@@ -136,7 +136,7 @@ You can further restrict permissions by assigning roles at smaller scopes or by
136
136
> | Disable device | [ Cloud Device Administrator] ( ../roles/permissions-reference.md#cloud-device-administrator ) | |
137
137
> | Enable device | [ Cloud Device Administrator] ( ../roles/permissions-reference.md#cloud-device-administrator ) | |
138
138
> | Read basic configuration | [ Default user role] ( ../fundamentals/users-default-permissions.md ) | |
139
- > | Read BitLocker keys | [ Security Reader] ( ../roles/permissions-reference.md#security-reader ) | [ Password Administrator] ( /roles/permissions-reference.md#password-administrator ) <br />[ Security Administrator] ( ../roles/permissions-reference.md#security-administrator ) |
139
+ > | Read BitLocker keys | [ Security Reader] ( ../roles/permissions-reference.md#security-reader ) | [ Password Administrator] ( .. /roles/permissions-reference.md#password-administrator) <br />[ Security Administrator] ( ../roles/permissions-reference.md#security-administrator ) |
140
140
141
141
## Enterprise applications
142
142
@@ -178,7 +178,7 @@ You can further restrict permissions by assigning roles at smaller scopes or by
178
178
> | Manage group expiration | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) | |
179
179
> | Manage group settings | [ Groups Administrator] ( ../roles/permissions-reference.md#groups-administrator ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
180
180
> | Read all configuration (except hidden membership) | [ Directory Readers] ( ../roles/permissions-reference.md#directory-readers ) | [ Default user role] ( ../fundamentals/users-default-permissions.md ) |
181
- > | Read hidden membership | Group member | [ Group owner] ( ../fundamentals/users-default-permissions.md#object-ownership ) <br />[ Password Administrator] ( /roles/permissions-reference.md#password-administrator ) <br />[ Exchange Administrator] ( ../roles/permissions-reference.md#exchange-administrator ) <br />[ SharePoint Administrator] ( ../roles/permissions-reference.md#sharepoint-administrator ) <br />[ Teams Administrator] ( ../roles/permissions-reference.md#teams-administrator ) <br />[ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
181
+ > | Read hidden membership | Group member | [ Group owner] ( ../fundamentals/users-default-permissions.md#object-ownership ) <br />[ Password Administrator] ( .. /roles/permissions-reference.md#password-administrator) <br />[ Exchange Administrator] ( ../roles/permissions-reference.md#exchange-administrator ) <br />[ SharePoint Administrator] ( ../roles/permissions-reference.md#sharepoint-administrator ) <br />[ Teams Administrator] ( ../roles/permissions-reference.md#teams-administrator ) <br />[ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
182
182
> | Read membership of groups with hidden membership | [ Helpdesk Administrator] ( ../roles/permissions-reference.md#helpdesk-administrator ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) <br />[ Teams Administrator] ( ../roles/permissions-reference.md#teams-administrator ) |
183
183
> | Revoke license | [ License Administrator] ( ../roles/permissions-reference.md#license-administrator ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
184
184
> | Update group membership | [ Group owner] ( ../fundamentals/users-default-permissions.md#object-ownership ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
@@ -368,11 +368,11 @@ You can further restrict permissions by assigning roles at smaller scopes or by
368
368
> | Create user | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) | |
369
369
> | Delete users | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) | |
370
370
> | Invalidate refresh tokens of limited admins | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) | |
371
- > | Invalidate refresh tokens of non-admins | [ Password Administrator] ( /roles/permissions-reference.md#password-administrator ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
371
+ > | Invalidate refresh tokens of non-admins | [ Password Administrator] ( .. /roles/permissions-reference.md#password-administrator) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
372
372
> | Invalidate refresh tokens of privileged admins | [ Privileged Authentication Administrator] ( ../roles/permissions-reference.md#privileged-authentication-administrator ) | |
373
373
> | Read basic configuration | [ Default user role] ( ../fundamentals/users-default-permissions.md ) | |
374
374
> | Reset password for limited admins | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) | |
375
- > | Reset password of non-admins | [ Password Administrator] ( /roles/permissions-reference.md#password-administrator ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
375
+ > | Reset password of non-admins | [ Password Administrator] ( .. /roles/permissions-reference.md#password-administrator) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
376
376
> | Reset password of privileged admins | [ Privileged Authentication Administrator] ( ../roles/permissions-reference.md#privileged-authentication-administrator ) | |
377
377
> | Revoke license | [ License Administrator] ( ../roles/permissions-reference.md#license-administrator ) | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) |
378
378
> | Update all properties except User Principal Name | [ User Administrator] ( ../roles/permissions-reference.md#user-administrator ) | |
@@ -386,7 +386,7 @@ You can further restrict permissions by assigning roles at smaller scopes or by
386
386
> [ !div class="mx-tableFixed"]
387
387
> | Task | Least privileged role | Additional roles |
388
388
> | ---- | --------------------- | ---------------- |
389
- > | Submit support ticket | [Service Support Administrator](../roles/permissions-reference.md#service-support-administrator) | [Application Administrator](../roles/permissions-reference.md#application-administrator)<br/>[Azure Information Protection Administrator](../roles/permissions-reference.md#azure-information-protection-administrator)<br/>[Billing Administrator](../roles/permissions-reference.md#billing-administrator)<br/>[Cloud Application Administrator](../roles/permissions-reference.md#cloud-application-administrator)<br/>[Compliance Administrator](../roles/permissions-reference.md#compliance-administrator)<br/>[Dynamics 365 Administrator](../roles/permissions-reference.md#dynamics-365-administrator)<br/>[Desktop Analytics Administrator](../roles/permissions-reference.md#desktop-analytics-administrator)<br/>[Exchange Administrator](../roles/permissions-reference.md#exchange-administrator)<br/>[Intune Administrator](../roles/permissions-reference.md#intune-administrator)<br/>[Password Administrator](/roles/permissions-reference.md#password-administrator)<br/>[Power BI Administrator](../roles/permissions-reference.md#power-bi-administrator)<br/>[Privileged Authentication Administrator](../roles/permissions-reference.md#privileged-authentication-administrator)<br/>[SharePoint Administrator](../roles/permissions-reference.md#sharepoint-administrator)<br/>[Skype for Business Administrator](../roles/permissions-reference.md#skype-for-business-administrator)<br/>[Teams Administrator](../roles/permissions-reference.md#teams-administrator)<br/>[Teams Communications Administrator](../roles/permissions-reference.md#teams-communications-administrator)<br/>[User Administrator](../roles/permissions-reference.md#user-administrator) |
389
+ > | Submit support ticket | [Service Support Administrator](../roles/permissions-reference.md#service-support-administrator) | [Application Administrator](../roles/permissions-reference.md#application-administrator)<br/>[Azure Information Protection Administrator](../roles/permissions-reference.md#azure-information-protection-administrator)<br/>[Billing Administrator](../roles/permissions-reference.md#billing-administrator)<br/>[Cloud Application Administrator](../roles/permissions-reference.md#cloud-application-administrator)<br/>[Compliance Administrator](../roles/permissions-reference.md#compliance-administrator)<br/>[Dynamics 365 Administrator](../roles/permissions-reference.md#dynamics-365-administrator)<br/>[Desktop Analytics Administrator](../roles/permissions-reference.md#desktop-analytics-administrator)<br/>[Exchange Administrator](../roles/permissions-reference.md#exchange-administrator)<br/>[Intune Administrator](../roles/permissions-reference.md#intune-administrator)<br/>[Password Administrator](../roles/permissions-reference.md#password-administrator)<br/>[Power BI Administrator](../roles/permissions-reference.md#power-bi-administrator)<br/>[Privileged Authentication Administrator](../roles/permissions-reference.md#privileged-authentication-administrator)<br/>[SharePoint Administrator](../roles/permissions-reference.md#sharepoint-administrator)<br/>[Skype for Business Administrator](../roles/permissions-reference.md#skype-for-business-administrator)<br/>[Teams Administrator](../roles/permissions-reference.md#teams-administrator)<br/>[Teams Communications Administrator](../roles/permissions-reference.md#teams-communications-administrator)<br/>[User Administrator](../roles/permissions-reference.md#user-administrator) |
390
390
391
391
## Next steps
392
392
0 commit comments