roles

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/25

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:39 AM on 10/4/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

26 Terms

1
New cards

Global Administrator

Role with full access to everything in Entra ID and Microsoft services using Entra identities; does NOT receive custom security attribute permissions by default.

2
New cards

Privileged Role Administrator

Role that assigns Entra roles and manages all aspects of Privileged Identity Management (PIM).

3
New cards

Global Reader

Read-only role that can view everything a Global Admin can see without making changes.

4
New cards

User Administrator

Broadest user-management role short of Global Admin; creates and manages users/groups and resets passwords for non-admins and limited admins.

5
New cards

Helpdesk Administrator

Role that resets passwords for non-admins and other Helpdesk Admins and invalidates refresh tokens, but cannot create users.

6
New cards

Password Administrator

Narrowest role dedicated solely to resetting passwords for non-admin users and other Password Admins.

7
New cards

Groups Administrator

Role that creates and manages groups and group settings (naming, expiration policies) without managing individual user accounts.

8
New cards

License Administrator

Role that assigns and removes licenses for users and groups (requires user usage location to be set prior to assignment).

9
New cards

Authentication Administrator

Role that views, sets, and resets authentication methods (MFA) for non-admin users only.

10
New cards

Privileged Authentication Administrator

Role that views, sets, and resets authentication methods (MFA) for any user, including administrators.

11
New cards

Authentication Policy Administrator

Role that manages tenant-wide authentication methods policy, MFA settings, and password protection without resetting individual user methods.

12
New cards

Conditional Access Administrator

Least-privilege role for creating and managing Conditional Access policies.

13
New cards

Security Administrator

Role that manages security configurations, including Identity Protection policies, and possesses full Security Reader permissions.

14
New cards

Security Operator

Role that responds to and manages security events and alerts (e.g., dismissing risky users) without configuring security policies.

15
New cards

Security Reader

Read-only role for viewing security information, alerts, and reports.

16
New cards

Application Administrator

Role that manages app registrations and enterprise apps, including Application Proxy.

17
New cards

Cloud Application Administrator

Role that manages enterprise apps and app registrations, excluding Application Proxy.

18
New cards

Application Developer

Role that allows users to register applications even when user registration is restricted, becoming owner of created apps.

19
New cards

Guest Inviter

Role that invites guest users when guest invitations are restricted, without permission to manage guests post-invitation.

20
New cards

External Identity Provider Administrator

Role that configures direct federation (SAML/WS-Fed) with partner identity providers.

21
New cards

Hybrid Identity Administrator

Role for configuring and managing Entra Connect, cloud sync, federation settings, and pass-through authentication.

22
New cards

Identity Governance Administrator

Role for managing access reviews, entitlement management (access packages), and lifecycle workflows.

23
New cards

Reports Reader

Read-only role for accessing sign-in and audit logs.

24
New cards

Cloud Device Administrator

Role that enables, disables, and deletes devices and reads BitLocker keys, without managing Intune policies.

25
New cards

Attribute Definition Administrator

Role required to define custom security attributes; must be explicitly granted as Global Admin does not possess it by default.

26
New cards

Attribute Assignment Administrator

Role required to assign custom security attributes to users and objects; must be explicitly granted as Global Admin does not possess it by default.