Role actions56·Control Plane40·Management Plane14·User Access2·Não classificadas0·CategoriaIdentity·EAM TierControl Plane

User Administrator

Privilegiada
Control PlaneIdentity56 role actions
Template ID
fe930be7-5e62-47db-91af-98c3a49a38b1
Categoria
Identity
EAM Tier
Control Plane (Tier 0)
Enterprise Access Model: Control Plane

Controle total do tenant. Comprometimento leva a takeover completo. Isole de planos inferiores.

Descrição

Users with this role can create and manage all aspects of users and groups. Additionally, this role includes the ability to manage support tickets and monitors service health. Some restrictions apply. For example, this role does not allo...

Permissões completas

Todas as 56 role actions desta role, classificadas por tier do EAM.

Role ActionCategoriaTier
microsoft.directory/accessReviews/definitions.applications/allProperties/allTasks
Entitlement ManagementTier 0
microsoft.directory/accessReviews/definitions.entitlementManagement/allProperties/allTasks
Entitlement ManagementTier 0
microsoft.directory/accessReviews/definitions.groups/allProperties/update
Entitlement ManagementTier 0
microsoft.directory/accessReviews/definitions.groups/create
Entitlement ManagementTier 0
microsoft.directory/accessReviews/definitions.groups/delete
Entitlement ManagementTier 0
microsoft.directory/deletedItems.groups/restore
Group ManagementTier 0
microsoft.directory/deletedItems.users/restore
Global User ManagementTier 0
microsoft.directory/entitlementManagement/allProperties/allTasks
Entitlement ManagementTier 0
microsoft.directory/groups/assignLicense
License ManagementTier 0
microsoft.directory/groups/basic/update
Group ManagementTier 0
microsoft.directory/groups/classification/update
Group ManagementTier 0
microsoft.directory/groups/create
Group ManagementTier 0
microsoft.directory/groups/delete
Group ManagementTier 0
microsoft.directory/groups/dynamicMembershipRule/update
Group ManagementTier 0
microsoft.directory/groups/groupType/update
Group ManagementTier 0
microsoft.directory/groups/members/update
Group ManagementTier 0
microsoft.directory/groups/onPremWriteBack/update
Group ManagementTier 0
microsoft.directory/groups/owners/update
Group ManagementTier 0
microsoft.directory/groups/reprocessLicenseAssignment
License ManagementTier 0
microsoft.directory/groups/restore
Group ManagementTier 0
microsoft.directory/groups/settings/update
Group ManagementTier 0
microsoft.directory/groups/visibility/update
Group ManagementTier 0
microsoft.directory/oAuth2PermissionGrants/allProperties/allTasks
Application and Workload IdentityTier 0
microsoft.directory/servicePrincipals/appRoleAssignedTo/update
Application and Workload IdentityTier 0
microsoft.directory/users/assignLicense
License ManagementTier 0
microsoft.directory/users/basic/update
Global User ManagementTier 0
microsoft.directory/users/convertExternalToInternalMemberUser
Global User ManagementTier 0
microsoft.directory/users/create
Global User ManagementTier 0
microsoft.directory/users/delete
Global User ManagementTier 0
microsoft.directory/users/disable
Global User ManagementTier 0
microsoft.directory/users/enable
Global User ManagementTier 0
microsoft.directory/users/invalidateAllRefreshTokens
Global User ManagementTier 0
microsoft.directory/users/manager/update
Global User ManagementTier 0
microsoft.directory/users/password/update
Global User ManagementTier 0
microsoft.directory/users/photo/update
Global User ManagementTier 0
microsoft.directory/users/reprocessLicenseAssignment
License ManagementTier 0
microsoft.directory/users/restore
Global User ManagementTier 0
microsoft.directory/users/sponsors/update
Global User ManagementTier 0
microsoft.directory/users/usageLocation/update
Global User ManagementTier 0
microsoft.directory/users/userPrincipalName/update
Global User ManagementTier 0
microsoft.azure.serviceHealth/allEntities/allTasks
Support and Service HealthTier 1
microsoft.azure.supportTickets/allEntities/allTasks
Support and Service HealthTier 1
microsoft.directory/accessReviews/definitions.directoryRoles/allProperties/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/accessReviews/definitions.groups/allProperties/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/contacts/basic/update
Microsoft Exchange OnlineTier 1
microsoft.directory/contacts/create
Microsoft Exchange OnlineTier 1
microsoft.directory/contacts/delete
Microsoft Exchange OnlineTier 1
microsoft.directory/groups.unified/assignedLabels/update
Microsoft 365 Group ManagementTier 1
microsoft.directory/groups/hiddenMembers/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/onPremisesSynchronization/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/users/lifeCycleInfo/read
Tenant Configuration (Reader)Tier 1
microsoft.office365.serviceHealth/allEntities/allTasks
Microsoft 365 Support OperationsTier 1
microsoft.office365.supportTickets/allEntities/allTasks
Microsoft 365 Support OperationsTier 1
microsoft.office365.webPortal/allEntities/standard/read
Microsoft 365 Support OperationsTier 1
microsoft.directory/policies/standard/read
Default memberTier 2
microsoft.directory/users/inviteGuest
External IdentitiesTier 2

56 de 56 role actions

PowerShell

Get-MgRoleManagementDirectoryRoleDefinition `
  -UnifiedRoleDefinitionId "fe930be7-5e62-47db-91af-98c3a49a38b1"

Microsoft Graph

GET https://graph.microsoft.com/v1.0/
  roleManagement/directory/
  roleDefinitions/fe930be7-5e62-47db-91af-98c3a49a38b1
Ver documentação oficial na Microsoft Learn

Roles relacionadas