTasks Manage all aspects of Office 365 Compliance Manager
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Compliance Data Administrator

Users with this role have permissions to track data in the Microsoft Purview portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance.

In Can do
Microsoft Purview portal Monitor compliance-related policies across Microsoft 365 services
Manage compliance alerts
Microsoft Purview Compliance Manager Track, assign, and verify your organization's regulatory compliance activities
Microsoft 365 Defender portal Manage data governance
Perform legal and data investigation
Manage Data Subject Request

This role has the same permissions as the Compliance Data Administrator role group in Microsoft 365 Defender portal role-based access control.
Intune View all Intune audit data
Microsoft Defender for Cloud Apps Has read-only permissions and can manage alerts
Can create and modify file policies and allow file governance actions
Can view all the built-in reports under Data Management
Actions Description
microsoft.azure.informationProtection/allEntities/allTasks Manage all aspects of Azure Information Protection
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/authorizationPolicy/standard/read Read standard properties of authorization policy
microsoft.directory/cloudAppSecurity/allProperties/allTasks Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps
microsoft.office365.complianceManager/allEntities/allTasks Manage all aspects of Office 365 Compliance Manager
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Conditional Access Administrator

Privileged label icon.

This is a privileged role. Users with this role have the ability to manage Microsoft Entra Conditional Access settings.

Actions Description
microsoft.directory/conditionalAccessPolicies/basic/update Update basic properties for Conditional Access policies
microsoft.directory/conditionalAccessPolicies/create Create Conditional Access policies
microsoft.directory/conditionalAccessPolicies/delete Delete Conditional Access policies
microsoft.directory/conditionalAccessPolicies/owners/read Read the owners of Conditional Access policies
microsoft.directory/conditionalAccessPolicies/owners/update Update owners for Conditional Access policies
microsoft.directory/conditionalAccessPolicies/policyAppliedTo/read Read the "applied to" property for Conditional Access policies
microsoft.directory/conditionalAccessPolicies/standard/read Read Conditional Access for policies
microsoft.directory/conditionalAccessPolicies/tenantDefault/update Update the default tenant for Conditional Access policies
microsoft.directory/namedLocations/basic/update Update basic properties of custom rules that define network locations
microsoft.directory/namedLocations/create Create custom rules that define network locations
microsoft.directory/namedLocations/delete Delete custom rules that define network locations
microsoft.directory/namedLocations/standard/read Read basic properties of custom rules that define network locations
microsoft.directory/resourceNamespaces/resourceActions/authenticationContext/update Update Conditional Access authentication context of Microsoft 365 role-based access control (RBAC) resource actions
Privileged label icon.

Customer Delegated Admin Relationship Administrator

Assign the Customer Delegated Admin Relationship Administrator role to users who need to do the following tasks:

  • Accept a granular delegated admin privileges (GDAP) relationship from a partner for their tenant.
  • List and view GDAP relationships with partners.
  • Terminate a GDAP relationship with a partner.
Actions Description
microsoft.commerce.tenantRelationships/customerDelegatedAdminPrivileges/allProperties/allTasks Manage all aspects of granular delegated admin privileges (GDAP) relationships in a customer tenant.
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Customer Lockbox Access Approver

Manages Microsoft Purview Customer Lockbox requests in your organization. They receive email notifications for Customer Lockbox requests and can approve and deny requests from the Microsoft 365 admin center. They can also turn the Customer Lockbox feature on or off. Only Global Administrators can reset the passwords of people assigned to this role.

Actions Description
microsoft.office365.lockbox/allEntities/allTasks Manage all aspects of Customer Lockbox
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Desktop Analytics Administrator

Users in this role can manage the Desktop Analytics service. This includes the ability to view asset inventory, create deployment plans, and view deployment and health status.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.directory/authorizationPolicy/standard/read Read standard properties of authorization policy
microsoft.office365.desktopAnalytics/allEntities/allTasks Manage all aspects of Desktop Analytics

Directory Readers

Users in this role can read basic directory information. This role should be used for:

  • Granting a specific set of guest users read access instead of granting it to all guest users.
  • Granting a specific set of non-admin users access to Microsoft Entra admin center when "Restrict access to Microsoft Entra admin center" is set to "Yes".
  • Granting service principals access to directory where Directory.Read.All is not an option.
Actions Description
microsoft.directory/administrativeUnits/members/read Read members of administrative units
microsoft.directory/administrativeUnits/standard/read Read basic properties on administrative units
microsoft.directory/applicationPolicies/standard/read Read standard properties of application policies
microsoft.directory/applications/owners/read Read owners of applications
microsoft.directory/applications/policies/read Read policies of applications
microsoft.directory/applications/standard/read Read standard properties of applications
microsoft.directory/contacts/memberOf/read Read the group membership for all contacts in Microsoft Entra ID
microsoft.directory/contacts/standard/read Read basic properties on contacts in Microsoft Entra ID
microsoft.directory/contracts/standard/read Read basic properties on partner contracts
microsoft.directory/devices/memberOf/read Read device memberships
microsoft.directory/devices/registeredOwners/read Read registered owners of devices
microsoft.directory/devices/registeredUsers/read Read registered users of devices
microsoft.directory/devices/standard/read Read basic properties on devices
microsoft.directory/directoryRoles/eligibleMembers/read Read the eligible members of Microsoft Entra roles
microsoft.directory/directoryRoles/members/read Read all members of Microsoft Entra roles
microsoft.directory/directoryRoles/standard/read Read basic properties of Microsoft Entra roles
microsoft.directory/domains/standard/read Read basic properties on domains
microsoft.directory/groups/appRoleAssignments/read Read application role assignments of groups
microsoft.directory/groups/memberOf/read Read the memberOf property on Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groups/members/read Read members of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groups/owners/read Read owners of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groups/settings/read Read settings of groups
microsoft.directory/groups/standard/read Read standard properties of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/groupSettings/standard/read Read basic properties on group settings
microsoft.directory/groupSettingTemplates/standard/read Read basic properties on group setting templates
microsoft.directory/oAuth2PermissionGrants/standard/read Read basic properties on OAuth 2.0 permission grants
microsoft.directory/organization/standard/read Read basic properties on an organization
microsoft.directory/organization/trustedCAsForPasswordlessAuth/read Read trusted certificate authorities for passwordless authentication
microsoft.directory/roleAssignments/standard/read Read basic properties on role assignments
microsoft.directory/roleDefinitions/standard/read Read basic properties on role definitions
microsoft.directory/servicePrincipals/appRoleAssignedTo/read Read service principal role assignments
microsoft.directory/servicePrincipals/appRoleAssignments/read Read role assignments assigned to service principals
microsoft.directory/servicePrincipals/memberOf/read Read the group memberships on service principals
microsoft.directory/servicePrincipals/oAuth2PermissionGrants/read Read delegated permission grants on service principals
microsoft.directory/servicePrincipals/ownedObjects/read Read owned objects of service principals
microsoft.directory/servicePrincipals/owners/read Read owners of service principals
microsoft.directory/servicePrincipals/policies/read Read policies of service principals
microsoft.directory/servicePrincipals/standard/read Read basic properties of service principals
microsoft.directory/subscribedSkus/standard/read Read basic properties on subscriptions
microsoft.directory/users/appRoleAssignments/read Read application role assignments for users
microsoft.directory/users/deviceForResourceAccount/read Read deviceForResourceAccount of users
microsoft.directory/users/directReports/read Read the direct reports for users
microsoft.directory/users/invitedBy/read Read the user that invited an external user to a tenant
microsoft.directory/users/licenseDetails/read Read license details of users
microsoft.directory/users/manager/read Read manager of users
microsoft.directory/users/memberOf/read Read the group memberships of users
microsoft.directory/users/oAuth2PermissionGrants/read Read delegated permission grants on users
microsoft.directory/users/ownedDevices/read Read owned devices of users
microsoft.directory/users/ownedObjects/read Read owned objects of users
microsoft.directory/users/photo/read Read photo of users
microsoft.directory/users/registeredDevices/read Read registered devices of users
microsoft.directory/users/scopedRoleMemberOf/read Read user's membership of a Microsoft Entra role, that is scoped to an administrative unit
microsoft.directory/users/sponsorOf/read Read all the agents or applications the user is sponsor of
microsoft.directory/users/sponsors/read Read sponsors of users
microsoft.directory/users/standard/read Read basic properties on users

Directory Synchronization Accounts

Do not use. This role is automatically assigned to the Microsoft Entra Connect service, and is not intended or supported for any other use.

Actions Description
microsoft.directory/onPremisesSynchronization/standard/read Read standard on-premises directory synchronization information

Directory Writers

Privileged label icon.

This is a privileged role. Users in this role can read and update basic information of users, groups, and service principals.

Actions Description
microsoft.directory/applications/extensionProperties/update Update extension properties on applications
microsoft.directory/contacts/create Create contacts
microsoft.directory/groups/assignedLabels/update Update the assigned labels property on groups of assigned membership type, excluding role-assignable groups
microsoft.directory/groups/assignLicense Assign product licenses to groups for group-based licensing
microsoft.directory/groups/basic/update Update basic properties on Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/classification/update Update the classification property on Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/create Create Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/dynamicMembershipRule/update Update the dynamic membership rule on Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/groupType/update Update properties that would affect the group type of Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/members/update Update members of Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/onPremWriteBack/update Update Microsoft Entra groups to be written back to on-premises with Microsoft Entra Connect
microsoft.directory/groups/owners/update Update owners of Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups/reprocessLicenseAssignment Reprocess license assignments for group-based licensing
microsoft.directory/groups/settings/update Update settings of groups
microsoft.directory/groups/visibility/update Update the visibility property of Security groups and Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groupSettings/basic/update Update basic properties on group settings
microsoft.directory/groupSettings/create Create group settings
microsoft.directory/groupSettings/delete Delete group settings
microsoft.directory/oAuth2PermissionGrants/basic/update Update OAuth 2.0 permission grants
Privileged label icon.
microsoft.directory/oAuth2PermissionGrants/create Create OAuth 2.0 permission grants
Privileged label icon.
microsoft.directory/servicePrincipals/appRoleAssignedTo/update Update service principal role assignments
microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/credentials/manage Manage cloud tenant to cloud tenant application provisioning secrets and credentials.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/jobs/manage Start, restart, and pause cloud tenant to cloud tenant application provisioning synchronization jobs.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/schema/manage Create and manage cloud tenant to cloud tenant application provisioning synchronization jobs and schema.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/credentials/manage Manage application provisioning secrets and credentials.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/jobs/manage Start, restart, and pause application provisioning synchronization jobs.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/schema/manage Create and manage application provisioning synchronization jobs and schema.
microsoft.directory/servicePrincipals/synchronizationCredentials/manage Manage application provisioning secrets and credentials
microsoft.directory/servicePrincipals/synchronizationJobs/manage Start, restart, and pause application provisioning synchronization jobs
microsoft.directory/servicePrincipals/synchronizationSchema/manage Create and manage application provisioning synchronization jobs and schema
microsoft.directory/users/assignLicense Manage user licenses
microsoft.directory/users/basic/update Update basic properties on users
microsoft.directory/users/create Add users
Privileged label icon.
microsoft.directory/users/disable Disable users
Privileged label icon.
microsoft.directory/users/enable Enable users
Privileged label icon.
microsoft.directory/users/invalidateAllRefreshTokens Force sign-out by invalidating user refresh tokens
Privileged label icon.
microsoft.directory/users/inviteGuest Invite guest users
microsoft.directory/users/manager/update Update manager for users
microsoft.directory/users/photo/update Update photo of users
microsoft.directory/users/reprocessLicenseAssignment Reprocess license assignments for users
microsoft.directory/users/sponsors/update Update sponsors of users
microsoft.directory/users/userPrincipalName/update Update User Principal Name of users
Privileged label icon.

Domain Name Administrator

Privileged label icon.

This is a privileged role. Users with this role can manage (read, add, verify, update, and delete) domain names. They can also read directory information about users, groups, and applications, as these objects possess domain dependencies. For on-premises environments, users with this role can configure domain names for federation so that associated users are always authenticated on-premises. These users can then sign into Microsoft Entra based services with their on-premises passwords via single sign-on. Federation settings need to be synced via Microsoft Entra Connect, so users also have permissions to manage Microsoft Entra Connect.

Actions Description
microsoft.directory/domains/allProperties/allTasks Create and delete domains, and read and update all properties
Privileged label icon.
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Dragon Administrator

Assign the Dragon Administrator role to users who need to do the following tasks:

  • Manage all aspects of the administrative experience in the Dragon admin center
  • Provision clinical applications
  • Create and manage the organization hierarchy
  • Oversee healthcare groups
  • Manage experiences of various clinical applications embedded in Electronic Health Record (EHR) systems
  • Configure clinical applications, such as manage settings, view analytics, and handle library objects
  • Create, manage, and view support tickets for their organization in the Dragon admin center
  • Create, view, manage, and monitor billing plans for licenses purchased by their organization (additional roles may be required)

Learn more

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.healthPlatform/allEntities/allProperties/allTasks Manage all aspects of Microsoft Dragon admin center
microsoft.office365.network/performance/allProperties/read Read all network performance properties in the Microsoft 365 admin center
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.usageReports/allEntities/allProperties/read Read Office 365 usage reports
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Dynamics 365 Administrator

Assign the Dynamics 365 Administrator role to users who need to manage all aspects of Dynamics 365 services, including configuration, user management, and support tickets.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.dynamics365/allEntities/allTasks Manage all aspects of Dynamics 365
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Dynamics 365 Business Central Administrator

Assign the Dynamics 365 Business Central Administrator role to users who need to do the following tasks:

  • Access Dynamics 365 Business Central environments
  • Perform all administrative tasks on environments
  • Manage the lifecycle of customer's environments
  • Supervise the extensions installed on environments
  • Control upgrades of environments
  • Perform data exports of environments
  • Read and configure Azure and Microsoft 365 service health dashboards

This role does not provide any permissions for other Dynamics 365 products.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.directory/domains/standard/read Read basic properties on domains
microsoft.directory/organization/standard/read Read basic properties on an organization
microsoft.directory/subscribedSkus/standard/read Read basic properties on subscriptions
microsoft.directory/users/standard/read Read basic properties on users
microsoft.dynamics365.businessCentral/allEntities/allProperties/allTasks Manage all aspects of Dynamics 365 Business Central
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Edge Administrator

Users in this role can create and manage the enterprise site list required for Internet Explorer mode on Microsoft Edge. This role grants permissions to create, edit, and publish the site list and additionally allows access to manage support tickets.

Learn more

Actions Description
microsoft.edge/allEntities/allProperties/allTasks Manage all aspects of Microsoft Edge
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Entra Backup Administrator

Assign the Entra Backup Administrator role to users who need to do the following tasks:

  • List all the snapshots in a tenant
  • Create a difference report (preview job) of a backup in the past and optionally include scoping filters
  • Compare states of changed directory objects that are in backup and recovery scope
  • Filter directory objects with supported scoping filters
  • Read status of a job
  • List all the jobs including preview and recovery jobs
  • Trigger recovery jobs and optionally include scoping filters
Actions Description
microsoft.directory/auditLogs/standard/read Read standard properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/backup/preview/cancel Cancel a Microsoft Entra backup operation to compare a backup snapshot with the current state.
microsoft.directory/backup/preview/create Create a Microsoft Entra backup operation that allows a user to compare a backup snapshot with the current state.
microsoft.directory/backup/recovery/cancel Cancel a Microsoft Entra recovery operation to recover the contents of a backup snapshot
microsoft.directory/backup/recovery/create Create a Microsoft Entra recovery operation that allows a user to recover the contents of a backup snapshot.
microsoft.directory/backup/standard/read List Microsoft Entra backups (for example, backup IDs and timestamps), view difference reports, and list recovery jobs and their associated properties.

Entra Backup Reader

Assign the Entra Backup Reader role to users who need to do the following tasks:

  • List all the snapshots in a tenant
  • Create a difference report (preview job) of a backup in the past and optionally include scoping filters
  • Compare states of changed directory objects that are in backup and recovery scope
  • Filter directory objects with supported scoping filters
  • Read status of a job
  • View all the jobs including preview and recovery jobs
Actions Description
microsoft.directory/auditLogs/standard/read Read standard properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/backup/preview/cancel Cancel a Microsoft Entra backup operation to compare a backup snapshot with the current state.
microsoft.directory/backup/preview/create Create a Microsoft Entra backup operation that allows a user to compare a backup snapshot with the current state.
microsoft.directory/backup/standard/read List Microsoft Entra backups (for example, backup IDs and timestamps), view difference reports, and list recovery jobs and their associated properties.

Exchange Administrator

Users with this role have global permissions within Microsoft Exchange Online, when the service is present. Also has the ability to create and manage all Microsoft 365 groups, manage support tickets, and monitor service health. For more information, see About admin roles in the Microsoft 365 admin center.

Note

In the Microsoft Graph API and Microsoft Graph PowerShell, this role is named Exchange Service Administrator. In the Azure portal, it is named Exchange Administrator. In the Exchange admin center, it is named Exchange Online administrator.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.backup/exchangeProtectionPolicies/allProperties/allTasks Create and manage Exchange Online protection policy in Microsoft 365 Backup
microsoft.backup/exchangeRestoreSessions/allProperties/allTasks Read and configure restore session for Exchange Online in Microsoft 365 Backup
microsoft.backup/restorePoints/userMailboxes/allProperties/allTasks Manage all restore points associated with selected Exchange Online mailboxes in M365 Backup
microsoft.backup/userMailboxProtectionUnits/allProperties/allTasks Manage mailboxes added to Exchange Online protection policy in Microsoft 365 Backup
microsoft.backup/userMailboxRestoreArtifacts/allProperties/allTasks Manage mailboxes added to restore session for Exchange Online in Microsoft 365 Backup
microsoft.directory/contacts/allProperties/read Read all properties for contacts
microsoft.directory/contacts/memberOf/read Read the group membership for all contacts in Microsoft Entra ID
microsoft.directory/contacts/standard/read Read basic properties on contacts in Microsoft Entra ID
microsoft.directory/groups.unified/assignedLabels/update Update the assigned labels property on Microsoft 365 groups of assigned membership type, excluding role-assignable groups
microsoft.directory/groups.unified/basic/update Update basic properties on Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups.unified/create Create Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups.unified/delete Delete Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups.unified/members/update Update members of Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups.unified/owners/update Update owners of Microsoft 365 groups, excluding role-assignable groups
microsoft.directory/groups.unified/restore Restore Microsoft 365 groups from soft-deleted container, excluding role-assignable groups
microsoft.directory/groups/hiddenMembers/read Read hidden members of Security groups and Microsoft 365 groups, including role-assignable groups
microsoft.directory/onPremisesSynchronization/standard/read Read standard on-premises directory synchronization information
microsoft.office365.exchange/allEntities/basic/allTasks Manage all aspects of Exchange Online
microsoft.office365.network/performance/allProperties/read Read all network performance properties in the Microsoft 365 admin center
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.usageReports/allEntities/allProperties/read Read Office 365 usage reports
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Exchange Backup Administrator

Assign the Exchange Backup Administrator role to users who need to do the following tasks:

  • Manage all aspects of Microsoft 365 Backup for Exchange Online
  • Back up and restore content including granular restore for Exchange Online
  • Create, edit, and manage backup configuration policies for Exchange Online
  • Perform restore operations for Exchange Online
Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.backup/exchangeProtectionPolicies/allProperties/allTasks Create and manage Exchange Online protection policy in Microsoft 365 Backup
microsoft.backup/exchangeRestoreSessions/allProperties/allTasks Read and configure restore session for Exchange Online in Microsoft 365 Backup
microsoft.backup/restorePoints/userMailboxes/allProperties/allTasks Manage all restore points associated with selected Exchange Online mailboxes in M365 Backup
microsoft.backup/userMailboxProtectionUnits/allProperties/allTasks Manage mailboxes added to Exchange Online protection policy in Microsoft 365 Backup
microsoft.backup/userMailboxRestoreArtifacts/allProperties/allTasks Manage mailboxes added to restore session for Exchange Online in Microsoft 365 Backup
microsoft.office365.network/performance/allProperties/read Read all network performance properties in the Microsoft 365 admin center
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.usageReports/allEntities/allProperties/read Read Office 365 usage reports
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center

Exchange Recipient Administrator

Users with this role have read access to recipients and write access to the attributes of those recipients in Exchange Online. For more information, see Recipients in Exchange Server.

Actions Description
microsoft.office365.exchange/migration/allProperties/allTasks Manage all tasks related to migration of recipients in Exchange Online
microsoft.office365.exchange/recipients/allProperties/allTasks Create and delete all recipients, and read and update all properties of recipients in Exchange Online

Extended Directory User Administrator

Actions Description
microsoft.directory/externalUserProfiles/basic/update Update basic properties of external user profiles in the extended directory for Teams
microsoft.directory/externalUserProfiles/delete Delete external user profiles in the extended directory for Teams
microsoft.directory/externalUserProfiles/standard/read Read standard properties of external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/basic/update Update basic properties of external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/create Create external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/delete Delete external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/standard/read Read standard properties of external user profiles in the extended directory for Teams

External ID User Flow Administrator

Users with this role can create and manage user flows (also called "built-in" policies) in the Azure portal. These users can customize HTML/CSS/JavaScript content, change MFA requirements, select claims in the token, manage API connectors and their credentials, and configure session settings for all user flows in the Microsoft Entra organization. On the other hand, this role does not include the ability to review user data or make changes to the attributes that are included in the organization schema. Changes to Identity Experience Framework policies (also known as custom policies) are also outside the scope of this role.

Actions Description
microsoft.directory/b2cUserFlow/allProperties/allTasks Read and configure user flow in Azure Active Directory B2C

External ID User Flow Attribute Administrator

Users with this role add or delete custom attributes available to all user flows in the Microsoft Entra organization. As such, users with this role can change or add new elements to the end-user schema and impact the behavior of all user flows, and indirectly result in changes to what data may be asked of end users and ultimately sent as claims to applications. This role can't edit user flows.

Actions Description
microsoft.directory/b2cUserAttribute/allProperties/allTasks Read and configure user attribute in Azure Active Directory B2C

External Identity Provider Administrator

Privileged label icon.

This is a privileged role. This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:

  • Microsoft Entra organizations for employees and partners: The addition of a federation (e.g. with Gmail) will immediately impact all guest invitations not yet redeemed. See Adding Google as an identity provider for B2B guest users.
  • Azure Active Directory B2C organizations: The addition of a federation (for example, with Facebook, or with another Microsoft Entra organization) does not immediately impact end-user flows until the identity provider is added as an option in a user flow (also called a built-in policy). See Configuring a Microsoft account as an identity provider for an example. To change user flows, the limited role of "B2C User Flow Administrator" is required.
Actions Description
microsoft.directory/domains/federation/update Update federation property of domains
Privileged label icon.
microsoft.directory/identityProviders/allProperties/allTasks Read and configure identity providers in Azure Active Directory B2C
Privileged label icon.

Fabric Administrator

Users with this role have global permissions within Microsoft Fabric and Power BI, when the service is present, as well as the ability to manage support tickets and monitor service health. For more information, see Understanding Fabric admin roles.

Actions Description
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center
microsoft.powerApps.powerBI/allEntities/allTasks Manage all aspects of Fabric and Power BI

Global Administrator

Privileged label icon.

This is a privileged role. Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft Defender portal, the Microsoft Purview portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can elevate their access to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.

Note

As a best practice, Microsoft recommends that you assign the Global Administrator role to fewer than five people in your organization. For more information, see Best practices for Microsoft Entra roles.

Actions Description
microsoft.agentRegistry/allEntities/allProperties/allTasks Manage all aspects of Agent Registry in Microsoft Entra ID
microsoft.azure.advancedThreatProtection/allEntities/allTasks Manage all aspects of Azure Advanced Threat Protection
microsoft.azure.informationProtection/allEntities/allTasks Manage all aspects of Azure Information Protection
microsoft.azure.serviceHealth/allEntities/allTasks Read and configure Azure Service Health
microsoft.azure.supportTickets/allEntities/allTasks Create and manage Azure support tickets
microsoft.backup/allEntities/allProperties/allTasks Manage all aspects of Microsoft 365 Backup
microsoft.cloudPC/allEntities/allProperties/allTasks Manage all aspects of Windows 365
microsoft.commerce.billing/allEntities/allProperties/allTasks Manage all aspects of Office 365 billing
microsoft.commerce.billing/purchases/standard/read Read purchase services in Microsoft 365 admin center.
microsoft.commerce.tenantRelationships/customerDelegatedAdminPrivileges/allProperties/allTasks Manage all aspects of granular delegated admin privileges (GDAP) relationships in a customer tenant.
microsoft.directory/accessReviews/allProperties/allTasks Create and delete access reviews, and read and update all properties of access reviews in Microsoft Entra ID
microsoft.directory/accessReviews/definitions/allProperties/allTasks Manage access reviews of all reviewable resources in Microsoft Entra ID
microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks Manage admin consent request policies in Microsoft Entra ID
microsoft.directory/administrativeUnits/allProperties/allTasks Create and manage administrative units (including members)
microsoft.directory/agentIdentities/appRoleAssignedTo/update Update agent identity role assignments
microsoft.directory/agentIdentities/authentication/update Update authentication on agent identities
microsoft.directory/agentIdentities/basic/update Update basic properties on agent identities
microsoft.directory/agentIdentities/create Create agent identities
microsoft.directory/agentIdentities/delete Delete agent identities
microsoft.directory/agentIdentities/disable Disable agent identities
microsoft.directory/agentIdentities/enable Enable agent identities
microsoft.directory/agentIdentities/owners/update Update owners on agent identities
microsoft.directory/agentIdentities/tag/update Update tags of agent identities
microsoft.directory/agentIdentityBlueprintPrincipals/appRoleAssignedTo/update Update agent identity blueprint principal role assignments
microsoft.directory/agentIdentityBlueprintPrincipals/authentication/update Update authentication on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/basic/update Update basic properties on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/create Create agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/delete Delete agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/disable Disable agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/enable Enable agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/owners/update Update owners on agent identity blueprint principals
microsoft.directory/agentIdentityBlueprintPrincipals/tag/update Update tags of agent identity blueprint principals
microsoft.directory/agentIdentityBlueprints/allProperties/update Update all properties of agent identity blueprints
Privileged label icon.
microsoft.directory/agentIdentityBlueprints/appRoles/update Update appRoles on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/audience/update Update audience on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/authentication/update Update authentication on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/basic/update Update basic properties on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/create Create agent identity blueprints
microsoft.directory/agentIdentityBlueprints/credentials/update Update credentials on agent identity blueprints
Privileged label icon.
microsoft.directory/agentIdentityBlueprints/delete Delete agent identity blueprints
microsoft.directory/agentIdentityBlueprints/owners/update Update owners on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/permissions/update Update exposed permissions and required permissions on agent identity blueprints
microsoft.directory/agentIdentityBlueprints/tag/update Update tags of agent identity blueprints
microsoft.directory/appConsent/appConsentRequests/allProperties/read Read all properties of consent requests for applications registered with Microsoft Entra ID
microsoft.directory/applications/allProperties/allTasks Create and delete applications, and read and update all properties
Privileged label icon.
microsoft.directory/applications/disablement/update Update whether an application is enabled for users to sign in
microsoft.directory/applications/synchronization/standard/read Read provisioning settings associated with the application object
microsoft.directory/applicationTemplates/instantiate Instantiate gallery applications from application templates
microsoft.directory/auditLogs/allProperties/read Read all properties on audit logs, excluding custom security attributes audit logs
microsoft.directory/authorizationPolicy/allProperties/allTasks Manage all aspects of authorization policy
Privileged label icon.
microsoft.directory/backup/preview/cancel Cancel a Microsoft Entra backup operation to compare a backup snapshot with the current state.
microsoft.directory/backup/preview/create Create a Microsoft Entra backup operation that allows a user to compare a backup snapshot with the current state.
microsoft.directory/backup/recovery/cancel Cancel a Microsoft Entra recovery operation to recover the contents of a backup snapshot
microsoft.directory/backup/recovery/create Create a Microsoft Entra recovery operation that allows a user to recover the contents of a backup snapshot.
microsoft.directory/backup/standard/read List Microsoft Entra backups (for example, backup IDs and timestamps), view difference reports, and list recovery jobs and their associated properties.
microsoft.directory/bitlockerKeys/key/read Read bitlocker metadata and key on devices
Privileged label icon.
microsoft.directory/bulkJobs/basic/update Update all the bulk jobs in a directory
microsoft.directory/bulkJobs/create Create all bulk jobs in a directory
microsoft.directory/cloudAppSecurity/allProperties/allTasks Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps
microsoft.directory/conditionalAccessPolicies/allProperties/allTasks Manage all properties of Conditional Access policies
microsoft.directory/connectorGroups/allProperties/read Read all properties of application proxy connector groups
microsoft.directory/connectorGroups/allProperties/update Update all properties of application proxy connector groups
microsoft.directory/connectorGroups/create Create application proxy connector groups
microsoft.directory/connectorGroups/delete Delete application proxy connector groups
microsoft.directory/connectors/allProperties/read Read all properties of application proxy connectors
microsoft.directory/connectors/create Create application proxy connectors
microsoft.directory/contacts/allProperties/allTasks Create and delete contacts, and read and update all properties
microsoft.directory/contracts/allProperties/allTasks Create and delete partner contracts, and read and update all properties
microsoft.directory/crossTenantAccessPolicy/allowedCloudEndpoints/update Update allowed cloud endpoints of cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/basic/update Update basic settings of cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/default/b2bCollaboration/update Update Microsoft Entra B2B collaboration settings of the default cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/default/b2bDirectConnect/update Update Microsoft Entra B2B direct connect settings of the default cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/default/crossCloudMeetings/update Update cross-cloud Teams meeting settings of the default cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/default/standard/read Read basic properties of the default cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/default/tenantRestrictions/update Update tenant restrictions of the default cross-tenant access policy
microsoft.directory/crossTenantAccessPolicy/partners/b2bCollaboration/update Update Microsoft Entra B2B collaboration settings of cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update Update Microsoft Entra B2B direct connect settings of cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/create Create cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update Update cross-cloud Teams meeting settings of cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/delete Delete cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/identitySynchronization/basic/update Update basic settings of cross-tenant sync policy
microsoft.directory/crossTenantAccessPolicy/partners/identitySynchronization/create Create cross-tenant sync policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/identitySynchronization/standard/read Read basic properties of cross-tenant sync policy
microsoft.directory/crossTenantAccessPolicy/partners/standard/read Read basic properties of cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/basic/update Update cross tenant sync policy templates for multi-tenant organization
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/resetToDefaultSettings Reset cross tenant sync policy template for multi-tenant organization to default settings
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/standard/read Read basic properties of cross tenant sync policy templates for multi-tenant organization
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/basic/update Update cross tenant access policy templates for multi-tenant organization
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/resetToDefaultSettings Reset cross tenant access policy template for multi-tenant organization to default settings
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read Read basic properties of cross tenant access policy templates for multi-tenant organization
microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update Update tenant restrictions of cross-tenant access policy for partners
microsoft.directory/crossTenantAccessPolicy/standard/read Read basic properties of cross-tenant access policy
microsoft.directory/customAuthenticationExtensions/allProperties/allTasks Create and manage custom authentication extensions
Privileged label icon.
microsoft.directory/deletedItems/delete Permanently delete objects, which can no longer be restored
microsoft.directory/deletedItems/restore Restore soft deleted objects to original state
microsoft.directory/deviceLocalCredentials/password/read Read all properties of the backed up local administrator account credentials for Microsoft Entra joined devices, including the password
microsoft.directory/deviceManagementPolicies/basic/update Update basic properties on mobile device management and mobile app management policies
Privileged label icon.
microsoft.directory/deviceManagementPolicies/standard/read Read standard properties on mobile device management and mobile app management policies
microsoft.directory/deviceRegistrationPolicy/basic/update Update basic properties on device registration policies
Privileged label icon.
microsoft.directory/deviceRegistrationPolicy/standard/read Read standard properties on device registration policies
microsoft.directory/devices/allProperties/allTasks Create and delete devices, and read and update all properties
Privileged label icon.
microsoft.directory/devices/permissions/update Update the alternative name property on an IoT device
microsoft.directory/deviceTemplates/owners/read Read owners on Internet of Things (IoT) device templates
microsoft.directory/deviceTemplates/owners/update Update owners on Internet of Things (IoT) device templates
microsoft.directory/directoryRoles/allProperties/allTasks Create and delete directory roles, and read and update all properties
microsoft.directory/directoryRoleTemplates/allProperties/allTasks Create and delete Microsoft Entra role templates, and read and update all properties
microsoft.directory/domains/allProperties/allTasks Create and delete domains, and read and update all properties
Privileged label icon.
microsoft.directory/domains/federationConfiguration/basic/update Update basic federation configuration for domains
microsoft.directory/domains/federationConfiguration/create Create federation configuration for domains
microsoft.directory/domains/federationConfiguration/delete Delete federation configuration for domains
microsoft.directory/domains/federationConfiguration/standard/read Read standard properties of federation configuration for domains
microsoft.directory/entitlementManagement/allProperties/allTasks Create and delete resources, and read and update all properties in Microsoft Entra entitlement management
Privileged label icon.
microsoft.directory/externalUserProfiles/basic/update Update basic properties of external user profiles in the extended directory for Teams
microsoft.directory/externalUserProfiles/delete Delete external user profiles in the extended directory for Teams
microsoft.directory/externalUserProfiles/standard/read Read standard properties of external user profiles in the extended directory for Teams
microsoft.directory/groups/allProperties/allTasks Create and delete groups, and read and update all properties
Privileged label icon.
microsoft.directory/groupsAssignableToRoles/allProperties/update Update role-assignable groups
microsoft.directory/groupsAssignableToRoles/assignLicense Assign a license to role-assignable groups
microsoft.directory/groupsAssignableToRoles/create Create role-assignable groups
microsoft.directory/groupsAssignableToRoles/delete Delete role-assignable groups
microsoft.directory/groupsAssignableToRoles/reprocessLicenseAssignment Reprocess license assignments to role-assignable groups
microsoft.directory/groupsAssignableToRoles/restore Restore role-assignable groups
microsoft.directory/groupSettings/allProperties/allTasks Create and delete group settings, and read and update all properties
microsoft.directory/groupSettingTemplates/allProperties/allTasks Create and delete group setting templates, and read and update all properties
microsoft.directory/hybridAuthenticationPolicy/allProperties/allTasks Manage hybrid authentication policy in Microsoft Entra ID
Privileged label icon.
microsoft.directory/identityProtection/allProperties/allTasks Create and delete all resources, and read and update standard properties in Microsoft Entra ID Protection
Privileged label icon.
microsoft.directory/lifecycleWorkflows/workflows/allProperties/allTasks Manage all aspects of lifecycle workflows and tasks in Microsoft Entra ID
microsoft.directory/loginOrganizationBranding/allProperties/allTasks Create and delete loginTenantBranding, and read and update all properties
microsoft.directory/multiTenantOrganization/basic/update Update basic properties of a multi-tenant organization
microsoft.directory/multiTenantOrganization/create Create a multi-tenant organization
microsoft.directory/multiTenantOrganization/joinRequest/organizationDetails/update Join a multi-tenant organization
microsoft.directory/multiTenantOrganization/joinRequest/standard/read Read properties of a multi-tenant organization join request
microsoft.directory/multiTenantOrganization/standard/read Read basic properties of a multi-tenant organization
microsoft.directory/multiTenantOrganization/tenants/create Create a tenant in a multi-tenant organization
microsoft.directory/multiTenantOrganization/tenants/delete Delete a tenant participating in a multi-tenant organization
microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read Read organization details of a tenant participating in a multi-tenant organization
microsoft.directory/multiTenantOrganization/tenants/organizationDetails/update Update basic properties of a tenant participating in a multi-tenant organization
microsoft.directory/multiTenantOrganization/tenants/standard/read Read basic properties of a tenant participating in a multi-tenant organization
microsoft.directory/namedLocations/basic/update Update basic properties of custom rules that define network locations
microsoft.directory/namedLocations/create Create custom rules that define network locations
microsoft.directory/namedLocations/delete Delete custom rules that define network locations
microsoft.directory/namedLocations/standard/read Read basic properties of custom rules that define network locations
microsoft.directory/oAuth2PermissionGrants/allProperties/allTasks Create and delete OAuth 2.0 permission grants, and read and update all properties
Privileged label icon.
microsoft.directory/onPremisesSynchronization/basic/update Update basic on-premises directory synchronization information
microsoft.directory/onPremisesSynchronization/standard/read Read standard on-premises directory synchronization information
microsoft.directory/organization/allProperties/allTasks Read and update all properties for an organization
microsoft.directory/passwordHashSync/allProperties/allTasks Manage all aspects of Password Hash Synchronization (PHS) in Microsoft Entra ID
microsoft.directory/pendingExternalUserProfiles/basic/update Update basic properties of external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/create Create external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/delete Delete external user profiles in the extended directory for Teams
microsoft.directory/pendingExternalUserProfiles/standard/read Read standard properties of external user profiles in the extended directory for Teams
microsoft.directory/permissionGrantPolicies/basic/update Update basic properties of permission grant policies
microsoft.directory/permissionGrantPolicies/create Create permission grant policies
microsoft.directory/permissionGrantPolicies/delete Delete permission grant policies
microsoft.directory/permissionGrantPolicies/standard/read Read standard properties of permission grant policies
microsoft.directory/policies/allProperties/allTasks Create and delete policies, and read and update all properties
Privileged label icon.
microsoft.directory/privilegedIdentityManagement/allProperties/read Read all resources in Privileged Identity Management
microsoft.directory/provisioningLogs/allProperties/read Read all properties of provisioning logs
microsoft.directory/resourceNamespaces/resourceActions/authenticationContext/update Update Conditional Access authentication context of Microsoft 365 role-based access control (RBAC) resource actions
Privileged label icon.
microsoft.directory/roleAssignments/allProperties/allTasks Create and delete role assignments, and read and update all role assignment properties
microsoft.directory/roleDefinitions/allProperties/allTasks Create and delete role definitions, and read and update all properties
microsoft.directory/scopedRoleMemberships/allProperties/allTasks Create and delete scopedRoleMemberships, and read and update all properties
microsoft.directory/serviceAction/activateService Can perform the "activate service" action for a service
microsoft.directory/serviceAction/disableDirectoryFeature Can perform the "disable directory feature" service action
microsoft.directory/serviceAction/enableDirectoryFeature Can perform the "enable directory feature" service action
microsoft.directory/serviceAction/getAvailableExtentionProperties Can perform the getAvailableExtentionProperties service action
microsoft.directory/servicePrincipalCreationPolicies/basic/update Update basic properties of service principal creation policies
microsoft.directory/servicePrincipalCreationPolicies/create Create service principal creation policies
microsoft.directory/servicePrincipalCreationPolicies/delete Delete service principal creation policies
microsoft.directory/servicePrincipalCreationPolicies/standard/read Read standard properties of service principal creation policies
microsoft.directory/servicePrincipals/allProperties/allTasks Create and delete service principals, and read and update all properties
Privileged label icon.
microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-company-admin Grant consent for any permission to any application
microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/credentials/manage Manage cloud tenant to cloud tenant application provisioning secrets and credentials.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/jobs/manage Start, restart, and pause cloud tenant to cloud tenant application provisioning synchronization jobs.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/schema/manage Create and manage cloud tenant to cloud tenant application provisioning synchronization jobs and schema.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/credentials/manage Manage application provisioning secrets and credentials.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/jobs/manage Start, restart, and pause application provisioning synchronization jobs.
microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/schema/manage Create and manage application provisioning synchronization jobs and schema.
microsoft.directory/servicePrincipals/synchronization/standard/read Read provisioning settings associated with your service principal
microsoft.directory/signInReports/allProperties/read Read all properties on sign-in reports, including privileged properties
microsoft.directory/subscribedSkus/allProperties/allTasks Buy and manage subscriptions and delete subscriptions
microsoft.directory/tenantManagement/tenants/create Create new tenants in Microsoft Entra ID
microsoft.directory/users/allProperties/allTasks Create and delete users, and read and update all properties
Privileged label icon.
microsoft.directory/users/authenticationMethods/basic/update Update basic properties of authentication methods for users
Privileged label icon.
microsoft.directory/users/authenticationMethods/create Update authentication methods for users
Privileged label icon.
microsoft.directory/users/authenticationMethods/delete Delete authentication methods for users
Privileged label icon.
microsoft.directory/users/authenticationMethods/standard/read Read standard properties of authentication methods for users
Privileged label icon.
microsoft.directory/users/convertExternalToInternalMemberUser Convert external user to internal user
microsoft.directory/verifiableCredentials/configuration/allProperties/read Read configuration required to create and manage verifiable credentials
microsoft.directory/verifiableCredentials/configuration/allProperties/update Update configuration required to create and manage verifiable credentials
microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/read Read a verifiable credential contract
microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/update Update a verifiable credential contract
microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read Read a verifiable credential card
microsoft.directory/verifiableCredentials/configuration/contracts/cards/revoke Revoke a verifiable credential card
microsoft.directory/verifiableCredentials/configuration/contracts/create Create a verifiable credential contract
microsoft.directory/verifiableCredentials/configuration/create Create configuration required to create and manage verifiable credentials
microsoft.directory/verifiableCredentials/configuration/delete Delete configuration required to create and manage verifiable credentials and delete all of its verifiable credentials
microsoft.dynamics365/allEntities/allTasks Manage all aspects of Dynamics 365
microsoft.edge/allEntities/allProperties/allTasks Manage all aspects of Microsoft Edge
microsoft.flow/allEntities/allTasks Manage all aspects of Microsoft Power Automate
microsoft.graph.dataConnect/allEntities/allProperties/allTasks Manage aspects of Microsoft Graph Data Connect
microsoft.hardware.support/shippingAddress/allProperties/allTasks Create, read, update, and delete shipping addresses for Microsoft hardware warranty claims, including shipping addresses created by others
microsoft.hardware.support/shippingStatus/allProperties/read Read shipping status for open Microsoft hardware warranty claims
microsoft.hardware.support/warrantyClaims/allProperties/allTasks Create and manage all aspects of Microsoft hardware warranty claims
microsoft.healthPlatform/allEntities/allProperties/allTasks Manage all aspects of Microsoft Dragon admin center
microsoft.insights/allEntities/allProperties/allTasks Manage all aspects of Insights app
microsoft.intune/allEntities/allTasks Manage all aspects of Microsoft Intune
microsoft.microsoft365.organizationalData/allEntities/allProperties/allTasks Manage all aspects of organizational data in Microsoft 365
microsoft.networkAccess/allEntities/allProperties/allTasks Manage all aspects of Microsoft Entra Network Access
microsoft.networkAccess/trafficLogs/standard/read Read standard properties of traffic logs such as DeviceId, DestinationIp and PolicyRuleId
microsoft.office365.complianceManager/allEntities/allTasks Manage all aspects of Office 365 Compliance Manager
microsoft.office365.copilot/allEntities/allProperties/allTasks Create and manage all settings for Microsoft 365 Copilot
microsoft.office365.desktopAnalytics/allEntities/allTasks Manage all aspects of Desktop Analytics
microsoft.office365.exchange/allEntities/basic/allTasks Manage all aspects of Exchange Online
microsoft.office365.fileStorageContainers/allEntities/allProperties/allTasks Manage all aspects of SharePoint Embedded containers
microsoft.office365.knowledge/contentUnderstanding/allProperties/allTasks Read and update all properties of content understanding in Microsoft 365 admin center
microsoft.office365.knowledge/contentUnderstanding/analytics/allProperties/read Read analytics reports of content understanding in Microsoft 365 admin center
microsoft.office365.knowledge/knowledgeNetwork/allProperties/allTasks Read and update all properties of knowledge network in Microsoft 365 admin center
microsoft.office365.knowledge/knowledgeNetwork/topicVisibility/allProperties/allTasks Manage topic visibility of knowledge network in Microsoft 365 admin center
microsoft.office365.knowledge/learningSources/allProperties/allTasks Manage learning sources and all their properties in Learning App.
microsoft.office365.lockbox/allEntities/allTasks Manage all aspects of Customer Lockbox
microsoft.office365.messageCenter/messages/read Read messages in Message Center in the Microsoft 365 admin center, excluding security messages
microsoft.office365.messageCenter/securityMessages/read Read security messages in Message Center in the Microsoft 365 admin center
microsoft.office365.migrations/allEntities/allProperties/allTasks Manage all aspects of Microsoft 365 migrations
microsoft.office365.network/performance/allProperties/read Read all network performance properties in the Microsoft 365 admin center
microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks Manage all authoring aspects of Microsoft 365 Organizational Messages
microsoft.office365.protectionCenter/allEntities/allProperties/allTasks Manage all aspects of the Security and Compliance centers
microsoft.office365.search/content/manage Create and delete content, and read and update all properties in Microsoft Search
microsoft.office365.securityComplianceCenter/allEntities/allTasks Create and delete all resources, and read and update standard properties in the Microsoft 365 Security and Compliance Center
microsoft.office365.serviceHealth/allEntities/allTasks Read and configure Service Health in the Microsoft 365 admin center
microsoft.office365.sharePoint/allEntities/allTasks Create and delete all resources, and read and update standard properties in SharePoint
microsoft.office365.sharePointAdvancedManagement/allEntities/allProperties/allTasks Manage all aspects of SharePoint Advanced Management
microsoft.office365.skypeForBusiness/allEntities/allTasks Manage all aspects of Skype for Business Online
microsoft.office365.supportTickets/allEntities/allTasks Create and manage Microsoft 365 service requests
microsoft.office365.usageReports/allEntities/allProperties/read Read Office 365 usage reports
microsoft.office365.userCommunication/allEntities/allTasks Read and update what's new messages visibility
microsoft.office365.webPortal/allEntities/standard/read Read basic properties on all resources in the Microsoft 365 admin center
microsoft.office365.yammer/allEntities/allProperties/allTasks Manage all aspects of Yammer
microsoft.people/users/photo/read Read profile photo of user
microsoft.people/users/photo/update Update profile photo of user
microsoft.peopleAdmin/organization/allProperties/read Read people settings for users, such as pronouns, name pronunciation, and profile card settings
microsoft.peopleAdmin/organization/allProperties/update Update people settings for users, such as pronouns, name pronunciation, and profile card settings
microsoft.permissionsManagement/allEntities/allProperties/allTasks Manage all aspects of Microsoft Entra Permissions Management
microsoft.powerApps.powerBI/allEntities/allTasks Manage all aspects of Fabric and Power BI
microsoft.powerApps/allEntities/allTasks Manage all aspects of Power Apps
microsoft.teams/allEntities/allProperties/allTasks Manage all resources in Teams
microsoft.virtualVisits/allEntities/allProperties/allTasks Manage and share Virtual Visits information and metrics from admin centers or the Virtual Visits app
microsoft.viva.glint/allEntities/allProperties/allTasks Manage and configure all Microsoft Viva Glint settings in the Microsoft 365 admin center
microsoft.viva.goals/allEntities/allProperties/allTasks Manage all aspects of Microsoft Viva Goals
microsoft.viva.pulse/allEntities/allProperties/allTasks Manage all aspects of Microsoft Viva Pulse
microsoft.windows.defenderAdvancedThreatProtection/allEntities/allTasks Manage all aspects of Microsoft Defender for Endpoint
microsoft.windows.updatesDeployments/allEntities/allProperties/allTasks Read and configure all aspects of Windows Update Service

Global Reader

Privileged label icon.

This is a privileged role. Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft Defender portal, Microsoft Purview portal, Azure portal, and Device Management admin center.

Users with this role cannot do the following:

  • Cannot access the Purchase Services area in the Microsoft 365 admin center.

Note

Global Reader role has the following limitations:

  • OneDrive admin center - OneDrive admin center does not support the Global Reader role
  • Microsoft Defender portal - Global Reader can't do content search or see Secure Score.