You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+47-1Lines changed: 47 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.workload: identity
10
10
ms.subservice: roles
11
11
ms.topic: reference
12
-
ms.date: 08/29/2023
12
+
ms.date: 10/03/2023
13
13
ms.author: rolyon
14
14
ms.reviewer: abhijeetsinha
15
15
ms.custom: generated, it-pro, fasttrack-edit
@@ -1006,6 +1006,16 @@ This is a [privileged role](privileged-roles-permissions.md). Users with this ro
1006
1006
> | microsoft.directory/deletedItems/delete | Permanently delete objects, which can no longer be restored |
1007
1007
> | microsoft.directory/deletedItems/restore | Restore soft deleted objects to original state |
1008
1008
> | microsoft.directory/devices/allProperties/allTasks | Create and delete devices, and read and update all properties |
1009
+
> | microsoft.directory/multiTenantOrganization/basic/update | Update basic properties of a multi-tenant organization |
1010
+
> | microsoft.directory/multiTenantOrganization/create | Create a multi-tenant organization |
1011
+
> | microsoft.directory/multiTenantOrganization/joinRequest/organizationDetails/update | Join a multi-tenant organization |
1012
+
> | microsoft.directory/multiTenantOrganization/joinRequest/standard/read | Read properties of a multi-tenant organization join request |
1013
+
> | microsoft.directory/multiTenantOrganization/standard/read | Read basic properties of a multi-tenant organization |
1014
+
> | microsoft.directory/multiTenantOrganization/tenants/organizationDetails/update | Update basic properties of a tenant participating in a multi-tenant organization |
1015
+
> | microsoft.directory/multiTenantOrganization/tenants/create | Create a tenant in a multi-tenant organization |
1016
+
> | microsoft.directory/multiTenantOrganization/tenants/delete | Delete a tenant participating in a multi-tenant organization |
1017
+
> | microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read | Read organization details of a tenant participating in a multi-tenant organization |
1018
+
> | microsoft.directory/multiTenantOrganization/tenants/standard/read | Read basic properties of a tenant participating in a multi-tenant organization |
> | microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/resetToDefaultSettings | Reset cross tenant access policy template for multi-tenant organization to default settings |
1067
+
> | microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read | Read basic properties of cross tenant access policy templates for multi-tenant organization |
1052
1068
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bCollaboration/update | Update Microsoft Entra B2B collaboration settings of cross-tenant access policy for partners |
1053
1069
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Microsoft Entra B2B direct connect settings of cross-tenant access policy for partners |
1054
1070
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
@@ -1072,6 +1088,7 @@ This is a [privileged role](privileged-roles-permissions.md). Users with this ro
1072
1088
> | microsoft.directory/signInReports/allProperties/read | Read all properties on sign-in reports, including privileged properties |
1073
1089
> | microsoft.directory/subscribedSkus/allProperties/allTasks | Buy and manage subscriptions and delete subscriptions |
1074
1090
> | microsoft.directory/users/allProperties/allTasks | Create and delete users, and read and update all properties<br/>[](privileged-roles-permissions.md)|
1091
+
> | microsoft.directory/users/convertExternalToInternalMemberUser | Convert external user to internal user |
1075
1092
> | microsoft.directory/permissionGrantPolicies/create | Create permission grant policies |
1076
1093
> | microsoft.directory/permissionGrantPolicies/delete | Delete permission grant policies |
1077
1094
> | microsoft.directory/permissionGrantPolicies/standard/read | Read standard properties of permission grant policies |
@@ -1213,9 +1230,15 @@ Users with this role **cannot** do the following:
> | microsoft.directory/deviceManagementPolicies/standard/read | Read standard properties on device management application policies |
1218
1237
> | microsoft.directory/deviceRegistrationPolicy/standard/read | Read standard properties on device registration policies |
1238
+
> | microsoft.directory/multiTenantOrganization/joinRequest/standard/read | Read properties of a multi-tenant organization join request |
1239
+
> | microsoft.directory/multiTenantOrganization/standard/read | Read basic properties of a multi-tenant organization |
1240
+
> | microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read | Read organization details of a tenant participating in a multi-tenant organization |
1241
+
> | microsoft.directory/multiTenantOrganization/tenants/standard/read | Read basic properties of a tenant participating in a multi-tenant organization |
1219
1242
> | microsoft.directory/privilegedIdentityManagement/allProperties/read | Read all resources in Privileged Identity Management |
1220
1243
> | microsoft.directory/provisioningLogs/allProperties/read | Read all properties of provisioning logs |
1221
1244
> | microsoft.directory/roleAssignments/allProperties/read | Read all properties of role assignments |
@@ -2120,6 +2143,12 @@ Azure Advanced Threat Protection | Monitor and respond to suspicious security ac
> | microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/resetToDefaultSettings | Reset cross tenant access policy template for multi-tenant organization to default settings |
2151
+
> | microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read | Read basic properties of cross tenant access policy templates for multi-tenant organization |
2123
2152
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bCollaboration/update | Update Microsoft Entra B2B collaboration settings of cross-tenant access policy for partners |
2124
2153
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Microsoft Entra B2B direct connect settings of cross-tenant access policy for partners |
2125
2154
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
@@ -2136,6 +2165,16 @@ Azure Advanced Threat Protection | Monitor and respond to suspicious security ac
2136
2165
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Microsoft Entra entitlement management |
2137
2166
> | microsoft.directory/identityProtection/allProperties/read | Read all resources in Microsoft Entra ID Protection |
2138
2167
> | microsoft.directory/identityProtection/allProperties/update | Update all resources in Microsoft Entra ID Protection<br/>[](privileged-roles-permissions.md)|
2168
+
> | microsoft.directory/multiTenantOrganization/basic/update | Update basic properties of a multi-tenant organization |
2169
+
> | microsoft.directory/multiTenantOrganization/create | Create a multi-tenant organization |
2170
+
> | microsoft.directory/multiTenantOrganization/joinRequest/organizationDetails/update | Join a multi-tenant organization |
2171
+
> | microsoft.directory/multiTenantOrganization/joinRequest/standard/read | Read properties of a multi-tenant organization join request |
2172
+
> | microsoft.directory/multiTenantOrganization/standard/read | Read basic properties of a multi-tenant organization |
2173
+
> | microsoft.directory/multiTenantOrganization/tenants/organizationDetails/update | Update basic properties of a tenant participating in a multi-tenant organization |
2174
+
> | microsoft.directory/multiTenantOrganization/tenants/create | Create a tenant in a multi-tenant organization |
2175
+
> | microsoft.directory/multiTenantOrganization/tenants/delete | Delete a tenant participating in a multi-tenant organization |
2176
+
> | microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read | Read organization details of a tenant participating in a multi-tenant organization |
2177
+
> | microsoft.directory/multiTenantOrganization/tenants/standard/read | Read basic properties of a tenant participating in a multi-tenant organization |
> | microsoft.directory/namedLocations/standard/read | Read basic properties of custom rules that define network locations |
@@ -2239,6 +2278,12 @@ In | Can do
2239
2278
> | microsoft.directory/conditionalAccessPolicies/standard/read | Read conditional access for policies |
2240
2279
> | microsoft.directory/conditionalAccessPolicies/owners/read | Read the owners of conditional access policies |
2241
2280
> | microsoft.directory/conditionalAccessPolicies/policyAppliedTo/read | Read the "applied to" property for conditional access policies |
2281
+
> | microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/standard/read | Read basic properties of cross tenant sync policy templates for multi-tenant organization |
2282
+
> | microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read | Read basic properties of cross tenant access policy templates for multi-tenant organization |
2283
+
> | microsoft.directory/multiTenantOrganization/joinRequest/standard/read | Read properties of a multi-tenant organization join request |
2284
+
> | microsoft.directory/multiTenantOrganization/standard/read | Read basic properties of a multi-tenant organization |
2285
+
> | microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read | Read organization details of a tenant participating in a multi-tenant organization |
2286
+
> | microsoft.directory/multiTenantOrganization/tenants/standard/read | Read basic properties of a tenant participating in a multi-tenant organization |
2242
2287
> | microsoft.directory/privilegedIdentityManagement/allProperties/read | Read all resources in Privileged Identity Management |
2243
2288
> | microsoft.directory/provisioningLogs/allProperties/read | Read all properties of provisioning logs |
2244
2289
> | microsoft.directory/signInReports/allProperties/read | Read all properties on sign-in reports, including privileged properties |
@@ -2516,6 +2561,7 @@ Users with this role **cannot** do the following:
2516
2561
> | microsoft.directory/servicePrincipals/appRoleAssignedTo/update | Update service principal role assignments |
2517
2562
> | microsoft.directory/users/assignLicense | Manage user licenses |
0 commit comments