Administrator Roles Flashcards
Application Administrator
Can administer enterprise applications, application registrations, and application proxy settings.
Application Developer
Can create application registrations.
Authentication Administrator
Can view current authentication method settings. Can set or reset non-password credentials. Can force MFA on next sign on.
Billing Administrator
Can purchase and manage subscriptions. Can manage support tickets and monitor service health.
Cloud Application Administrator
Can manage all aspects of enterprise applications and registrations, but cannot manage application proxy.
Cloud Device Administrator
Can enable, disable, and remove devices in Azure AD. Can view Windows 10 BitLocker Drive Encryption Keys through Azure portal.
Compliance Administrator
Manage features in the Microsoft 365 compliance Center, Microsoft 365 Admin Center and Microsoft 365 Security and Compliance Center.
Conditional Access Administrator
Administrative rights over Azure AD conditional access configuration.
Customer Lockbox access approver
Manage customer lockbox requests. Can also enable and disable the customer lockbox feature.
Device Administrators
Users assigned this role will become local administrators on all computers running Windows 10 that are joined to Azure AD.
Directory Readers
Role for applications that do not support consent framework. Should not be assigned to users.
Directory Synchronization Accounts
Assigned to the Azure AD Connect service and not used for user accounts.
Directory Writers
A legacy role assigned to applications that do not support the consent framework. Should only be assigned to applications and not user accounts.
Dynamics 365 Administrator/ CRM Administrator
Administrative access to Dynamics 365 Online
Exchange Administrator
Administrative Access to Exchange Online