Resources/Roles/GDAPRoles.json

[
  {
    "Description": "Can create and manage all aspects of app registrations and enterprise apps.",
    "Name": "Application Administrator",
    "ObjectId": "9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3"
  },
  {
    "Description": "Can create application registrations independent of the \u0027Users can register applications\u0027 setting.",
    "Name": "Application Developer",
    "ObjectId": "cf1c38e5-3621-4004-a7cb-879624dced7c"
  },
  {
    "Description": "Can create attack payloads that an administrator can initiate later.",
    "Name": "Attack Payload Author",
    "ObjectId": "9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f"
  },
  {
    "Description": "Can create and manage all aspects of attack simulation campaigns.",
    "Name": "Attack Simulation Administrator",
    "ObjectId": "c430b396-e693-46cc-96f3-db01bf8bb62a"
  },
  {
    "Description": "Assign custom security attribute keys and values to supported Azure AD objects.",
    "Name": "Attribute Assignment Administrator",
    "ObjectId": "58a13ea3-c632-46ae-9ee0-9c0d43cd7f3d"
  },
  {
    "Description": "Read custom security attribute keys and values for supported Azure AD objects.",
    "Name": "Attribute Assignment Reader",
    "ObjectId": "ffd52fa5-98dc-465c-991d-fc073eb59f8f"
  },
  {
    "Description": "Define and manage the definition of custom security attributes.",
    "Name": "Attribute Definition Administrator",
    "ObjectId": "8424c6f0-a189-499e-bbd0-26c1753c96d4"
  },
  {
    "Description": "Read the definition of custom security attributes.",
    "Name": "Attribute Definition Reader",
    "ObjectId": "1d336d2c-4ae8-42ef-9711-b3604ce3fc2c"
  },
  {
    "Description": "Allowed to view, set and reset authentication method information for any non-admin user.",
    "Name": "Authentication Administrator",
    "ObjectId": "c4e39bd9-1100-46d3-8c65-fb160da0071f"
  },
  {
    "Description": "Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials.",
    "Name": "Authentication Policy Administrator",
    "ObjectId": "0526716b-113d-4c15-b2c8-68e3c22b9f80"
  },
  {
    "Description": "Users assigned to this role are added to the local administrators group on Azure AD-joined devices.",
    "Name": "Azure AD Joined Device Local Administrator",
    "ObjectId": "9f06204d-73c1-4d4c-880a-6edb90606fd8"
  },
  {
    "Description": "Can manage Azure DevOps organization policy and settings.",
    "Name": "Azure DevOps Administrator",
    "ObjectId": "e3973bdf-4987-49ae-837a-ba8e231c7286"
  },
  {
    "Description": "Can manage all aspects of the Azure Information Protection product.",
    "Name": "Azure Information Protection Administrator",
    "ObjectId": "7495fdc4-34c4-4d15-a289-98788ce399fd"
  },
  {
    "Description": "Can manage secrets for federation and encryption in the Identity Experience Framework (IEF).",
    "Name": "B2C IEF Keyset Administrator",
    "ObjectId": "aaf43236-0c0d-4d5f-883a-6955382ac081"
  },
  {
    "Description": "Can create and manage trust framework policies in the Identity Experience Framework (IEF).",
    "Name": "B2C IEF Policy Administrator",
    "ObjectId": "3edaf663-341e-4475-9f94-5c398ef6c070"
  },
  {
    "Description": "Can perform common billing related tasks like updating payment information.",
    "Name": "Billing Administrator",
    "ObjectId": "b0f54661-2d74-4c50-afa3-1ec803f12efe"
  },
  {
    "Description": "Can manage all aspects of the Cloud App Security product.",
    "Name": "Cloud App Security Administrator",
    "ObjectId": "892c5842-a9a6-463a-8041-72aa08ca3cf6"
  },
  {
    "Description": "Can create and manage all aspects of app registrations and enterprise apps except App Proxy.",
    "Name": "Cloud Application Administrator",
    "ObjectId": "158c047a-c907-4556-b7ef-446551a6b5f7"
  },
  {
    "Description": "Full access to manage devices in Azure AD.",
    "Name": "Cloud Device Administrator",
    "ObjectId": "7698a772-787b-4ac8-901f-60d6b08affd2"
  },
  {
    "Description": "Can read and manage compliance configuration and reports in Azure AD and Microsoft 365.",
    "Name": "Compliance Administrator",
    "ObjectId": "17315797-102d-40b4-93e0-432062caca18"
  },
  {
    "Description": "Creates and manages compliance content.",
    "Name": "Compliance Data Administrator",
    "ObjectId": "e6d1a23a-da11-4be4-9570-befc86d067a7"
  },
  {
    "Description": "Can manage Conditional Access capabilities.",
    "Name": "Conditional Access Administrator",
    "ObjectId": "b1be1c3e-b65d-4f19-8427-f6fa0d97feb9"
  },
  {
    "Description": "Can approve Microsoft support requests to access customer organizational data.",
    "Name": "Customer LockBox Access Approver",
    "ObjectId": "5c4f9dcd-47dc-4cf7-8c9a-9e4207cbfc91"
  },
  {
    "Description": "Can access and manage Desktop management tools and services.",
    "Name": "Desktop Analytics Administrator",
    "ObjectId": "38a96431-2bdf-4b4c-8b6e-5d3d8abac1a4"
  },
  {
    "Description": "Device Join",
    "Name": "Device Join",
    "ObjectId": "9c094953-4995-41c8-84c8-3ebb9b32c93f"
  },
  {
    "Description": "Device Users",
    "Name": "Device Users",
    "ObjectId": "d405c6df-0af8-4e3b-95e4-4d06e542189e"
  },
  {
    "Description": "Can read basic directory information. Commonly used to grant directory read access to applications and guests.",
    "Name": "Directory Readers",
    "ObjectId": "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
  },
  {
    "Description": "Only used by Azure AD Connect service.",
    "Name": "Directory Synchronization Accounts",
    "ObjectId": "d29b2b05-8046-44ba-8758-1e26182fcf32"
  },
  {
    "Description": "Can read and write basic directory information. For granting access to applications, not intended for users.",
    "Name": "Directory Writers",
    "ObjectId": "9360feb5-f418-4baa-8175-e2a00bac4301"
  },
  {
    "Description": "Can manage domain names in cloud and on-premises.",
    "Name": "Domain Name Administrator",
    "ObjectId": "8329153b-31d0-4727-b945-745eb3bc5f31"
  },
  {
    "Description": "Can manage all aspects of the Dynamics 365 product.",
    "Name": "Dynamics 365 Administrator",
    "ObjectId": "44367163-eba1-44c3-98af-f5787879f96a"
  },
  {
    "Description": "Manage all aspects of Microsoft Edge.",
    "Name": "Edge Administrator",
    "ObjectId": "3f1acade-1e04-4fbc-9b69-f0302cd84aef"
  },
  {
    "Description": "Can manage all aspects of the Exchange product.",
    "Name": "Exchange Administrator",
    "ObjectId": "29232cdf-9323-42fd-ade2-1d097af3e4de"
  },
  {
    "Description": "Can create or update Exchange Online recipients within the Exchange Online organization.",
    "Name": "Exchange Recipient Administrator",
    "ObjectId": "31392ffb-586c-42d1-9346-e59415a2cc4e"
  },
  {
    "Description": "Can create and manage all aspects of user flows.",
    "Name": "External ID User Flow Administrator",
    "ObjectId": "6e591065-9bad-43ed-90f3-e9424366d2f0"
  },
  {
    "Description": "Can create and manage the attribute schema available to all user flows.",
    "Name": "External ID User Flow Attribute Administrator",
    "ObjectId": "0f971eea-41eb-4569-a71e-57bb8a3eff1e"
  },
  {
    "Description": "Can configure identity providers for use in direct federation.",
    "Name": "External Identity Provider Administrator",
    "ObjectId": "be2f45a1-457d-42af-a067-6ec1fa63bc45"
  },
  {
    "Description": "Can read everything that a Global Administrator can, but not update anything.",
    "Name": "Global Reader",
    "ObjectId": "f2ef992c-3afb-46b9-b7cf-a126ee74c451"
  },
  {
    "Description": "Can manage all aspects of Microsoft Entra ID and Microsoft services that use Microsoft Entra identities.",
    "Name": "Global Administrator",
    "ObjectId": "62e90394-69f5-4237-9190-012177145e10"
  },
  {
    "Description": "Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.",
    "Name": "Groups Administrator",
    "ObjectId": "fdd7a751-b60b-444a-984c-02652fe8fa1c"
  },
  {
    "Description": "Can invite guest users independent of the \u0027members can invite guests\u0027 setting.",
    "Name": "Guest Inviter",
    "ObjectId": "95e79109-95c0-4d8e-aee3-d01accf2d47b"
  },
  {
    "Description": "Can reset passwords for non-administrators and Helpdesk Administrators.",
    "Name": "Helpdesk Administrator",
    "ObjectId": "729827e3-9c14-49f7-bb1b-9608f156bbb8"
  },
  {
    "Description": "Can manage AD to Azure AD cloud provisioning, Azure AD Connect, and federation settings.",
    "Name": "Hybrid Identity Administrator",
    "ObjectId": "8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2"
  },
  {
    "Description": "Manage access using Azure AD for identity governance scenarios.",
    "Name": "Identity Governance Administrator",
    "ObjectId": "45d8d3c5-c802-45c6-b32a-1d70b5e1e86e"
  },
  {
    "Description": "Has administrative access in the Microsoft 365 Insights app.",
    "Name": "Insights Administrator",
    "ObjectId": "eb1f4a8d-243a-41f0-9fbd-c7cdf6c5ef7c"
  },
  {
    "Description": "Access the analytical capabilities in Microsoft Viva Insights and run custom queries.",
    "Name": "Insights Analyst",
    "ObjectId": "25df335f-86eb-4119-b717-0ff02de207e9"
  },
  {
    "Description": "Can view and share dashboards and insights via the M365 Insights app.",
    "Name": "Insights Business Leader",
    "ObjectId": "31e939ad-9672-4796-9c2e-873181342d2d"
  },
  {
    "Description": "Can manage all aspects of the Intune product.",
    "Name": "Intune Administrator",
    "ObjectId": "3a2c62db-5318-420d-8d74-23affee5d9d5"
  },
  {
    "Description": "Can manage settings for Microsoft Kaizala.",
    "Name": "Kaizala Administrator",
    "ObjectId": "74ef975b-6605-40af-a5d2-b9539d836353"
  },
  {
    "Description": "Can configure knowledge, learning, and other intelligent features.",
    "Name": "Knowledge Administrator",
    "ObjectId": "b5a8dcf3-09d5-43a9-a639-8e29ef291470"
  },
  {
    "Description": "Has access to topic management dashboard and can manage content.",
    "Name": "Knowledge Manager",
    "ObjectId": "744ec460-397e-42ad-a462-8b3f9747a02c"
  },
  {
    "Description": "Can manage product licenses on users and groups.",
    "Name": "License Administrator",
    "ObjectId": "4d6ac14f-3453-41d0-bef9-a3e0c569773a"
  },
  {
    "Description": "Create and manage all aspects of workflows and tasks associated with Lifecycle Workflows in Azure AD.",
    "Name": "Lifecycle Workflows Administrator",
    "ObjectId": "59d46f88-662b-457b-bceb-5c3809e5908f"
  },
  {
    "Description": "Can read security messages and updates in Office 365 Message Center only.",
    "Name": "Message Center Privacy Reader",
    "ObjectId": "ac16e43d-7b2d-40e0-ac05-243ff356ab5b"
  },
  {
    "Description": "Can read messages and updates for their organization in Office 365 Message Center only.",
    "Name": "Message Center Reader",
    "ObjectId": "790c1fb9-7f7d-4f88-86a1-ef1f95c05c1b"
  },
  {
    "Description": "Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications.",
    "Name": "Network Administrator",
    "ObjectId": "d37c8bed-0711-4417-ba38-b4abe66ce4c2"
  },
  {
    "Description": "Can manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish \u0027what\u0027s new\u0027 feature content to end-user\u0027s devices.",
    "Name": "Office Apps Administrator",
    "ObjectId": "2b745bdf-0803-4d80-aa65-822c4493daac"
  },
  {
    "Description": "Do not use - not intended for general use.",
    "Name": "Partner Tier1 Support",
    "ObjectId": "4ba39ca4-527c-499a-b93d-d9b492c50246"
  },
  {
    "Description": "Do not use - not intended for general use.",
    "Name": "Partner Tier2 Support",
    "ObjectId": "e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8"
  },
  {
    "Description": "Can reset passwords for non-administrators and Password Administrators.",
    "Name": "Password Administrator",
    "ObjectId": "966707d0-3269-4727-9be2-8c3a10f19b9d"
  },
  {
    "Description": "Manage all aspects of Entra Permissions Management.",
    "Name": "Permissions Management Administrator",
    "ObjectId": "af78dc32-cf4d-46f9-ba4e-4428526346b5"
  },
  {
    "Description": "Can manage all aspects of the Power BI product.",
    "Name": "Power BI Administrator",
    "ObjectId": "a9ea8996-122f-4c74-9520-8edcd192826c"
  },
  {
    "Description": "Can create and manage all aspects of Microsoft Dynamics 365, PowerApps and Microsoft Flow.",
    "Name": "Power Platform Administrator",
    "ObjectId": "11648597-926c-4cf3-9c36-bcebb0ba8dcc"
  },
  {
    "Description": "Can manage all aspects of printers and printer connectors.",
    "Name": "Printer Administrator",
    "ObjectId": "644ef478-e28f-4e28-b9dc-3fdde9aa0b1f"
  },
  {
    "Description": "Can manage all aspects of printers and printer connectors.",
    "Name": "Printer Technician",
    "ObjectId": "e8cef6f1-e4bd-4ea8-bc07-4b8d950f4477"
  },
  {
    "Description": "Allowed to view, set and reset authentication method information for any user (admin or non-admin).",
    "Name": "Privileged Authentication Administrator",
    "ObjectId": "7be44c8a-adaf-4e2a-84d6-ab2649e08a13"
  },
  {
    "Description": "Can manage role assignments in Azure AD, and all aspects of Privileged Identity Management.",
    "Name": "Privileged Role Administrator",
    "ObjectId": "e8611ab8-c189-46e8-94e1-60213ab1f814"
  },
  {
    "Description": "Can read sign-in and audit reports.",
    "Name": "Reports Reader",
    "ObjectId": "4a5d8f65-41da-4de4-8968-e035b65339cf"
  },
  {
    "Description": "Can create and manage all aspects of Microsoft Search settings.",
    "Name": "Search Administrator",
    "ObjectId": "0964bb5e-9bdb-4d7b-ac29-58e794862a40"
  },
  {
    "Description": "Can create and manage the editorial content such as bookmarks, Q and As, locations, floorplan.",
    "Name": "Search Editor",
    "ObjectId": "8835291a-918c-4fd7-a9ce-faa49f0cf7d9"
  },
  {
    "Description": "Security Administrator allows ability to read and manage security configuration and reports.",
    "Name": "Security Administrator",
    "ObjectId": "194ae4cb-b126-40b2-bd5b-6091b380977d"
  },
  {
    "Description": "Creates and manages security events.",
    "Name": "Security Operator",
    "ObjectId": "5f2222b1-57c3-48ba-8ad5-d4759f1fde6f"
  },
  {
    "Description": "Can read security information and reports in Azure AD and Office 365.",
    "Name": "Security Reader",
    "ObjectId": "5d6b6bb7-de71-4623-b4af-96380a352509"
  },
  {
    "Description": "Can read service health information and manage support tickets.",
    "Name": "Service Support Administrator",
    "ObjectId": "f023fd81-a637-4b56-95fd-791ac0226033"
  },
  {
    "Description": "Can manage all aspects of the SharePoint service.",
    "Name": "SharePoint Administrator",
    "ObjectId": "f28a1f50-f6e7-4571-818b-6a12f2af6b6c"
  },
  {
    "Description": "Can manage all aspects of the Skype for Business product.",
    "Name": "Skype for Business Administrator",
    "ObjectId": "75941009-915a-4869-abe7-691bff18279e"
  },
  {
    "Description": "Can manage the Microsoft Teams service.",
    "Name": "Teams Administrator",
    "ObjectId": "69091246-20e8-4a56-aa4d-066075b2a7a8"
  },
  {
    "Description": "Can manage calling and meetings features within the Microsoft Teams service.",
    "Name": "Teams Communications Administrator",
    "ObjectId": "baf37b3a-610e-45da-9e62-d9d1e5e8914b"
  },
  {
    "Description": "Can troubleshoot communications issues within Teams using advanced tools.",
    "Name": "Teams Communications Support Engineer",
    "ObjectId": "f70938a0-fc10-4177-9e90-2178f8765737"
  },
  {
    "Description": "Can troubleshoot communications issues within Teams using basic tools.",
    "Name": "Teams Communications Support Specialist",
    "ObjectId": "fcf91098-03e3-41a9-b5ba-6f0ec8188a12"
  },
  {
    "Description": "Can perform management related tasks on Teams certified devices.",
    "Name": "Teams Devices Administrator",
    "ObjectId": "3d762c5a-1b6c-493f-843e-55a3b42923d4"
  },
  {
    "Description": "Can see only tenant level aggregates in Microsoft 365 Usage Analytics and Productivity Score.",
    "Name": "Usage Summary Reports Reader",
    "ObjectId": "75934031-6c7e-415a-99d7-48dbd49e875e"
  },
  {
    "Description": "Can manage all aspects of users and groups, including resetting passwords for limited admins.",
    "Name": "User Administrator",
    "ObjectId": "fe930be7-5e62-47db-91af-98c3a49a38b1"
  },
  {
    "Description": "Manage and share Virtual Visits information and metrics from admin centers or the Virtual Visits app.",
    "Name": "Virtual Visits Administrator",
    "ObjectId": "e300d9e7-4a2b-4295-9eff-f1c78b36cc98"
  },
  {
    "Description": "Can provision and manage all aspects of Cloud PCs.",
    "Name": "Windows 365 Administrator",
    "ObjectId": "11451d60-acb2-45eb-a7d6-43d0f0125c13"
  },
  {
    "Description": "Can create and manage all aspects of Windows Update deployments through the Windows Update for Business deployment service.",
    "Name": "Windows Update Deployment Administrator",
    "ObjectId": "32696413-001a-46ae-978c-ce0f6b3620d2"
  },
  {
    "Description": "Workplace Device Join",
    "Name": "Workplace Device Join",
    "ObjectId": "c34f683f-4d5a-4403-affd-6615e00e3a7f"
  },
  {
    "Description": "Manage all aspects of Yammer.",
    "Name": "Yammer Administrator",
    "ObjectId": "810a2642-a034-447f-a5e8-41beaa378541"
  }
]