You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -915,6 +918,7 @@ This administrator manages federation between Azure AD organizations and externa
915
918
> [!div class="mx-tableFixed"]
916
919
> | Actions | Description |
917
920
> | --- | --- |
921
+
> | microsoft.directory/domains/federation/update | Update federation property of domains |
918
922
> | microsoft.directory/identityProviders/allProperties/allTasks | Read and configure identity providers in Azure Active Directory B2C |
919
923
920
924
## Global Administrator
@@ -1020,6 +1024,7 @@ Users with this role have access to all administrative features in Azure Active
1020
1024
> | microsoft.directory/servicePrincipalCreationPolicies/delete | Delete service principal creation policies |
1021
1025
> | microsoft.directory/servicePrincipalCreationPolicies/standard/read | Read standard properties of service principal creation policies |
1022
1026
> | microsoft.directory/servicePrincipalCreationPolicies/basic/update | Update basic properties of service principal creation policies |
1027
+
> | microsoft.directory/tenantManagement/tenants/create | Create new tenants in Azure Active Directory |
1023
1028
> | microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read | Read a verifiable credential card |
1024
1029
> | microsoft.directory/verifiableCredentials/configuration/contracts/cards/revoke | Revoke a verifiable credential card |
1025
1030
> | microsoft.directory/verifiableCredentials/configuration/contracts/create | Create a verifiable credential contract |
@@ -1029,7 +1034,7 @@ Users with this role have access to all administrative features in Azure Active
1029
1034
> | microsoft.directory/verifiableCredentials/configuration/delete | Delete configuration required to create and manage verifiable credentials and delete all of its verifiable credentials |
1030
1035
> | microsoft.directory/verifiableCredentials/configuration/allProperties/read | Read configuration required to create and manage verifiable credentials |
1031
1036
> | microsoft.directory/verifiableCredentials/configuration/allProperties/update | Update configuration required to create and manage verifiable credentials |
1032
-
> | microsoft.directory/lifecycleManagement/workflows/allProperties/allTasks | Manage all aspects of lifecycle management workflows and tasks in Azure AD |
1037
+
> | microsoft.directory/lifecycleWorkflows/workflows/allProperties/allTasks | Manage all aspects of lifecycle workflows and tasks in Azure AD |
1033
1038
> | microsoft.azure.advancedThreatProtection/allEntities/allTasks | Manage all aspects of Azure Advanced Threat Protection |
1034
1039
> | microsoft.azure.informationProtection/allEntities/allTasks | Manage all aspects of Azure Information Protection |
1035
1040
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
@@ -1064,6 +1069,7 @@ Users with this role have access to all administrative features in Azure Active
1064
1069
> | microsoft.office365.userCommunication/allEntities/allTasks | Read and update what's new messages visibility |
1065
1070
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1066
1071
> | microsoft.office365.yammer/allEntities/allProperties/allTasks | Manage all aspects of Yammer |
1072
+
> | microsoft.permissionsManagement/allEntities/allProperties/allTasks | Manage all aspects of Entra Permissions Management |
1067
1073
> | microsoft.powerApps/allEntities/allTasks | Manage all aspects of Power Apps |
1068
1074
> | microsoft.powerApps.powerBI/allEntities/allTasks | Manage all aspects of Power BI |
1069
1075
> | microsoft.teams/allEntities/allProperties/allTasks | Manage all resources in Teams |
@@ -1146,7 +1152,7 @@ Users in this role can read settings and administrative information across Micro
1146
1152
> | microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read | Read a verifiable credential card |
1147
1153
> | microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/read | Read a verifiable credential contract |
1148
1154
> | microsoft.directory/verifiableCredentials/configuration/allProperties/read | Read configuration required to create and manage verifiable credentials |
1149
-
> | microsoft.directory/lifecycleManagement/workflows/allProperties/read | Read all properties of lifecycle management workflows and tasks in Azure AD |
1155
+
> | microsoft.directory/lifecycleWorkflows/workflows/allProperties/read | Read all properties of lifecycle workflows and tasks in Azure AD |
1150
1156
> | microsoft.cloudPC/allEntities/allProperties/read | Read all aspects of Windows 365 |
1151
1157
> | microsoft.commerce.billing/allEntities/allProperties/read | Read all resources of Office 365 billing |
1152
1158
> | microsoft.edge/allEntities/allProperties/read | Read all aspects of Microsoft Edge |
@@ -1160,6 +1166,7 @@ Users in this role can read settings and administrative information across Micro
> | microsoft.directory/devices/delete | Delete devices from Azure AD |
1386
1395
> | microsoft.directory/devices/disable | Disable devices in Azure AD |
@@ -1492,7 +1501,7 @@ Assign the Lifecycle Workflows Administrator role to users who need to do the fo
1492
1501
> [!div class="mx-tableFixed"]
1493
1502
> | Actions | Description |
1494
1503
> | --- | --- |
1495
-
> | microsoft.directory/lifecycleManagement/workflows/allProperties/allTasks | Manage all aspects of lifecycle management workflows and tasks in Azure AD |
1504
+
> | microsoft.directory/lifecycleWorkflows/workflows/allProperties/allTasks | Manage all aspects of lifecycle workflows and tasks in Azure AD |
1496
1505
1497
1506
## Message Center Privacy Reader
1498
1507
@@ -1901,6 +1910,7 @@ Azure Advanced Threat Protection | Monitor and respond to suspicious security ac
1901
1910
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of cross-tenant access policy for partners |
1902
1911
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
1903
1912
> | microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update | Update tenant restrictions of cross-tenant access policy for partners |
1913
+
> | microsoft.directory/domains/federation/update | Update federation property of domains |
1904
1914
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
1905
1915
> | microsoft.directory/identityProtection/allProperties/read | Read all resources in Azure AD Identity Protection |
1906
1916
> | microsoft.directory/identityProtection/allProperties/update | Update all resources in Azure AD Identity Protection |
@@ -2292,6 +2302,8 @@ Assign the Windows 365 Administrator role to users who need to do the following
2292
2302
> [!div class="mx-tableFixed"]
2293
2303
> | Actions | Description |
2294
2304
> | --- | --- |
2305
+
> | microsoft.directory/deletedItems.devices/delete | Permanently delete devices, which can no longer be restored |
2306
+
> | microsoft.directory/deletedItems.devices/restore | Restore soft deleted devices to original state |
0 commit comments