Microsoft Entra ID RBAC Roles

Explore all Microsoft Entra ID administrative roles across identity, security, conditional access, identity governance, and application management.

140 roles across 19 categories. Open the interactive map →

Developer & Technical

DevOps, network, and technical administration roles

  • Azure DevOps Administrator

    Can manage all enterprise Azure DevOps policies for organizations backed by Microsoft Entra ID.

  • Network Administrator

    Can manage network locations and review enterprise network design insights for Microsoft 365 SaaS applications.

  • Desktop Analytics Administrator

    Can access and manage Desktop management tools and services for Windows device analytics.

  • Edge Administrator

    Manage all aspects of Microsoft Edge including policies, settings, and enterprise configurations.

  • Organizational Data Source Administrator

    Manages organizational data ingestion for Microsoft 365 and Microsoft Viva applications.

  • Agent ID Administrator

    Manages all aspects of agents in a tenant including identity lifecycle operations for agent blueprints, agent service principals, agent identities, and agentic users.

  • Agent ID Developer

    Creates agent blueprints and their service principals. The user is added as owner of the agent blueprint and its service principal.

  • Agent Registry Administrator

    Manages all aspects of the Agent Registry service in Microsoft Entra ID including metadata, collections, and visibility of AI agents.

  • Authentication Extensibility Administrator

    Creates and manages custom authentication extensions to customize sign-in and sign-up experiences for users.

  • Dragon Administrator

    Manages all aspects of the Microsoft Dragon admin center for healthcare voice recognition.

  • Authentication Extensibility Password Administrator

    Triggers password submit events for custom authentication extensions. Works alongside Authentication Extensibility Administrator to enable password-based custom authentication flows.

B2C & External Identity

Azure AD B2C, Identity Experience Framework, and external identity management

Hardware & Devices

Microsoft hardware warranty, IoT devices, and device management

Universal Print

Universal Print service and printer management

  • Printer Administrator

    Manages all aspects of printers and printer connectors in Microsoft Universal Print including configuration and connector settings.

  • Printer Technician

    Registers and unregisters printers, updates printer status, and reads connector information but cannot set permissions.

Privileged Identity Management

Just-in-time privileged access and approval workflows

  • PIM Administrator

    Can manage all aspects of Privileged Identity Management including settings, eligible assignments, and approval workflows. This role is equivalent to Privileged Role Administrator for PIM purposes.

  • PIM Approver

    Designated as approver for PIM role activation requests. Can approve or deny activation requests but cannot modify PIM settings.

Identity Protection

Risk-based identity security and threat detection

  • Identity Protection Administrator

    Can manage Identity Protection policies, investigate and remediate risky users and sign-ins, and configure risk-based policies. Requires Microsoft Entra ID P2 license.

  • Identity Protection Reader

    Can read Identity Protection reports, risk detections, and configurations but cannot remediate risks or modify policies. Requires Microsoft Entra ID P2 license.

Identity Governance

Lifecycle workflows, permissions management, and attribute governance

Security & Compliance

Data protection, compliance, and security governance roles

  • Security Operator

    Can manage security events, view reports, dismiss alerts, and take limited remediation actions. Cannot modify security policies.

  • Attack Simulation Administrator

    Can create and manage all aspects of attack simulation campaigns including phishing simulations, payload creation, and campaign reporting.

  • Compliance Administrator

    Can read and manage compliance configuration and reports across Microsoft Entra ID and Microsoft 365 including DLP, retention, sensitivity labels, and eDiscovery.

  • Compliance Data Administrator

    Creates and manages compliance content, tracks data in Microsoft Purview, and can perform eDiscovery operations.

  • Azure Information Protection Administrator

    Can manage all aspects of the Azure Information Protection product including labels, policies, and protection templates.

  • Customer LockBox Access Approver

    Can approve Microsoft support requests to access customer organizational data. Critical for controlling Microsoft engineer access.

  • Microsoft 365 Backup Administrator

    Manages all aspects of Microsoft 365 Backup including policies, restore operations, and backup configurations.

  • Message Center Privacy Reader

    Can read all notifications in Message Center including data privacy messages. Important for privacy compliance awareness.

  • Attack Payload Author

    Creates attack payloads for security awareness training but cannot launch simulations. Payloads are available to all tenant admins.

  • Cloud App Security Administrator

    Full permissions in Microsoft Defender for Cloud Apps including adding administrators, policies, and governance actions.

Reporting & Knowledge

Usage reports, insights, and knowledge management

  • Reports Reader

    Can read sign-in and audit reports, and view the Microsoft Agent 365 overview and agent registry for the tenant including agent metadata. Ideal for compliance and security monitoring without broader…

  • Knowledge Administrator

    Can configure knowledge, learning, and intelligent features including Microsoft Viva Topics, Learning, and search customizations.

  • Search Editor

    Can create and manage editorial content for Microsoft Search such as bookmarks, Q&A, and locations.

  • Insights Analyst

    Access the analytical capabilities in Microsoft Viva Insights and run custom queries.

  • Insights Business Leader

    Can view and share dashboards and insights via the Microsoft Viva Insights app.

  • User Experience Success Manager

    Views product feedback, survey results, and reports to find training and communication opportunities for users.

Global Secure Access

Entra Private Access and Internet Access (ZTNA/SSE)

Conditional Access

Policy-based access controls for secure authentication

Access Reviews

Periodic access recertification and attestation

  • Access Reviews Administrator

    Can create and manage access reviews for group memberships, application assignments, and role assignments. Requires Microsoft Entra ID P2 license.

  • Access Review Reviewer

    Designated reviewer for access reviews who can approve or deny continued access. Cannot modify review settings.

Entitlement Management

Access packages, catalogs, and connected organizations

Teams Communication

Teams voice, telephony, and communication services

Viva & Employee Experience

Microsoft Viva suite and employee experience administration

  • AI Administrator

    Manage all aspects of Microsoft 365 Copilot, Microsoft Agent 365, and AI-related enterprise services including extensibility and copilot agents. Has tenant-wide visibility and full governance…

  • Viva Goals Administrator

    Manage and configure all aspects of Microsoft Viva Goals including OKR settings and integrations.

  • Viva Pulse Administrator

    Can manage all settings for Microsoft Viva Pulse app including survey configurations and privacy settings.

  • Viva Glint Tenant Administrator

    Manage and configure Microsoft Viva Glint settings in the Microsoft 365 admin center including admin assignments.

  • Insights Administrator

    Has administrative access in the Microsoft 365 Insights app for organizational analytics.

  • AI Reader

    Read all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365. Recommended least-privilege role for viewing the complete agent inventory in Microsoft Agent 365 and the…

M365 & Platform Services

Power Platform, Dynamics 365, and AI service administration

M365 Workloads & Services

Intune, Exchange, SharePoint, Teams, Yammer, Search, and Office Apps administration

  • Intune Administrator

    Can manage all aspects of Microsoft Intune product including devices, apps, policies, and user management for endpoints.

  • Exchange Administrator

    Can manage all aspects of Exchange Online including mailboxes, groups, connectors, mail flow rules, and organization-wide settings.

  • SharePoint Administrator

    Can manage all aspects of SharePoint Online including site collections, sharing policies, term store, and OneDrive for Business settings.

  • Teams Administrator

    Can manage the Microsoft Teams service including meetings, calling, messaging policies, and Teams-certified devices.

  • Yammer Administrator

    Manage all aspects of the Yammer service including network settings, usage policies, and content moderation.

  • Search Administrator

    Can create and manage all aspects of Microsoft Search settings including bookmarks, Q&A, and locations.

  • Office Apps Administrator

    Can manage Microsoft 365 apps cloud settings including policies, feature management, and whats new content.

  • Service Support Administrator

    Can create and manage support requests with Microsoft for Azure and Microsoft 365 services.

  • Virtual Visits Administrator

    Manage and share Virtual Visits information and metrics from admin centers or the Virtual Visits app.

  • Knowledge Manager

    Creates and manages content like topics, acronyms, and manages topic visibility and taxonomies.

  • Microsoft Graph Data Connect Administrator

    Manages Microsoft Graph Data Connect settings including dataset configuration and application authorization.

  • Microsoft 365 Migration Administrator

    Performs all migration functionality to migrate content to Microsoft 365 using Migration Manager.

  • SharePoint Advanced Management Administrator

    Performs all SharePoint Administrator actions plus advanced management capabilities like viewing file metadata and removing permissions.

  • SharePoint Backup Administrator

    Manages all aspects of Microsoft 365 Backup for SharePoint and OneDrive including backup policies and restore operations.

  • SharePoint Embedded Administrator

    Manages all aspects of SharePoint Embedded containers using PowerShell, Graph API, or SharePoint admin center.

  • Exchange Backup Administrator

    Backs up and restores content including granular restore for Exchange Online in Microsoft 365 Backup.

  • Exchange Recipient Administrator

    Creates or updates Exchange Online recipients within the Exchange Online organization.

  • Skype for Business Administrator

    Can manage all aspects of the Skype for Business product. Legacy role retained for organizations still using Skype for Business features.

Organizational Management

Branding, tenant management, and organizational settings

Remaining Built-in Roles

Additional pre-defined roles for administrative tasks in Microsoft Entra ID

  • Global Administrator

    Can manage all aspects of Microsoft Entra ID and Microsoft services. This is the highest privilege role with the ability to reset any password, consent to any app, and elevate to Azure subscriptions.

  • Global Reader

    Can read everything that a Global Administrator can read, but cannot update anything. This is a PRIVILEGED role - the information visible can be used to plan attacks.

  • Privileged Role Administrator

    Can manage role assignments in Microsoft Entra ID and all aspects of Privileged Identity Management (PIM). This role can grant any role to any user including Global Administrator.

  • Privileged Authentication Administrator

    Can set or reset any authentication method (including passwords) for any user, including Global Administrators. This is one of the highest-privilege roles.

  • Security Administrator

    Can read security information and reports, and manage configuration in Microsoft Entra ID and Microsoft 365. This role has broad security configuration permissions across services.

  • Security Reader

    Can read security information and reports across Microsoft Entra ID, Identity Protection, Privileged Identity Management, and Microsoft 365 Defender.

  • Billing Administrator

    Can perform billing related tasks including purchases, subscription management, support tickets, and service health monitoring.

  • License Administrator

    Can manage product licenses on users and groups. Can also manage usage location and read service plans but cannot purchase or manage subscriptions.

  • User Administrator

    Can create users and groups, and manage all aspects of users and groups, including resetting passwords for limited admins. This is a privileged role with significant scope.

  • Authentication Administrator

    Can view, set, and reset authentication method information for any non-admin user. Cannot manage MFA settings or password protection policies.

  • Authentication Policy Administrator

    Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials configuration.

  • Helpdesk Administrator

    Can reset passwords for non-administrators and Helpdesk Administrators. Cannot manage service health, support tickets, or advanced user properties.

  • Password Administrator

    Can reset passwords for non-administrators. Most limited password reset role without additional service health or support ticket access.

  • Groups Administrator

    Can create and manage all aspects of groups and group settings like naming and expiration policies, and manage group membership and ownership.

  • Guest Inviter

    Can invite guest users independent of the member invitation settings. This is the most limited guest invitation role.

  • Directory Readers

    Can read basic directory information. Commonly used to grant directory read access to service principals and guest users.

  • Directory Writers

    Can read and write basic directory information. Primarily used for granting access to applications and services, not intended for end users.

  • Application Administrator

    Can create and manage all aspects of app registrations and enterprise apps. This is a privileged role that can impersonate applications.

  • Cloud Application Administrator

    Can create and manage all aspects of app registrations and enterprise apps except App Proxy. Ideal for cloud-only environments.

  • Application Developer

    Can create application registrations independent of the "Users can register applications" setting. Most limited application role.

  • Cloud Device Administrator

    Can enable, disable, and delete devices in Microsoft Entra ID and read Windows BitLocker recovery keys in the Azure portal.

  • Windows Update Deployment Administrator

    Can create and manage all aspects of Windows Update deployments through Windows Update for Business.

  • Windows 365 Administrator

    Can provision and manage all aspects of Cloud PCs.

  • Hybrid Identity Administrator

    Can manage AD to Microsoft Entra cloud provisioning, Microsoft Entra Connect, pass-through authentication, and federation settings for hybrid environments.

  • Domain Name Administrator

    Can manage domain names in cloud and on-premises including adding, verifying, and removing custom domains.

  • Entra Backup Administrator

    Manages all aspects of Microsoft Entra Backup including creating recovery jobs and managing backup snapshots for directory data.

  • Entra Backup Reader

    Read-only access to Microsoft Entra Backup including listing preview jobs, recovery jobs, and backup snapshots. Can create preview jobs to assess recovery scope.

  • Partner Tier1 Support

    Legacy Microsoft partner support role. Microsoft documents this role with "Do not use — not intended for general use." Superseded by Granular Delegated Admin Privileges (GDAP) and the Customer…

  • Partner Tier2 Support

    Legacy Microsoft partner support role with elevated permissions over Partner Tier1 Support. Microsoft documents this role with "Do not use — not intended for general use." Superseded by Granular…