Skip to content

Commit c9235b7

Browse files
Merge pull request #228240 from rolyon/rolyon-aadroles-roles-feb
[Azure AD roles] Updates to roles and permissions for February
2 parents ad2e07b + 449200a commit c9235b7

File tree

1 file changed

+23
-9
lines changed

1 file changed

+23
-9
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 23 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.workload: identity
1010
ms.subservice: roles
1111
ms.topic: reference
12-
ms.date: 01/28/2023
12+
ms.date: 02/21/2023
1313
ms.author: rolyon
1414
ms.reviewer: abhijeetsinha
1515
ms.custom: generated, it-pro, fasttrack-edit
@@ -180,8 +180,8 @@ This role also grants the ability to consent for delegated permissions and appli
180180
> | microsoft.directory/servicePrincipals/enable | Enable service principals |
181181
> | microsoft.directory/servicePrincipals/getPasswordSingleSignOnCredentials | Manage password single sign-on credentials on service principals |
182182
> | microsoft.directory/servicePrincipals/synchronizationCredentials/manage | Manage application provisioning secrets and credentials |
183-
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning syncronization jobs |
184-
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning syncronization jobs and schema |
183+
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning synchronization jobs |
184+
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning synchronization jobs and schema |
185185
> | microsoft.directory/servicePrincipals/managePasswordSingleSignOnCredentials | Read password single sign-on credentials on service principals |
186186
> | microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-application-admin | Grant consent for application permissions and delegated permissions on behalf of any user or all users, except for application permissions for Microsoft Graph |
187187
> | microsoft.directory/servicePrincipals/appRoleAssignedTo/update | Update service principal role assignments |
@@ -524,8 +524,8 @@ This role also grants the ability to consent for delegated permissions and appli
524524
> | microsoft.directory/servicePrincipals/enable | Enable service principals |
525525
> | microsoft.directory/servicePrincipals/getPasswordSingleSignOnCredentials | Manage password single sign-on credentials on service principals |
526526
> | microsoft.directory/servicePrincipals/synchronizationCredentials/manage | Manage application provisioning secrets and credentials |
527-
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning syncronization jobs |
528-
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning syncronization jobs and schema |
527+
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning synchronization jobs |
528+
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning synchronization jobs and schema |
529529
> | microsoft.directory/servicePrincipals/managePasswordSingleSignOnCredentials | Read password single sign-on credentials on service principals |
530530
> | microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-application-admin | Grant consent for application permissions and delegated permissions on behalf of any user or all users, except for application permissions for Microsoft Graph |
531531
> | microsoft.directory/servicePrincipals/appRoleAssignedTo/update | Update service principal role assignments |
@@ -807,8 +807,8 @@ Users in this role can read and update basic information of users, groups, and s
807807
> | microsoft.directory/oAuth2PermissionGrants/create | Create OAuth 2.0 permission grants |
808808
> | microsoft.directory/oAuth2PermissionGrants/basic/update | Update OAuth 2.0 permission grants |
809809
> | microsoft.directory/servicePrincipals/synchronizationCredentials/manage | Manage application provisioning secrets and credentials |
810-
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning syncronization jobs |
811-
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning syncronization jobs and schema |
810+
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning synchronization jobs |
811+
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning synchronization jobs and schema |
812812
> | microsoft.directory/servicePrincipals/appRoleAssignedTo/update | Update service principal role assignments |
813813
> | microsoft.directory/users/assignLicense | Manage user licenses |
814814
> | microsoft.directory/users/create | Add users |
@@ -977,6 +977,10 @@ Users with this role have access to all administrative features in Azure Active
977977
> | microsoft.directory/directoryRoles/allProperties/allTasks | Create and delete directory roles, and read and update all properties |
978978
> | microsoft.directory/directoryRoleTemplates/allProperties/allTasks | Create and delete Azure AD role templates, and read and update all properties |
979979
> | microsoft.directory/domains/allProperties/allTasks | Create and delete domains, and read and update all properties |
980+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
981+
> | microsoft.directory/domains/federationConfiguration/basic/update | Update basic federation configuration for domains |
982+
> | microsoft.directory/domains/federationConfiguration/create | Create federation configuration for domains |
983+
> | microsoft.directory/domains/federationConfiguration/delete | Delete federation configuration for domains |
980984
> | microsoft.directory/entitlementManagement/allProperties/allTasks | Create and delete resources, and read and update all properties in Azure AD entitlement management |
981985
> | microsoft.directory/groups/allProperties/allTasks | Create and delete groups, and read and update all properties |
982986
> | microsoft.directory/groupsAssignableToRoles/create | Create role-assignable groups |
@@ -1134,6 +1138,7 @@ Users with this role **cannot** do the following:
11341138
> | microsoft.directory/directoryRoles/allProperties/read | Read all properties of directory roles |
11351139
> | microsoft.directory/directoryRoleTemplates/allProperties/read | Read all properties of directory role templates |
11361140
> | microsoft.directory/domains/allProperties/read | Read all properties of domains |
1141+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
11371142
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
11381143
> | microsoft.directory/groups/allProperties/read | Read all properties (including privileged properties) on Security groups and Microsoft 365 groups, including role-assignable groups |
11391144
> | microsoft.directory/groupSettings/allProperties/read | Read all properties of group settings |
@@ -1300,6 +1305,10 @@ Users in this role can create, manage and deploy provisioning configuration setu
13001305
> | microsoft.directory/deletedItems.applications/restore | Restore soft deleted applications to original state |
13011306
> | microsoft.directory/domains/allProperties/read | Read all properties of domains |
13021307
> | microsoft.directory/domains/federation/update | Update federation property of domains |
1308+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
1309+
> | microsoft.directory/domains/federationConfiguration/basic/update | Update basic federation configuration for domains |
1310+
> | microsoft.directory/domains/federationConfiguration/create | Create federation configuration for domains |
1311+
> | microsoft.directory/domains/federationConfiguration/delete | Delete federation configuration for domains |
13031312
> | microsoft.directory/hybridAuthenticationPolicy/allProperties/allTasks | Manage hybrid authentication policy in Azure AD |
13041313
> | microsoft.directory/organization/dirSync/update | Update the organization directory sync property |
13051314
> | microsoft.directory/passwordHashSync/allProperties/allTasks | Manage all aspects of Password Hash Synchronization (PHS) in Azure AD |
@@ -1309,8 +1318,8 @@ Users in this role can create, manage and deploy provisioning configuration setu
13091318
> | microsoft.directory/servicePrincipals/disable | Disable service principals |
13101319
> | microsoft.directory/servicePrincipals/enable | Enable service principals |
13111320
> | microsoft.directory/servicePrincipals/synchronizationCredentials/manage | Manage application provisioning secrets and credentials |
1312-
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning syncronization jobs |
1313-
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning syncronization jobs and schema |
1321+
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning synchronization jobs |
1322+
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning synchronization jobs and schema |
13141323
> | microsoft.directory/servicePrincipals/audience/update | Update audience properties on service principals |
13151324
> | microsoft.directory/servicePrincipals/authentication/update | Update authentication properties on service principals |
13161325
> | microsoft.directory/servicePrincipals/basic/update | Update basic properties on service principals |
@@ -2007,6 +2016,10 @@ Azure Advanced Threat Protection | Monitor and respond to suspicious security ac
20072016
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
20082017
> | microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update | Update tenant restrictions of cross-tenant access policy for partners |
20092018
> | microsoft.directory/domains/federation/update | Update federation property of domains |
2019+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
2020+
> | microsoft.directory/domains/federationConfiguration/basic/update | Update basic federation configuration for domains |
2021+
> | microsoft.directory/domains/federationConfiguration/create | Create federation configuration for domains |
2022+
> | microsoft.directory/domains/federationConfiguration/delete | Delete federation configuration for domains |
20102023
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
20112024
> | microsoft.directory/identityProtection/allProperties/read | Read all resources in Azure AD Identity Protection |
20122025
> | microsoft.directory/identityProtection/allProperties/update | Update all resources in Azure AD Identity Protection |
@@ -2097,6 +2110,7 @@ In | Can do
20972110
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
20982111
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
20992112
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
2113+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
21002114
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
21012115
> | microsoft.directory/identityProtection/allProperties/read | Read all resources in Azure AD Identity Protection |
21022116
> | microsoft.directory/namedLocations/standard/read | Read basic properties of custom rules that define network locations |

0 commit comments

Comments
 (0)