You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+16-2Lines changed: 16 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.workload: identity
10
10
ms.subservice: roles
11
11
ms.topic: reference
12
-
ms.date: 02/21/2023
12
+
ms.date: 04/28/2023
13
13
ms.author: rolyon
14
14
ms.reviewer: abhijeetsinha
15
15
ms.custom: generated, it-pro, fasttrack-edit
@@ -562,6 +562,7 @@ Users in this role can enable, disable, and delete devices in Azure AD and read
562
562
> | microsoft.directory/devices/delete | Delete devices from Azure AD |
563
563
> | microsoft.directory/devices/disable | Disable devices in Azure AD |
564
564
> | microsoft.directory/devices/enable | Enable devices in Azure AD |
565
+
> | microsoft.directory/deviceLocalCredentials/password/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, including the password |
565
566
> | microsoft.directory/deviceManagementPolicies/standard/read | Read standard properties on device management application policies |
> | microsoft.directory/namedLocations/standard/read | Read basic properties of custom rules that define network locations |
973
976
> | microsoft.directory/namedLocations/basic/update | Update basic properties of custom rules that define network locations |
977
+
> | microsoft.directory/deviceLocalCredentials/password/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, including the password |
974
978
> | microsoft.directory/deviceManagementPolicies/standard/read | Read standard properties on device management application policies |
> | microsoft.directory/deviceLocalCredentials/standard/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, except the password |
1138
1143
> | microsoft.directory/devices/allProperties/read | Read all properties of devices |
1139
1144
> | microsoft.directory/directoryRoles/allProperties/read | Read all properties of directory roles |
1140
1145
> | microsoft.directory/directoryRoleTemplates/allProperties/read | Read all properties of directory role templates |
@@ -1246,6 +1251,7 @@ Users in this role can manage Azure Active Directory B2B guest user invitations
1246
1251
> | microsoft.directory/users/photo/read | Read photo of users |
1247
1252
> | microsoft.directory/users/registeredDevices/read | Read registered devices of users |
1248
1253
> | microsoft.directory/users/scopedRoleMemberOf/read | Read user's membership of an Azure AD role, that is scoped to an administrative unit |
1254
+
> | microsoft.directory/users/sponsors/read | Read sponsors of users |
1249
1255
1250
1256
## Helpdesk Administrator
1251
1257
@@ -1272,6 +1278,7 @@ This role was previously named Password Administrator in the [Azure portal](../.
1272
1278
> | Actions | Description |
1273
1279
> | --- | --- |
1274
1280
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
1281
+
> | microsoft.directory/deviceLocalCredentials/standard/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, except the password |
1275
1282
> | microsoft.directory/users/invalidateAllRefreshTokens | Force sign-out by invalidating user refresh tokens |
1276
1283
> | microsoft.directory/users/password/update | Reset passwords for all users |
1277
1284
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
@@ -1331,6 +1338,7 @@ Users in this role can create, manage and deploy provisioning configuration setu
1331
1338
> | microsoft.directory/servicePrincipals/tag/update | Update the tag property for service principals |
1332
1339
> | microsoft.directory/servicePrincipals/synchronization/standard/read | Read provisioning settings associated with your service principal |
1333
1340
> | microsoft.directory/signInReports/allProperties/read | Read all properties on sign-in reports, including privileged properties |
1341
+
> | microsoft.directory/users/authorizationInfo/update | Update the multivalued Certificate user IDs property of users |
1334
1342
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
1335
1343
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
1336
1344
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
@@ -1430,6 +1438,7 @@ This role can create and manage all security groups. However, Intune Administrat
1430
1438
> | microsoft.directory/devices/extensionAttributeSet3/update | Update the extensionAttribute11 to extensionAttribute15 properties on devices |
1431
1439
> | microsoft.directory/devices/registeredOwners/update | Update registered owners of devices |
1432
1440
> | microsoft.directory/devices/registeredUsers/update | Update registered users of devices |
1441
+
> | microsoft.directory/deviceLocalCredentials/password/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, including the password |
1433
1442
> | microsoft.directory/deviceManagementPolicies/standard/read | Read standard properties on device management application policies |
1434
1443
> | microsoft.directory/deviceRegistrationPolicy/standard/read | Read standard properties on device registration policies |
1435
1444
> | microsoft.directory/groups/hiddenMembers/read | Read hidden members of Security groups and Microsoft 365 groups, including role-assignable groups |
@@ -1895,6 +1904,7 @@ Users with this role **cannot** do the following:
1895
1904
> | microsoft.directory/users/invalidateAllRefreshTokens | Force sign-out by invalidating user refresh tokens |
> | microsoft.directory/users/basic/update | Update basic properties on users |
1907
+
> | microsoft.directory/users/authorizationInfo/update | Update the multivalued Certificate user IDs property of users |
1898
1908
> | microsoft.directory/users/manager/update | Update manager for users |
1899
1909
> | microsoft.directory/users/password/update | Reset passwords for all users |
1900
1910
> | microsoft.directory/users/userPrincipalName/update | Update User Principal Name of users |
@@ -2017,6 +2027,7 @@ Azure Advanced Threat Protection | Monitor and respond to suspicious security ac
2017
2027
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of cross-tenant access policy for partners |
2018
2028
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
2019
2029
> | microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update | Update tenant restrictions of cross-tenant access policy for partners |
2030
+
> | microsoft.directory/deviceLocalCredentials/standard/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, except the password |
2020
2031
> | microsoft.directory/domains/federation/update | Update federation property of domains |
2021
2032
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
2113
2124
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
2114
2125
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
2126
+
> | microsoft.directory/deviceLocalCredentials/standard/read | Read all properties of the backed up local administrator account credentials for Azure AD joined devices, except the password |
2115
2127
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
2116
2128
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
2117
2129
> | microsoft.directory/identityProtection/allProperties/read | Read all resources in Azure AD Identity Protection |
@@ -2392,6 +2404,8 @@ Users with this role **cannot** do the following:
2392
2404
> | microsoft.directory/users/manager/update | Update manager for users |
2393
2405
> | microsoft.directory/users/password/update | Reset passwords for all users |
2394
2406
> | microsoft.directory/users/photo/update | Update photo of users |
2407
+
> | microsoft.directory/users/sponsors/update | Update sponsors of users |
2408
+
> | microsoft.directory/users/usageLocation/update | Update usage location of users |
2395
2409
> | microsoft.directory/users/userPrincipalName/update | Update User Principal Name of users |
2396
2410
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
2397
2411
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
@@ -2422,7 +2436,7 @@ Assign the Viva Goals Administrator role to users who need to do the following t
2422
2436
- Manage and configure all aspects of the Microsoft Viva Goals application
2423
2437
- Configure Microsoft Viva Goals admin settings
2424
2438
- Read Azure AD tenant information
2425
-
- Monitor Microsoft 365 service health
2439
+
- Monitor Microsoft 365 service health
2426
2440
- Create and manage Microsoft 365 service requests
2427
2441
2428
2442
For more information, see [Roles and permissions in Viva Goals](/viva/goals/roles-permissions-in-viva-goals) and [Introduction to Microsoft Viva Goals](/viva/goals/intro-to-ms-viva-goals).
0 commit comments