Skip to content

Commit d2a8305

Browse files
Merge pull request #212531 from rolyon/rolyon-aadroles-roles-sept
[Azure AD roles] Updates to roles and permissions for September
2 parents 9526537 + fae9afa commit d2a8305

File tree

1 file changed

+16
-4
lines changed

1 file changed

+16
-4
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.workload: identity
1010
ms.subservice: roles
1111
ms.topic: reference
12-
ms.date: 08/03/2022
12+
ms.date: 09/26/2022
1313
ms.author: rolyon
1414
ms.reviewer: abhijeetsinha
1515
ms.custom: generated, it-pro, fasttrack-edit
@@ -550,6 +550,8 @@ Users in this role can enable, disable, and delete devices in Azure AD and read
550550
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, including privileged properties |
551551
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
552552
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
553+
> | microsoft.directory/deletedItems.devices/delete | Permanently delete devices, which can no longer be restored |
554+
> | microsoft.directory/deletedItems.devices/restore | Restore soft deleted devices to original state |
553555
> | microsoft.directory/devices/delete | Delete devices from Azure AD |
554556
> | microsoft.directory/devices/disable | Disable devices in Azure AD |
555557
> | microsoft.directory/devices/enable | Enable devices in Azure AD |
@@ -779,6 +781,7 @@ Users in this role can read and update basic information of users, groups, and s
779781
> | Actions | Description |
780782
> | --- | --- |
781783
> | microsoft.directory/applications/extensionProperties/update | Update extension properties on applications |
784+
> | microsoft.directory/contacts/create | Create contacts |
782785
> | microsoft.directory/groups/assignLicense | Assign product licenses to groups for group-based licensing |
783786
> | microsoft.directory/groups/create | Create Security groups and Microsoft 365 groups, excluding role-assignable groups |
784787
> | microsoft.directory/groups/reprocessLicenseAssignment | Reprocess license assignments for group-based licensing |
@@ -915,6 +918,7 @@ This administrator manages federation between Azure AD organizations and externa
915918
> [!div class="mx-tableFixed"]
916919
> | Actions | Description |
917920
> | --- | --- |
921+
> | microsoft.directory/domains/federation/update | Update federation property of domains |
918922
> | microsoft.directory/identityProviders/allProperties/allTasks | Read and configure identity providers in Azure Active Directory B2C |
919923
920924
## Global Administrator
@@ -1020,6 +1024,7 @@ Users with this role have access to all administrative features in Azure Active
10201024
> | microsoft.directory/servicePrincipalCreationPolicies/delete | Delete service principal creation policies |
10211025
> | microsoft.directory/servicePrincipalCreationPolicies/standard/read | Read standard properties of service principal creation policies |
10221026
> | microsoft.directory/servicePrincipalCreationPolicies/basic/update | Update basic properties of service principal creation policies |
1027+
> | microsoft.directory/tenantManagement/tenants/create | Create new tenants in Azure Active Directory |
10231028
> | microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read | Read a verifiable credential card |
10241029
> | microsoft.directory/verifiableCredentials/configuration/contracts/cards/revoke | Revoke a verifiable credential card |
10251030
> | microsoft.directory/verifiableCredentials/configuration/contracts/create | Create a verifiable credential contract |
@@ -1029,7 +1034,7 @@ Users with this role have access to all administrative features in Azure Active
10291034
> | microsoft.directory/verifiableCredentials/configuration/delete | Delete configuration required to create and manage verifiable credentials and delete all of its verifiable credentials |
10301035
> | microsoft.directory/verifiableCredentials/configuration/allProperties/read | Read configuration required to create and manage verifiable credentials |
10311036
> | microsoft.directory/verifiableCredentials/configuration/allProperties/update | Update configuration required to create and manage verifiable credentials |
1032-
> | microsoft.directory/lifecycleManagement/workflows/allProperties/allTasks | Manage all aspects of lifecycle management workflows and tasks in Azure AD |
1037+
> | microsoft.directory/lifecycleWorkflows/workflows/allProperties/allTasks | Manage all aspects of lifecycle workflows and tasks in Azure AD |
10331038
> | microsoft.azure.advancedThreatProtection/allEntities/allTasks | Manage all aspects of Azure Advanced Threat Protection |
10341039
> | microsoft.azure.informationProtection/allEntities/allTasks | Manage all aspects of Azure Information Protection |
10351040
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
@@ -1064,6 +1069,7 @@ Users with this role have access to all administrative features in Azure Active
10641069
> | microsoft.office365.userCommunication/allEntities/allTasks | Read and update what's new messages visibility |
10651070
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
10661071
> | microsoft.office365.yammer/allEntities/allProperties/allTasks | Manage all aspects of Yammer |
1072+
> | microsoft.permissionsManagement/allEntities/allProperties/allTasks | Manage all aspects of Entra Permissions Management |
10671073
> | microsoft.powerApps/allEntities/allTasks | Manage all aspects of Power Apps |
10681074
> | microsoft.powerApps.powerBI/allEntities/allTasks | Manage all aspects of Power BI |
10691075
> | microsoft.teams/allEntities/allProperties/allTasks | Manage all resources in Teams |
@@ -1146,7 +1152,7 @@ Users in this role can read settings and administrative information across Micro
11461152
> | microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read | Read a verifiable credential card |
11471153
> | microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/read | Read a verifiable credential contract |
11481154
> | microsoft.directory/verifiableCredentials/configuration/allProperties/read | Read configuration required to create and manage verifiable credentials |
1149-
> | microsoft.directory/lifecycleManagement/workflows/allProperties/read | Read all properties of lifecycle management workflows and tasks in Azure AD |
1155+
> | microsoft.directory/lifecycleWorkflows/workflows/allProperties/read | Read all properties of lifecycle workflows and tasks in Azure AD |
11501156
> | microsoft.cloudPC/allEntities/allProperties/read | Read all aspects of Windows 365 |
11511157
> | microsoft.commerce.billing/allEntities/allProperties/read | Read all resources of Office 365 billing |
11521158
> | microsoft.edge/allEntities/allProperties/read | Read all aspects of Microsoft Edge |
@@ -1160,6 +1166,7 @@ Users in this role can read settings and administrative information across Micro
11601166
> | microsoft.office365.usageReports/allEntities/allProperties/read | Read Office 365 usage reports |
11611167
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
11621168
> | microsoft.office365.yammer/allEntities/allProperties/read | Read all aspects of Yammer |
1169+
> | microsoft.permissionsManagement/allEntities/allProperties/read | Read all aspects of Entra Permissions Management |
11631170
> | microsoft.teams/allEntities/allProperties/read | Read all properties of Microsoft Teams |
11641171
> | microsoft.virtualVisits/allEntities/allProperties/read | Read all aspects of Virtual Visits |
11651172
> | microsoft.windows.updatesDeployments/allEntities/allProperties/read | Read all aspects of Windows Update Service |
@@ -1381,6 +1388,8 @@ This role can create and manage all security groups. However, Intune Administrat
13811388
> | microsoft.directory/contacts/create | Create contacts |
13821389
> | microsoft.directory/contacts/delete | Delete contacts |
13831390
> | microsoft.directory/contacts/basic/update | Update basic properties on contacts |
1391+
> | microsoft.directory/deletedItems.devices/delete | Permanently delete devices, which can no longer be restored |
1392+
> | microsoft.directory/deletedItems.devices/restore | Restore soft deleted devices to original state |
13841393
> | microsoft.directory/devices/create | Create devices (enroll in Azure AD) |
13851394
> | microsoft.directory/devices/delete | Delete devices from Azure AD |
13861395
> | microsoft.directory/devices/disable | Disable devices in Azure AD |
@@ -1492,7 +1501,7 @@ Assign the Lifecycle Workflows Administrator role to users who need to do the fo
14921501
> [!div class="mx-tableFixed"]
14931502
> | Actions | Description |
14941503
> | --- | --- |
1495-
> | microsoft.directory/lifecycleManagement/workflows/allProperties/allTasks | Manage all aspects of lifecycle management workflows and tasks in Azure AD |
1504+
> | microsoft.directory/lifecycleWorkflows/workflows/allProperties/allTasks | Manage all aspects of lifecycle workflows and tasks in Azure AD |
14961505
14971506
## Message Center Privacy Reader
14981507

@@ -1901,6 +1910,7 @@ Azure Advanced Threat Protection | Monitor and respond to suspicious security ac
19011910
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of cross-tenant access policy for partners |
19021911
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
19031912
> | microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update | Update tenant restrictions of cross-tenant access policy for partners |
1913+
> | microsoft.directory/domains/federation/update | Update federation property of domains |
19041914
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
19051915
> | microsoft.directory/identityProtection/allProperties/read | Read all resources in Azure AD Identity Protection |
19061916
> | microsoft.directory/identityProtection/allProperties/update | Update all resources in Azure AD Identity Protection |
@@ -2292,6 +2302,8 @@ Assign the Windows 365 Administrator role to users who need to do the following
22922302
> [!div class="mx-tableFixed"]
22932303
> | Actions | Description |
22942304
> | --- | --- |
2305+
> | microsoft.directory/deletedItems.devices/delete | Permanently delete devices, which can no longer be restored |
2306+
> | microsoft.directory/deletedItems.devices/restore | Restore soft deleted devices to original state |
22952307
> | microsoft.directory/devices/create | Create devices (enroll in Azure AD) |
22962308
> | microsoft.directory/devices/delete | Delete devices from Azure AD |
22972309
> | microsoft.directory/devices/disable | Disable devices in Azure AD |

0 commit comments

Comments
 (0)