Skip to content

Commit 6c83e1a

Browse files
authored
Merge pull request #189189 from rolyon/rolyon-aadroles-roles-feb
[Azure AD roles] Updates to roles and permissions for February
2 parents 972949d + 7776e3e commit 6c83e1a

File tree

1 file changed

+31
-1
lines changed

1 file changed

+31
-1
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 31 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.workload: identity
1010
ms.subservice: roles
1111
ms.topic: reference
12-
ms.date: 01/16/2022
12+
ms.date: 02/18/2022
1313
ms.author: rolyon
1414
ms.reviewer: abhijeetsinha
1515
ms.custom: generated, it-pro, fasttrack-edit
@@ -123,6 +123,8 @@ This role also grants the ability to consent for delegated permissions and appli
123123
> [!div class="mx-tableFixed"]
124124
> | Actions | Description |
125125
> | --- | --- |
126+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Azure AD |
127+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
126128
> | microsoft.directory/applications/create | Create all types of applications |
127129
> | microsoft.directory/applications/delete | Delete all types of applications |
128130
> | microsoft.directory/applications/applicationProxy/read | Read all application proxy properties |
@@ -464,6 +466,8 @@ This role also grants the ability to consent for delegated permissions and appli
464466
> [!div class="mx-tableFixed"]
465467
> | Actions | Description |
466468
> | --- | --- |
469+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Azure AD |
470+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
467471
> | microsoft.directory/applications/create | Create all types of applications |
468472
> | microsoft.directory/applications/delete | Delete all types of applications |
469473
> | microsoft.directory/applications/appRoles/update | Update the appRoles property on all types of applications |
@@ -914,7 +918,10 @@ Users with this role have access to all administrative features in Azure Active
914918
> | Actions | Description |
915919
> | --- | --- |
916920
> | microsoft.directory/accessReviews/allProperties/allTasks | Create and delete access reviews, read and update all properties of access reviews, and manage access reviews of groups in Azure AD |
921+
> | microsoft.directory/accessReviews/definitions/allProperties/allTasks | Manage access reviews of all reviewable resources in Azure AD |
922+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Azure AD |
917923
> | microsoft.directory/administrativeUnits/allProperties/allTasks | Create and manage administrative units (including members) |
924+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
918925
> | microsoft.directory/applications/allProperties/allTasks | Create and delete applications, and read and update all properties |
919926
> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
920927
> | microsoft.directory/applicationTemplates/instantiate | Instantiate gallery applications from application templates |
@@ -1056,7 +1063,10 @@ Users in this role can read settings and administrative information across Micro
10561063
> | Actions | Description |
10571064
> | --- | --- |
10581065
> | microsoft.directory/accessReviews/allProperties/read | Read all properties of access reviews |
1066+
> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Azure AD |
1067+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/read | Read all properties of admin consent request policies in Azure AD |
10591068
> | microsoft.directory/administrativeUnits/allProperties/read | Read all properties of administrative units, including members |
1069+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
10601070
> | microsoft.directory/applications/allProperties/read | Read all properties (including privileged properties) on all types of applications |
10611071
> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
10621072
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
@@ -1259,6 +1269,12 @@ Users with this role can manage Azure AD identity governance configuration, incl
12591269
> [!div class="mx-tableFixed"]
12601270
> | Actions | Description |
12611271
> | --- | --- |
1272+
> | microsoft.directory/accessReviews/definitions.applications/allProperties/allTasks | Manage access reviews of application role assignments in Azure AD |
1273+
> | microsoft.directory/accessReviews/definitions.entitlementManagement/allProperties/allTasks | Manage access reviews for access package assignments in entitlement management |
1274+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/read | Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
1275+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/update | Update all properties of access reviews for membership in Security and Microsoft 365 groups, excluding role-assignable groups. |
1276+
> | microsoft.directory/accessReviews/definitions.groups/create | Create access reviews for membership in Security and Microsoft 365 groups. |
1277+
> | microsoft.directory/accessReviews/definitions.groups/delete | Delete access reviews for membership in Security and Microsoft 365 groups. |
12621278
> | microsoft.directory/accessReviews/allProperties/allTasks | Create and delete access reviews, read and update all properties of access reviews, and manage access reviews of groups in Azure AD |
12631279
> | microsoft.directory/entitlementManagement/allProperties/allTasks | Create and delete resources, and read and update all properties in Azure AD entitlement management |
12641280
> | microsoft.directory/groups/members/update | Update members of Security groups and Microsoft 365 groups, excluding role-assignable groups |
@@ -1696,6 +1712,12 @@ Users with this role can manage role assignments in Azure Active Directory, as w
16961712
> [!div class="mx-tableFixed"]
16971713
> | Actions | Description |
16981714
> | --- | --- |
1715+
> | microsoft.directory/accessReviews/definitions.applications/allProperties/read | Read all properties of access reviews of application role assignments in Azure AD |
1716+
> | microsoft.directory/accessReviews/definitions.directoryRoles/allProperties/allTasks | Manage access reviews for Azure AD role assignments |
1717+
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/allProperties/update | Update all properties of access reviews for membership in groups that are assignable to Azure AD roles |
1718+
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Azure AD roles |
1719+
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/delete | Delete access reviews for membership in groups that are assignable to Azure AD roles |
1720+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/read | Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
16991721
> | microsoft.directory/administrativeUnits/allProperties/allTasks | Create and manage administrative units (including members) |
17001722
> | microsoft.directory/authorizationPolicy/allProperties/allTasks | Manage all aspects of authorization policies |
17011723
> | microsoft.directory/directoryRoles/allProperties/allTasks | Create and delete directory roles, and read and update all properties |
@@ -1868,6 +1890,7 @@ Identity Protection Center | Read all security reports and settings information
18681890
> [!div class="mx-tableFixed"]
18691891
> | Actions | Description |
18701892
> | --- | --- |
1893+
> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Azure AD |
18711894
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
18721895
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policies |
18731896
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
@@ -2070,6 +2093,13 @@ Users with this role can create users, and manage all aspects of users with some
20702093
> [!div class="mx-tableFixed"]
20712094
> | Actions | Description |
20722095
> | --- | --- |
2096+
> | microsoft.directory/accessReviews/definitions.applications/allProperties/allTasks | Manage access reviews of application role assignments in Azure AD |
2097+
> | microsoft.directory/accessReviews/definitions.directoryRoles/allProperties/read | Read all properties of access reviews for Azure AD role assignments |
2098+
> | microsoft.directory/accessReviews/definitions.entitlementManagement/allProperties/allTasks | Manage access reviews for access package assignments in entitlement management |
2099+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/update | Update all properties of access reviews for membership in Security and Microsoft 365 groups, excluding role-assignable groups. |
2100+
> | microsoft.directory/accessReviews/definitions.groups/create | Create access reviews for membership in Security and Microsoft 365 groups. |
2101+
> | microsoft.directory/accessReviews/definitions.groups/delete | Delete access reviews for membership in Security and Microsoft 365 groups. |
2102+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/read | Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
20732103
> | microsoft.directory/contacts/create | Create contacts |
20742104
> | microsoft.directory/contacts/delete | Delete contacts |
20752105
> | microsoft.directory/contacts/basic/update | Update basic properties on contacts |

0 commit comments

Comments
 (0)