Skip to content

Commit a534e93

Browse files
Merge pull request #227013 from rolyon/rolyon-aadroles-roles-partner-tier
[Azure AD roles] Partner Tier updates
2 parents 9d0d289 + 46004d0 commit a534e93

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -930,7 +930,7 @@ This administrator manages federation between Azure AD organizations and externa
930930
931931
## Global Administrator
932932

933-
Users with this role have access to all administrative features in Azure Active Directory, as well as services that use Azure Active Directory identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Furthermore, Global Administrators can [elevate their access](../../role-based-access-control/elevate-access-global-admin.md) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Azure AD Tenant. The person who signs up for the Azure AD organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators.
933+
Users with this role have access to all administrative features in Azure Active Directory, as well as services that use Azure Active Directory identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Furthermore, Global Administrators can [elevate their access](../../role-based-access-control/elevate-access-global-admin.md) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Azure AD Tenant. The person who signs up for the Azure AD organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
934934

935935
> [!NOTE]
936936
> As a best practice, Microsoft recommends that you assign the Global Administrator role to fewer than five people in your organization. For more information, see [Best practices for Azure AD roles](best-practices.md).
@@ -1663,7 +1663,7 @@ Assign the Organizational Messages Writer role to users who need to do the follo
16631663
Do not use. This role has been deprecated and will be removed from Azure AD in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
16641664

16651665
> [!IMPORTANT]
1666-
> This role can reset passwords and invalidate refresh tokens for only non-administrators. This role should not be used as it is deprecated and it will no longer be returned in API.
1666+
> This role can reset passwords and invalidate refresh tokens for only non-administrators. This role should not be used because it is deprecated.
16671667
16681668
> [!div class="mx-tableFixed"]
16691669
> | Actions | Description |
@@ -1713,7 +1713,7 @@ Do not use. This role has been deprecated and will be removed from Azure AD in t
17131713
Do not use. This role has been deprecated and will be removed from Azure AD in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
17141714

17151715
> [!IMPORTANT]
1716-
> This role can reset passwords and invalidate refresh tokens for all non-administrators and administrators (including Global Administrators). This role should not be used as it is deprecated and it will no longer be returned in API.
1716+
> This role can reset passwords and invalidate refresh tokens for all non-administrators and administrators (including Global Administrators). This role should not be used because it is deprecated.
17171717
17181718
> [!div class="mx-tableFixed"]
17191719
> | Actions | Description |
@@ -2557,13 +2557,13 @@ User Admin |   |   |   | :heavy_check_mark: | :heavy_check_mark:
25572557
Usage Summary Reports Reader |   | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:
25582558
All custom roles | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:
25592559

2560-
\* A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has 0 Global Administrators.
2560+
> [!IMPORTANT]
2561+
> The [Partner Tier2 Support](#partner-tier2-support) role can reset passwords and invalidate refresh tokens for all non-administrators and administrators (including Global Administrators). The [Partner Tier1 Support](#partner-tier1-support) role can reset passwords and invalidate refresh tokens for only non-administrators. These roles should not be used because they are deprecated.
25612562
2562-
> [!NOTE]
2563-
> The ability to reset a password includes the ability to update the following sensitive properties required for [self-service password reset](../authentication/concept-sspr-howitworks.md):
2564-
> - businessPhones
2565-
> - mobilePhone
2566-
> - otherMails
2563+
The ability to reset a password includes the ability to update the following sensitive properties required for [self-service password reset](../authentication/concept-sspr-howitworks.md):
2564+
- businessPhones
2565+
- mobilePhone
2566+
- otherMails
25672567

25682568
## Who can perform sensitive actions
25692569

0 commit comments

Comments
 (0)