Azure AD Built-in Roller

Azure Active Directory’de (Azure AD),  bir yöneticinin veya yönetici olmayan kişinin Azure AD kaynaklarını yönetmesi gerekiyorsa, onlara ihtiyaç duydukları izinleri sağlayan bir Azure AD rolü atanabilir. Örneğin, kullanıcı eklemeye veya  değiştirmeye, kullanıcı parolalarını sıfırlamaya, kullanıcı lisanslarını yönetmeye veya alan adlarını yönetmeye izin verecek roller atayabilirsiniz.

Azure AD kaynaklarının yönetimine izin vermek için atayabileceğiniz Azure AD rolleri aşağıdaki tabloda listelenmiştir.

RoleDescriptionTemplate ID
Application AdministratorCan create and manage all aspects of app registrations and enterprise apps.9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3
Application DeveloperCan create application registrations independent of the ‘Users can register applications’ setting.cf1c38e5-3621-4004-a7cb-879624dced7c
Attack Payload AuthorCan create attack payloads that an administrator can initiate later.9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f
Attack Simulation AdministratorCan create and manage all aspects of attack simulation campaigns.c430b396-e693-46cc-96f3-db01bf8bb62a
Authentication AdministratorCan access to view, set and reset authentication method information for any non-admin user.c4e39bd9-1100-46d3-8c65-fb160da0071f
Authentication Policy AdministratorCan create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials.0526716b-113d-4c15-b2c8-68e3c22b9f80
Azure AD Joined Device Local AdministratorUsers assigned to this role are added to the local administrators group on Azure AD-joined devices.9f06204d-73c1-4d4c-880a-6edb90606fd8
Azure DevOps AdministratorCan manage Azure DevOps organization policy and settings.e3973bdf-4987-49ae-837a-ba8e231c7286
Azure Information Protection AdministratorCan manage all aspects of the Azure Information Protection product.7495fdc4-34c4-4d15-a289-98788ce399fd
B2C IEF Keyset AdministratorCan manage secrets for federation and encryption in the Identity Experience Framework (IEF).aaf43236-0c0d-4d5f-883a-6955382ac081
B2C IEF Policy AdministratorCan create and manage trust framework policies in the Identity Experience Framework (IEF).3edaf663-341e-4475-9f94-5c398ef6c070
Billing AdministratorCan perform common billing related tasks like updating payment information.b0f54661-2d74-4c50-afa3-1ec803f12efe
Cloud App Security AdministratorCan manage all aspects of the Cloud App Security product.892c5842-a9a6-463a-8041-72aa08ca3cf6
Cloud Application AdministratorCan create and manage all aspects of app registrations and enterprise apps except App Proxy.158c047a-c907-4556-b7ef-446551a6b5f7
Cloud Device AdministratorLimited access to manage devices in Azure AD.7698a772-787b-4ac8-901f-60d6b08affd2
Compliance AdministratorCan read and manage compliance configuration and reports in Azure AD and Microsoft 365.17315797-102d-40b4-93e0-432062caca18
Compliance Data AdministratorCreates and manages compliance content.e6d1a23a-da11-4be4-9570-befc86d067a7
Conditional Access AdministratorCan manage Conditional Access capabilities.b1be1c3e-b65d-4f19-8427-f6fa0d97feb9
Customer LockBox Access ApproverCan approve Microsoft support requests to access customer organizational data.5c4f9dcd-47dc-4cf7-8c9a-9e4207cbfc91
Desktop Analytics AdministratorCan access and manage Desktop management tools and services.38a96431-2bdf-4b4c-8b6e-5d3d8abac1a4
Directory ReadersCan read basic directory information. Commonly used to grant directory read access to applications and guests.88d8e3e3-8f55-4a1e-953a-9b9898b8876b
Directory Synchronization AccountsOnly used by Azure AD Connect service.d29b2b05-8046-44ba-8758-1e26182fcf32
Directory WritersCan read and write basic directory information. For granting access to applications, not intended for users.9360feb5-f418-4baa-8175-e2a00bac4301
Domain Name AdministratorCan manage domain names in cloud and on-premises.8329153b-31d0-4727-b945-745eb3bc5f31
Dynamics 365 AdministratorCan manage all aspects of the Dynamics 365 product.44367163-eba1-44c3-98af-f5787879f96a
Exchange AdministratorCan manage all aspects of the Exchange product.29232cdf-9323-42fd-ade2-1d097af3e4de
Exchange Recipient AdministratorCan create or update Exchange Online recipients within the Exchange Online organization.31392ffb-586c-42d1-9346-e59415a2cc4e
External ID User Flow AdministratorCan create and manage all aspects of user flows.6e591065-9bad-43ed-90f3-e9424366d2f0
External ID User Flow Attribute AdministratorCan create and manage the attribute schema available to all user flows.0f971eea-41eb-4569-a71e-57bb8a3eff1e
External Identity Provider AdministratorCan configure identity providers for use in direct federation.be2f45a1-457d-42af-a067-6ec1fa63bc45
Global AdministratorCan manage all aspects of Azure AD and Microsoft services that use Azure AD identities.62e90394-69f5-4237-9190-012177145e10
Global ReaderCan read everything that a Global Administrator can, but not update anything.f2ef992c-3afb-46b9-b7cf-a126ee74c451
Groups AdministratorMembers of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.fdd7a751-b60b-444a-984c-02652fe8fa1c
Guest InviterCan invite guest users independent of the ‘members can invite guests’ setting.95e79109-95c0-4d8e-aee3-d01accf2d47b
Helpdesk AdministratorCan reset passwords for non-administrators and Helpdesk Administrators.729827e3-9c14-49f7-bb1b-9608f156bbb8
Hybrid Identity AdministratorCan manage AD to Azure AD cloud provisioning, Azure AD Connect, and federation settings.8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2
Identity Governance AdministratorManage access using Azure AD for identity governance scenarios.45d8d3c5-c802-45c6-b32a-1d70b5e1e86e
Insights AdministratorHas administrative access in the Microsoft 365 Insights app.eb1f4a8d-243a-41f0-9fbd-c7cdf6c5ef7c
Insights Business LeaderCan view and share dashboards and insights via the M365 Insights app.31e939ad-9672-4796-9c2e-873181342d2d
Intune AdministratorCan manage all aspects of the Intune product.3a2c62db-5318-420d-8d74-23affee5d9d5
Kaizala AdministratorCan manage settings for Microsoft Kaizala.74ef975b-6605-40af-a5d2-b9539d836353
Knowledge AdministratorCan configure knowledge, learning, and other intelligent features.b5a8dcf3-09d5-43a9-a639-8e29ef291470
Knowledge ManagerCan organize, create, manage, and promote topics and knowledge.744ec460-397e-42ad-a462-8b3f9747a02c
License AdministratorCan manage product licenses on users and groups.4d6ac14f-3453-41d0-bef9-a3e0c569773a
Message Center Privacy ReaderCan read security messages and updates in Office 365 Message Center only.ac16e43d-7b2d-40e0-ac05-243ff356ab5b
Message Center ReaderCan read messages and updates for their organization in Office 365 Message Center only.790c1fb9-7f7d-4f88-86a1-ef1f95c05c1b
Modern Commerce UserCan manage commercial purchases for a company, department or team.d24aef57-1500-4070-84db-2666f29cf966
Network AdministratorCan manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications.d37c8bed-0711-4417-ba38-b4abe66ce4c2
Office Apps AdministratorCan manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish ‘what’s new’ feature content to end-user’s devices.2b745bdf-0803-4d80-aa65-822c4493daac
Partner Tier1 SupportDo not use – not intended for general use.4ba39ca4-527c-499a-b93d-d9b492c50246
Partner Tier2 SupportDo not use – not intended for general use.e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8
Password AdministratorCan reset passwords for non-administrators and Password Administrators.966707d0-3269-4727-9be2-8c3a10f19b9d
Power BI AdministratorCan manage all aspects of the Power BI product.a9ea8996-122f-4c74-9520-8edcd192826c
Power Platform AdministratorCan create and manage all aspects of Microsoft Dynamics 365, PowerApps and Microsoft Flow.11648597-926c-4cf3-9c36-bcebb0ba8dcc
Printer AdministratorCan manage all aspects of printers and printer connectors.644ef478-e28f-4e28-b9dc-3fdde9aa0b1f
Printer TechnicianCan register and unregister printers and update printer status.e8cef6f1-e4bd-4ea8-bc07-4b8d950f4477
Privileged Authentication AdministratorCan access to view, set and reset authentication method information for any user (admin or non-admin).7be44c8a-adaf-4e2a-84d6-ab2649e08a13
Privileged Role AdministratorCan manage role assignments in Azure AD, and all aspects of Privileged Identity Management.e8611ab8-c189-46e8-94e1-60213ab1f814
Reports ReaderCan read sign-in and audit reports.4a5d8f65-41da-4de4-8968-e035b65339cf
Search AdministratorCan create and manage all aspects of Microsoft Search settings.0964bb5e-9bdb-4d7b-ac29-58e794862a40
Search EditorCan create and manage the editorial content such as bookmarks, Q and As, locations, floorplan.8835291a-918c-4fd7-a9ce-faa49f0cf7d9
Security AdministratorCan read security information and reports, and manage configuration in Azure AD and Office 365.194ae4cb-b126-40b2-bd5b-6091b380977d
Security OperatorCreates and manages security events.5f2222b1-57c3-48ba-8ad5-d4759f1fde6f
Security ReaderCan read security information and reports in Azure AD and Office 365.5d6b6bb7-de71-4623-b4af-96380a352509
Service Support AdministratorCan read service health information and manage support tickets.f023fd81-a637-4b56-95fd-791ac0226033
SharePoint AdministratorCan manage all aspects of the SharePoint service.f28a1f50-f6e7-4571-818b-6a12f2af6b6c
Skype for Business AdministratorCan manage all aspects of the Skype for Business product.75941009-915a-4869-abe7-691bff18279e
Teams AdministratorCan manage the Microsoft Teams service.69091246-20e8-4a56-aa4d-066075b2a7a8
Teams Communications AdministratorCan manage calling and meetings features within the Microsoft Teams service.baf37b3a-610e-45da-9e62-d9d1e5e8914b
Teams Communications Support EngineerCan troubleshoot communications issues within Teams using advanced tools.f70938a0-fc10-4177-9e90-2178f8765737
Teams Communications Support SpecialistCan troubleshoot communications issues within Teams using basic tools.fcf91098-03e3-41a9-b5ba-6f0ec8188a12
Teams Devices AdministratorCan perform management related tasks on Teams certified devices.3d762c5a-1b6c-493f-843e-55a3b42923d4
Usage Summary Reports ReaderCan see only tenant level aggregates in Microsoft 365 Usage Analytics and Productivity Score.75934031-6c7e-415a-99d7-48dbd49e875e
User AdministratorCan manage all aspects of users and groups, including resetting passwords for limited admins.fe930be7-5e62-47db-91af-98c3a49a38b1
Windows Update Deployment AdministratorCreate and manage all aspects of Windows Update deployments through the Windows Update for Business deployment service.32696413-001a-46ae-978c-ce0f6b3620d2

Kaynak: https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference