|
|
|
|
|
|
|
|
Application Administrator
|
Can create and manage all aspects of app registrations and enterprise apps.
|
|
|
|
|
|
Can create application registrations independent of the 'Users can register applications' setting.
|
|
|
|
|
|
Can create attack payloads that an administrator can initiate later.
|
|
|
|
|
Attack Simulation Administrator
|
Can create and manage all aspects of attack simulation campaigns.
|
|
|
|
|
Attribute Assignment Administrator
|
Assign custom security attribute keys and values to supported Microsoft Entra objects.
|
|
|
|
|
Attribute Assignment Reader
|
Read custom security attribute keys and values for supported Microsoft Entra objects.
|
|
|
|
|
Attribute Definition Administrator
|
Define and manage the definition of custom security attributes.
|
|
|
|
|
Attribute Definition Reader
|
Read the definition of custom security attributes.
|
|
|
|
|
Attribute Log Administrator
|
Read audit logs and configure diagnostic settings for events related to custom security attributes.
|
|
|
|
|
|
Read audit logs related to custom security attributes.
|
|
|
|
|
Authentication Administrator
|
Can access to view, set and reset authentication method information for any non-admin user.
|
|
|
|
|
Authentication Extensibility Administrator
|
Customize sign in and sign up experiences for users by creating and managing custom authentication extensions.
|
|
|
|
|
Authentication Policy Administrator
|
Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials.
|
|
|
|
|
Azure DevOps Administrator
|
Can manage Azure DevOps organization policy and settings.
|
|
|
|
|
Azure Information Protection Administrator
|
Can manage all aspects of the Azure Information Protection product.
|
|
|
|
|
B2C IEF Keyset Administrator
|
Can manage secrets for federation and encryption in the Identity Experience Framework (IEF).
|
|
|
|
|
B2C IEF Policy Administrator
|
Can create and manage trust framework policies in the Identity Experience Framework (IEF).
|
|
|
|
|
|
Can perform common billing related tasks like updating payment information.
|
|
|
|
|
Cloud App Security Administrator
|
Can manage all aspects of the Cloud App Security product.
|
|
|
|
|
Cloud Application Administrator
|
Can create and manage all aspects of app registrations and enterprise apps except App Proxy.
|
|
|
|
|
Cloud Device Administrator
|
Limited access to manage devices in Microsoft Entra ID.
|
|
|
|
|
|
Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365.
|
|
|
|
|
Compliance Data Administrator
|
Creates and manages compliance content.
|
|
|
|
|
Conditional Access Administrator
|
Can manage Conditional Access capabilities.
|
|
|
|
|
Customer LockBox Access Approver
|
Can approve Microsoft support requests to access customer organizational data.
|
|
|
|
|
Desktop Analytics Administrator
|
Can access and manage Desktop management tools and services.
|
|
|
|
|
|
Can read basic directory information. Commonly used to grant directory read access to applications and guests.
|
|
|
|
|
|
Can read and write basic directory information. For granting access to applications, not intended for users.
|
|
|
|
|
Domain Name Administrator
|
Can manage domain names in cloud and on-premises.
|
|
|
|
|
Dynamics 365 Administrator
|
Can manage all aspects of the Dynamics 365 product.
|
|
|
|
|
Dynamics 365 Business Central Administrator
|
Access and perform all administrative tasks on Dynamics 365 Business Central environments.
|
|
|
|
|
|
Manage all aspects of Microsoft Edge.
|
|
|
|
|
|
Can manage all aspects of the Exchange product.
|
|
|
|
|
Exchange Recipient Administrator
|
Can create or update Exchange Online recipients within the Exchange Online organization.
|
|
|
|
|
Extended Directory User Administrator
|
Manage all aspects of external user profiles in the extended directory for Teams.
|
|
|
|
|
External ID User Flow Administrator
|
Can create and manage all aspects of user flows.
|
|
|
|
|
External ID User Flow Attribute Administrator
|
Can create and manage the attribute schema available to all user flows.
|
|
|
|
|
External Identity Provider Administrator
|
Can configure identity providers for use in direct federation.
|
|
|
|
|
|
Can manage all aspects of Microsoft Fabric.
|
|
|
|
|
|
Can manage all aspects of Microsoft Entra ID and Microsoft services that use Microsoft Entra identities.
|
|
|
|
|
|
Can read everything that a Global Administrator can, but not update anything.
|
|
|
|
|
Global Secure Access Administrator
|
Create and manage all aspects of Microsoft Entra Internet Access and Microsoft Entra Private Access, including managing access to public and private endpoints.
|
|
|
|
|
|
Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.
|
|
|
|
|
|
Can invite guest users independent of the 'members can invite guests' setting.
|
|
|
|
|
|
Can reset passwords for non-administrators and Helpdesk Administrators.
|
|
|
|
|
Hybrid Identity Administrator
|
Can manage AD to Microsoft Entra cloud provisioning, Microsoft Entra Connect, and federation settings.
|
|
|
|
|
Identity Governance Administrator
|
Manage access using Microsoft Entra ID Governance scenarios.
|
|
|
|
|
|
Has administrative access in the Microsoft 365 Insights app.
|
|
|
|
|
|
Access the analytical capabilities in Microsoft Viva Insights and run custom queries.
|
|
|
|
|
|
Can view and share dashboards and insights via the M365 Insights app.
|
|
|
|
|
|
Can manage all aspects of the Intune product.
|
|
|
|
|
|
Can manage settings for Microsoft Kaizala.
|
|
|
|
|
|
Can configure knowledge, learning, and other intelligent features.
|
|
|
|
|
|
Has access to topic management dashboard and can manage content.
|
|
|
|
|
|
Can manage product licenses on users and groups.
|
|
|
|
|
Lifecycle Workflows Administrator
|
Create and manage all aspects of workflows and tasks associated with Lifecycle Workflows in Microsoft Entra ID.
|
|
|
|
|
Message Center Privacy Reader
|
Can read security messages and updates in Office 365 Message Center only.
|
|
|
|
|
|
Can read messages and updates for their organization in Office 365 Message Center only.
|
|
|
|
|
Microsoft 365 Migration Administrator
|
Perform all migration functionality to migrate content to Microsoft 365 using Migration Manager.
|
|
|
|
|
Microsoft Entra Joined Device Local Administrator
|
Users assigned to this role are added to the local administrators group on Microsoft Entra joined devices.
|
|
|
|
|
Microsoft Hardware Warranty Administrator
|
Create and manage all aspects warranty claims and entitlements for Microsoft manufactured hardware, like Surface and HoloLens.
|
|
|
|
|
Microsoft Hardware Warranty Specialist
|
Create and read warranty claims for Microsoft manufactured hardware, like Surface and HoloLens.
|
|
|
|
|
|
Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications.
|
|
|
|
|
Office Apps Administrator
|
Can manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish 'what's new' feature content to end-user's devices.
|
|
|
|
|
Organizational Branding Administrator
|
Manage all aspects of organizational branding in a tenant.
|
|
|
|
|
Organizational Messages Approver
|
Review, approve, or reject new organizational messages for delivery in the Microsoft 365 admin center before they are sent to users.
|
|
|
|
|
Organizational Messages Writer
|
Write, publish, manage, and review the organizational messages for end-users through Microsoft product surfaces.
|
|
|
|
|
|
Can reset passwords for non-administrators and Password Administrators.
|
|
|
|
|
Permissions Management Administrator
|
Manage all aspects of Entra Permissions Management.
|
|
|
|
|
Power Platform Administrator
|
Can create and manage all aspects of Microsoft Dynamics 365, PowerApps and Microsoft Flow.
|
|
|
|
|
|
Can manage all aspects of printers and printer connectors.
|
|
|
|
|
|
Can register and unregister printers and update printer status.
|
|
|
|
|
Privileged Authentication Administrator
|
Can access to view, set and reset authentication method information for any user (admin or non-admin).
|
|
|
|
|
Privileged Role Administrator
|
Can manage role assignments in Microsoft Entra ID, and all aspects of Privileged Identity Management.
|
|
|
|
|
|
Can read sign-in and audit reports.
|
|
|
|
|
|
Can create and manage all aspects of Microsoft Search settings.
|
|
|
|
|
|
Can create and manage the editorial content such as bookmarks, Q and As, locations, floorplan.
|
|
|
|
|
|
Can read security information and reports, and manage configuration in Microsoft Entra ID and Office 365.
|
|
|
|
|
|
Creates and manages security events.
|
|
|
|
|
|
Can read security information and reports in Microsoft Entra ID and Microsoft 365.
|
|
|
|
|
Service Support Administrator
|
Can read service health information and manage support tickets.
|
|
|
|
|
|
Can manage all aspects of the SharePoint service.
|
|
|
|
|
SharePoint Embedded Administrator
|
Manage all aspects of SharePoint Embedded containers.
|
|
|
|
|
Skype for Business Administrator
|
Can manage all aspects of the Skype for Business product.
|
|
|
|
|
|
Can manage the Microsoft Teams service.
|
|
|
|
|
Teams Communications Administrator
|
Can manage calling and meetings features within the Microsoft Teams service.
|
|
|
|
|
Teams Communications Support Engineer
|
Can troubleshoot communications issues within Teams using advanced tools.
|
|
|
|
|
Teams Communications Support Specialist
|
Can troubleshoot communications issues within Teams using basic tools.
|
|
|
|
|
Teams Devices Administrator
|
Can perform management related tasks on Teams certified devices.
|
|
|
|
|
Teams Telephony Administrator
|
Manage voice and telephony features and troubleshoot communication issues within the Microsoft Teams service.
|
|
|
|
|
|
Create new Microsoft Entra or Azure AD B2C tenants.
|
|
|
|
|
Usage Summary Reports Reader
|
Can see only tenant level aggregates in Microsoft 365 Usage Analytics and Productivity Score.
|
|
|
|
|
|
Can manage all aspects of users and groups, including resetting passwords for limited admins.
|
|
|
|
|
User Experience Success Manager
|
View product feedback, survey results, and reports to find training and communication opportunities.
|
|
|
|
|
Virtual Visits Administrator
|
Manage and share Virtual Visits information and metrics from admin centers or the Virtual Visits app.
|
|
|
|
|
|
Manage and configure all aspects of Microsoft Viva Goals.
|
|
|
|
|
|
Can manage all settings for Microsoft Viva Pulse app.
|
|
|
|
|
Windows 365 Administrator
|
Can provision and manage all aspects of Cloud PCs.
|
|
|
|
|
Windows Update Deployment Administrator
|
Can create and manage all aspects of Windows Update deployments through the Windows Update for Business deployment service.
|
|
|
|
|
|
Manage all aspects of the Yammer service.
|
|
|