Administrator Roles Flashcards
Application Administrator
Can administer enterprise applications, application registrations, and application proxy settings.
Application Developer
Can create application registrations.
Authentication Administrator
Can view current authentication method settings. Can set or reset non-password credentials. Can force MFA on next sign on.
Billing Administrator
Can purchase and manage subscriptions. Can manage support tickets and monitor service health.
Cloud Application Administrator
Can manage all aspects of enterprise applications and registrations, but cannot manage application proxy.
Cloud Device Administrator
Can enable, disable, and remove devices in Azure AD. Can view Windows 10 BitLocker Drive Encryption Keys through Azure portal.
Compliance Administrator
Manage features in the Microsoft 365 compliance Center, Microsoft 365 Admin Center and Microsoft 365 Security and Compliance Center.
Conditional Access Administrator
Administrative rights over Azure AD conditional access configuration.
Customer Lockbox access approver
Manage customer lockbox requests. Can also enable and disable the customer lockbox feature.
Device Administrators
Users assigned this role will become local administrators on all computers running Windows 10 that are joined to Azure AD.
Directory Readers
Role for applications that do not support consent framework. Should not be assigned to users.
Directory Synchronization Accounts
Assigned to the Azure AD Connect service and not used for user accounts.
Directory Writers
A legacy role assigned to applications that do not support the consent framework. Should only be assigned to applications and not user accounts.
Dynamics 365 Administrator/ CRM Administrator
Administrative access to Dynamics 365 Online
Exchange Administrator
Administrative Access to Exchange Online
Global Administrator/ Company Administrator
Administrative access to all Azure AD features. This includes administrative access to services that use Azure AD Identities including Microsoft 365 security center, Microsoft 365 compliance center, Exchange Online, SharePoint Online, and Skype for Business Online. The account used to sign up for the tenancy becomes the global admin. Global admins can reset the password of any user, including other global admins.
Guest Inviter
Can manage Azure AD B2B guest user invitations.
Information Protection Administrator
Has the ability to manage all aspects of Azure Information Protection including configuring labels, managing protection templates, and activating protection.
Intune Administrator
Has full administrative rights to Microsoft Intune
License Administrator
Can manage license assignments on users and groups. Cannot purchase or manage subscriptions.
Message Center Reader
Can monitor notification and Microsoft advisories in the Microsoft 365 Message Center.
Password Administrator / Helpdesk Administrator
Able to perform the following tasks for all users except those that have administrative roles:
- Change passwords
- Invalidate refresh tokens
- Manage service requests
- Monitor service health
Power BI Administrator
Has administrator permissions over Power BI
Privileged Role Administrator
Can manage all aspects of Azure AD Privileged Identity Management. Can manage role assignments in Azure AD.
Reports Reader
Can view reporting data in the Microsoft 365 reports dashboard
Security Administrator
Has administrator level access to manage security features in the Microsoft 365 security center, Azure AD Identity Protection, Azure Information Protection, And Microsoft 365 Security and Compliance Center.
Security Reader
Has read-only access to security Microsoft 365 related services.
Service Support Administrator
Can open and view support requests with Microsoft for Microsoft 365 related services.
SharePoint Administrator
Has global administrator permissions for SharePoint Online workloads.
Skype for Business / Lync Administrator
Has global administrator permissions for Skype for Business workloads.
Teams Administrator
Can administer all elements of Microsoft Teams
Teams Communications Administrator
Can manage Teams workloads related to voice and telephony including telephone number assignment, voice and meeting policies.
Teams Communications Support Engineer
Can troubleshoot communication issues within Teams & Skype for Business. Can view details of call records for all participants in a conversation.
Teams Communications Support Specialist
Can troubleshoot communication issues with Teams & Skype for Business. Can only view user details in the call for a specific user.
User Account Administrator
Can create and manage user accounts. Can create and manage groups. Can manage user views, support tickets and monitor service health.