mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3.1 KiB
3.1 KiB
| 1 | azureadrole | isprvilegedadrole | description | |||||
|---|---|---|---|---|---|---|---|---|
| 2 | "Application Administrator" | True | Can create and manage all aspects of app registrations and enterprise apps. | |||||
| 3 | "Authentication Administrator" | True | Can access to view | set and reset authentication method information for any non-admin user. | ||||
| 4 | "Authentication Policy Administrator" | True | Can create and manage the authentication methods policy | tenant-wide MFA settings | password protection policy | and verifiable credentials. | ||
| 5 | "Azure AD Joined Device Local Administrator" | True | Users assigned to this role are added to the local administrators group on Azure AD-joined devices. | |||||
| 6 | "Azure DevOps Administrator" | True | Can manage Azure DevOps policies and settings. | |||||
| 7 | "Azure Information Protection Administrator" | True | Can manage all aspects of the Azure Information Protection product. | |||||
| 8 | "Cloud Application Administrator" | True | Can create and manage all aspects of app registrations and enterprise apps except App Proxy. | |||||
| 9 | "Cloud Device Administrator" | True | Limited access to manage devices in Azure AD. | |||||
| 10 | "Compliance Administrator" | True | Can read and manage compliance configuration and reports in Azure AD and Microsoft 365. | |||||
| 11 | "Conditional Access Administrator" | True | Can manage Conditional Access capabilities. | |||||
| 12 | "Exchange Administrator" | True | Can manage all aspects of the Exchange product. | |||||
| 13 | "External Identity Provider Administrator" | True | Can configure identity providers for use in direct federation. | |||||
| 14 | "Groups Administrator" | True | Members of this role can create/manage groups | create/manage groups settings like naming and expiration policies | and view groups activity and audit reports. | |||
| 15 | "Helpdesk Administrator" | True | Can reset passwords for non-administrators and Helpdesk Administrators. | |||||
| 16 | "Hybrid Identity Administrator" | True | Can manage AD to Azure AD cloud provisioning | Azure AD Connect | Pass-through Authentication (PTA) | Password hash synchronization (PHS) | Seamless Single sign-on (Seamless SSO) | and federation settings. |
| 17 | "Intune Administrator" | True | Can manage all aspects of the Intune product. | |||||
| 18 | "License Administrator" | True | Can manage product licenses on users and groups. | |||||
| 19 | "Network Administrator" | True | Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications. | |||||
| 20 | "Password Administrator" | True | Can reset passwords for non-administrators and Password Administrators. | |||||
| 21 | "Privileged Authentication Administrator" | True | Can access to view | set and reset authentication method information for any user (admin or non-admin). | ||||
| 22 | "Privileged Role Administrator" | True | Can manage role assignments in Azure AD | and all aspects of Privileged Identity Management. | ||||
| 23 | "Security Administrator" | True | Can read security information and reports | and manage configuration in Azure AD and Office 365. | ||||
| 24 | "SharePoint Administrator" | True | Can manage all aspects of the SharePoint service. | |||||
| 25 | "Teams Administrator" | True | Can manage the Microsoft Teams service. | |||||
| 26 | "User Administrator" | True | Can manage all aspects of users and groups | including resetting passwords for limited admins. | ||||
| 27 | "Windows 365 Administrator" | True | Can provision and manage all aspects of Cloud PCs. |