You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+9-1Lines changed: 9 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -317,6 +317,8 @@ The [Authentication Policy Administrator](#authentication-policy-administrator)
317
317
> [!IMPORTANT]
318
318
> This role can't manage MFA settings in the legacy MFA management portal or Hardware OATH tokens. The same functions can be accomplished using the [Set-MsolUser](/powershell/module/msonline/set-msoluser) commandlet Azure AD PowerShell module.
319
319
320
+
Users with this role can't change the credentials or reset MFA for members and owners of a [role-assignable group](groups-concept.md).
321
+
320
322
> [!div class="mx-tableFixed"]
321
323
> | Actions | Description |
322
324
> | --- | --- |
@@ -1205,6 +1207,8 @@ Users with this role can change passwords, invalidate refresh tokens, create and
1205
1207
>- Administrators in other services outside of Azure AD like Exchange Online, Office Security and Compliance Center, and human resources systems.
1206
1208
>- Non-administrators like executives, legal counsel, and human resources employees who may have access to sensitive or private information.
1207
1209
1210
+
Users with this role can't change the credentials or reset MFA for members and owners of a [role-assignable group](groups-concept.md).
1211
+
1208
1212
Delegating administrative permissions over subsets of users and applying policies to a subset of users is possible with [Administrative Units](administrative-units.md).
1209
1213
1210
1214
This role was previously called "Password Administrator" in the [Azure portal](https://portal.azure.com/). The "Helpdesk Administrator" name in Azure AD now matches its name in Azure AD PowerShell and the Microsoft Graph API.
@@ -1612,6 +1616,8 @@ Do not use. This role has been deprecated and will be removed from Azure AD in t
1612
1616
1613
1617
Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Password reset permissions](#password-reset-permissions).
1614
1618
1619
+
Users with this role can't change the credentials or reset MFA for members and owners of a [role-assignable group](groups-concept.md).
1620
+
1615
1621
> [!div class="mx-tableFixed"]
1616
1622
> | Actions | Description |
1617
1623
> | --- | --- |
@@ -2125,6 +2131,8 @@ Users with this role can create users, and manage all aspects of users with some
2125
2131
>- Administrators in other services outside of Azure AD like Exchange Online, Office Security and Compliance Center, and human resources systems.
2126
2132
>- Non-administrators like executives, legal counsel, and human resources employees who may have access to sensitive or private information.
2127
2133
2134
+
Users with this role can't change the credentials or reset MFA for members and owners of a [role-assignable group](groups-concept.md).
0 commit comments