1/25
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Global Administrator
Role with full access to everything in Entra ID and Microsoft services using Entra identities; does NOT receive custom security attribute permissions by default.
Privileged Role Administrator
Role that assigns Entra roles and manages all aspects of Privileged Identity Management (PIM).
Global Reader
Read-only role that can view everything a Global Admin can see without making changes.
User Administrator
Broadest user-management role short of Global Admin; creates and manages users/groups and resets passwords for non-admins and limited admins.
Helpdesk Administrator
Role that resets passwords for non-admins and other Helpdesk Admins and invalidates refresh tokens, but cannot create users.
Password Administrator
Narrowest role dedicated solely to resetting passwords for non-admin users and other Password Admins.
Groups Administrator
Role that creates and manages groups and group settings (naming, expiration policies) without managing individual user accounts.
License Administrator
Role that assigns and removes licenses for users and groups (requires user usage location to be set prior to assignment).
Authentication Administrator
Role that views, sets, and resets authentication methods (MFA) for non-admin users only.
Privileged Authentication Administrator
Role that views, sets, and resets authentication methods (MFA) for any user, including administrators.
Authentication Policy Administrator
Role that manages tenant-wide authentication methods policy, MFA settings, and password protection without resetting individual user methods.
Conditional Access Administrator
Least-privilege role for creating and managing Conditional Access policies.
Security Administrator
Role that manages security configurations, including Identity Protection policies, and possesses full Security Reader permissions.
Security Operator
Role that responds to and manages security events and alerts (e.g., dismissing risky users) without configuring security policies.
Security Reader
Read-only role for viewing security information, alerts, and reports.
Application Administrator
Role that manages app registrations and enterprise apps, including Application Proxy.
Cloud Application Administrator
Role that manages enterprise apps and app registrations, excluding Application Proxy.
Application Developer
Role that allows users to register applications even when user registration is restricted, becoming owner of created apps.
Guest Inviter
Role that invites guest users when guest invitations are restricted, without permission to manage guests post-invitation.
External Identity Provider Administrator
Role that configures direct federation (SAML/WS-Fed) with partner identity providers.
Hybrid Identity Administrator
Role for configuring and managing Entra Connect, cloud sync, federation settings, and pass-through authentication.
Identity Governance Administrator
Role for managing access reviews, entitlement management (access packages), and lifecycle workflows.
Reports Reader
Read-only role for accessing sign-in and audit logs.
Cloud Device Administrator
Role that enables, disables, and deletes devices and reads BitLocker keys, without managing Intune policies.
Attribute Definition Administrator
Role required to define custom security attributes; must be explicitly granted as Global Admin does not possess it by default.
Attribute Assignment Administrator
Role required to assign custom security attributes to users and objects; must be explicitly granted as Global Admin does not possess it by default.