You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+31-1Lines changed: 31 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.workload: identity
10
10
ms.subservice: roles
11
11
ms.topic: reference
12
-
ms.date: 01/16/2022
12
+
ms.date: 02/18/2022
13
13
ms.author: rolyon
14
14
ms.reviewer: abhijeetsinha
15
15
ms.custom: generated, it-pro, fasttrack-edit
@@ -123,6 +123,8 @@ This role also grants the ability to consent for delegated permissions and appli
123
123
> [!div class="mx-tableFixed"]
124
124
> | Actions | Description |
125
125
> | --- | --- |
126
+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Azure AD |
127
+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
126
128
> | microsoft.directory/applications/create | Create all types of applications |
127
129
> | microsoft.directory/applications/delete | Delete all types of applications |
128
130
> | microsoft.directory/applications/applicationProxy/read | Read all application proxy properties |
@@ -464,6 +466,8 @@ This role also grants the ability to consent for delegated permissions and appli
464
466
> [!div class="mx-tableFixed"]
465
467
> | Actions | Description |
466
468
> | --- | --- |
469
+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Azure AD |
470
+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
467
471
> | microsoft.directory/applications/create | Create all types of applications |
468
472
> | microsoft.directory/applications/delete | Delete all types of applications |
469
473
> | microsoft.directory/applications/appRoles/update | Update the appRoles property on all types of applications |
@@ -914,7 +918,10 @@ Users with this role have access to all administrative features in Azure Active
914
918
> | Actions | Description |
915
919
> | --- | --- |
916
920
> | microsoft.directory/accessReviews/allProperties/allTasks | Create and delete access reviews, read and update all properties of access reviews, and manage access reviews of groups in Azure AD |
921
+
> | microsoft.directory/accessReviews/definitions/allProperties/allTasks | Manage access reviews of all reviewable resources in Azure AD |
922
+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Azure AD |
917
923
> | microsoft.directory/administrativeUnits/allProperties/allTasks | Create and manage administrative units (including members) |
924
+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
918
925
> | microsoft.directory/applications/allProperties/allTasks | Create and delete applications, and read and update all properties |
919
926
> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
@@ -1056,7 +1063,10 @@ Users in this role can read settings and administrative information across Micro
1056
1063
> | Actions | Description |
1057
1064
> | --- | --- |
1058
1065
> | microsoft.directory/accessReviews/allProperties/read | Read all properties of access reviews |
1066
+
> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Azure AD |
1067
+
> | microsoft.directory/adminConsentRequestPolicy/allProperties/read | Read all properties of admin consent request policies in Azure AD |
1059
1068
> | microsoft.directory/administrativeUnits/allProperties/read | Read all properties of administrative units, including members |
1069
+
> | microsoft.directory/appConsent/appConsentRequests/allProperties/read | Read all properties of consent requests for applications registered with Azure AD |
1060
1070
> | microsoft.directory/applications/allProperties/read | Read all properties (including privileged properties) on all types of applications |
1061
1071
> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
1062
1072
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
@@ -1259,6 +1269,12 @@ Users with this role can manage Azure AD identity governance configuration, incl
1259
1269
> [!div class="mx-tableFixed"]
1260
1270
> | Actions | Description |
1261
1271
> | --- | --- |
1272
+
> | microsoft.directory/accessReviews/definitions.applications/allProperties/allTasks | Manage access reviews of application role assignments in Azure AD |
1273
+
> | microsoft.directory/accessReviews/definitions.entitlementManagement/allProperties/allTasks | Manage access reviews for access package assignments in entitlement management |
1274
+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/read | Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
1275
+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/update | Update all properties of access reviews for membership in Security and Microsoft 365 groups, excluding role-assignable groups. |
1276
+
> | microsoft.directory/accessReviews/definitions.groups/create | Create access reviews for membership in Security and Microsoft 365 groups. |
1277
+
> | microsoft.directory/accessReviews/definitions.groups/delete | Delete access reviews for membership in Security and Microsoft 365 groups. |
1262
1278
> | microsoft.directory/accessReviews/allProperties/allTasks | Create and delete access reviews, read and update all properties of access reviews, and manage access reviews of groups in Azure AD |
1263
1279
> | microsoft.directory/entitlementManagement/allProperties/allTasks | Create and delete resources, and read and update all properties in Azure AD entitlement management |
1264
1280
> | microsoft.directory/groups/members/update | Update members of Security groups and Microsoft 365 groups, excluding role-assignable groups |
@@ -1696,6 +1712,12 @@ Users with this role can manage role assignments in Azure Active Directory, as w
1696
1712
> [!div class="mx-tableFixed"]
1697
1713
> | Actions | Description |
1698
1714
> | --- | --- |
1715
+
> | microsoft.directory/accessReviews/definitions.applications/allProperties/read | Read all properties of access reviews of application role assignments in Azure AD |
1716
+
> | microsoft.directory/accessReviews/definitions.directoryRoles/allProperties/allTasks | Manage access reviews for Azure AD role assignments |
1717
+
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/allProperties/update | Update all properties of access reviews for membership in groups that are assignable to Azure AD roles |
1718
+
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Azure AD roles |
1719
+
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/delete | Delete access reviews for membership in groups that are assignable to Azure AD roles |
1720
+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/read | Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
1699
1721
> | microsoft.directory/administrativeUnits/allProperties/allTasks | Create and manage administrative units (including members) |
1700
1722
> | microsoft.directory/authorizationPolicy/allProperties/allTasks | Manage all aspects of authorization policies |
1701
1723
> | microsoft.directory/directoryRoles/allProperties/allTasks | Create and delete directory roles, and read and update all properties |
@@ -1868,6 +1890,7 @@ Identity Protection Center | Read all security reports and settings information
1868
1890
> [!div class="mx-tableFixed"]
1869
1891
> | Actions | Description |
1870
1892
> | --- | --- |
1893
+
> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Azure AD |
1871
1894
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
1872
1895
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policies |
1873
1896
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
@@ -2070,6 +2093,13 @@ Users with this role can create users, and manage all aspects of users with some
2070
2093
> [!div class="mx-tableFixed"]
2071
2094
> | Actions | Description |
2072
2095
> | --- | --- |
2096
+
> | microsoft.directory/accessReviews/definitions.applications/allProperties/allTasks | Manage access reviews of application role assignments in Azure AD |
2097
+
> | microsoft.directory/accessReviews/definitions.directoryRoles/allProperties/read | Read all properties of access reviews for Azure AD role assignments |
2098
+
> | microsoft.directory/accessReviews/definitions.entitlementManagement/allProperties/allTasks | Manage access reviews for access package assignments in entitlement management |
2099
+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/update | Update all properties of access reviews for membership in Security and Microsoft 365 groups, excluding role-assignable groups. |
2100
+
> | microsoft.directory/accessReviews/definitions.groups/create | Create access reviews for membership in Security and Microsoft 365 groups. |
2101
+
> | microsoft.directory/accessReviews/definitions.groups/delete | Delete access reviews for membership in Security and Microsoft 365 groups. |
2102
+
> | microsoft.directory/accessReviews/definitions.groups/allProperties/read | Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
0 commit comments