Role actions63·Control Plane52·Management Plane8·User Access3·Não classificadas0·CategoriaIdentity·EAM TierControl Plane

Agent ID Administrator

Privilegiada
Control PlaneIdentity63 role actions
Template ID
db506228-d27e-4b7d-95e5-295956d6615f
Categoria
Identity
EAM Tier
Control Plane (Tier 0)
Enterprise Access Model: Control Plane

Controle total do tenant. Comprometimento leva a takeover completo. Isole de planos inferiores.

Descrição

Manage the full lifecycle of agent identities, agent identity blueprint principals, agent identity blueprints, and agent users in a tenant

Permissões completas

Todas as 63 role actions desta role, classificadas por tier do EAM.

Role ActionCategoriaTier
microsoft.directory/agentIdentities/appRoleAssignedTo/update
Agent IdentityTier 0
microsoft.directory/agentIdentities/authentication/update
Agent IdentityTier 0
microsoft.directory/agentIdentities/basic/update
Agent IdentityTier 0
microsoft.directory/agentIdentities/create
Agent IdentityTier 0
microsoft.directory/agentIdentities/delete
Agent IdentityTier 0
microsoft.directory/agentIdentities/disable
Agent IdentityTier 0
microsoft.directory/agentIdentities/enable
Agent IdentityTier 0
microsoft.directory/agentIdentities/owners/update
Agent IdentityTier 0
microsoft.directory/agentIdentities/tag/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/appRoleAssignedTo/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/authentication/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/basic/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/create
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/delete
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/disable
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/enable
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/owners/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprintPrincipals/tag/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/allProperties/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/appRoles/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/audience/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/authentication/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/basic/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/create
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/credentials/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/delete
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/owners/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/permissions/update
Agent IdentityTier 0
microsoft.directory/agentIdentityBlueprints/tag/update
Agent IdentityTier 0
microsoft.directory/agentUsers/assignLicense
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/basic/update
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/create
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/delete
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/disable
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/enable
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/invalidateAllRefreshTokens
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/lifeCycleInfo/read
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/lifeCycleInfo/update
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/manager/update
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/photo/update
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/reprocessLicenseAssignment
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/restore
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/revokeSignInSessions
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/sponsors/update
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/usageLocation/update
Global Agent User ManagementTier 0
microsoft.directory/agentUsers/userPrincipalName/update
Global Agent User ManagementTier 0
microsoft.directory/deletedItems.agentIdentities/delete
Agent IdentityTier 0
microsoft.directory/deletedItems.agentIdentities/restore
Agent IdentityTier 0
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/delete
Agent IdentityTier 0
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/restore
Agent IdentityTier 0
microsoft.directory/deletedItems.agentIdentityBlueprints/delete
Agent IdentityTier 0
microsoft.directory/deletedItems.agentIdentityBlueprints/restore
Agent IdentityTier 0
microsoft.azure.serviceHealth/allEntities/allTasks
Support and Service HealthTier 1
microsoft.azure.supportTickets/allEntities/allTasks
Support and Service HealthTier 1
microsoft.directory/auditLogs/allProperties/read
Security and ComplianceTier 1
microsoft.directory/externalUserProfiles/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/groups/hiddenMembers/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/signInReports/allProperties/read
Security and ComplianceTier 1
microsoft.office365.serviceHealth/allEntities/allTasks
Microsoft 365 Support OperationsTier 1
microsoft.office365.supportTickets/allEntities/allTasks
Microsoft 365 Support OperationsTier 1
microsoft.directory/groups.unified/createAsOwner
Extended memberTier 2
microsoft.directory/organization/standard/read
Default memberTier 2
microsoft.directory/policies/standard/read
Default memberTier 2

63 de 63 role actions

PowerShell

Get-MgRoleManagementDirectoryRoleDefinition `
  -UnifiedRoleDefinitionId "db506228-d27e-4b7d-95e5-295956d6615f"

Microsoft Graph

GET https://graph.microsoft.com/v1.0/
  roleManagement/directory/
  roleDefinitions/db506228-d27e-4b7d-95e5-295956d6615f
Ver documentação oficial na Microsoft Learn

Roles relacionadas