You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Create, read, update, and delete password reset user flows | B2C User Flow Administrator |
48
+
Create, read, update, and delete profile editing user flows | B2C User Flow Administrator |
49
+
Create, read, update, and delete sign-in user flows | B2C User Flow Administrator |
50
+
Create, read, update, and delete sign-up user flow |B2C User Flow Administrator |
51
+
Create, read, update, and delete user attributes | B2C User Flow Attribute Administrator |
52
+
Create, read, update, and delete users | User Administrator
53
53
Read all configuration | Global reader |
54
54
Read B2C audit logs | Global reader ([see documentation](https://docs.microsoft.com/azure/active-directory-b2c/active-directory-b2c-faqs)) |
55
55
@@ -124,7 +124,7 @@ Task | Least privileged role | Additional roles
124
124
---- | --------------------- | ----------------
125
125
Consent to any delegated permissions | Cloud application administrator | Application administrator
126
126
Consent to application permissions not including Microsoft Graph | Cloud application administrator | Application administrator
127
-
Consent to application permissions to Microsoft Graph | Global Administrator |
127
+
Consent to application permissions to Microsoft Graph | Privileged Role Administrator |
128
128
Consent to applications accessing own data | Default user role ([see documentation](https://docs.microsoft.com/azure/active-directory/fundamentals/users-default-permissions)) |
@@ -153,7 +153,7 @@ Assign license | User administrator |
153
153
Create group | User administrator |
154
154
Create, update, or delete access review of a group or of an app | User administrator |
155
155
Manage group expiration | User administrator |
156
-
Manage group settings | Global Administrator |
156
+
Manage group settings | Groups Administrator | User Administrator |
157
157
Read all configuration (except hidden membership) | Directory readers | Default user role ([see documentation](https://docs.microsoft.com/azure/active-directory/fundamentals/users-default-permissions))
158
158
Read hidden membership | Group member | Group owner, Password administrator, Exchange administrator, SharePoint administrator, Teams administrator, User administrator
159
159
Read membership of groups with hidden membership | Helpdesk Administrator | User administrator, Teams administrator
@@ -231,7 +231,7 @@ Read server status | Global reader |
231
231
232
232
Task | Least privileged role | Additional roles
233
233
---- | --------------------- | ----------------
234
-
Manage identity providers | Global Administrator |
@@ -327,11 +327,11 @@ Create user | User administrator |
327
327
Delete users | User administrator |
328
328
Invalidate refresh tokens of limited admins (see documentation) | User administrator |
329
329
Invalidate refresh tokens of non-admins (see documentation) | Password administrator | User administrator
330
-
Invalidate refresh tokens of privileged admins (see documentation) | Global Administrator |
330
+
Invalidate refresh tokens of privileged admins (see documentation) | Privileged Authentication Administrator |
331
331
Read basic configuration | Default User role ([see documentation](https://docs.microsoft.com/azure/active-directory/fundamentals/users-default-permissions) |
332
332
Reset password for limited admins (see documentation) | User administrator |
333
333
Reset password of non-admins (see documentation) | Password administrator | User administrator
334
-
Reset password of privileged admins | Global Administrator |
334
+
Reset password of privileged admins | Privileged Authentication Administrator |
335
335
Revoke license | License administrator | User administrator
336
336
Update all properties except User Principal Name | User administrator |
337
337
Update User Principal Name for limited admins (see documentation) | User administrator |
0 commit comments