| microsoft.azure.serviceHealth/allEntities/allTasks |
Read and configure Azure Service Health |
| microsoft.azure.supportTickets/allEntities/allTasks |
Create and manage Azure support tickets |
| microsoft.directory/accessReviews/definitions.applications/allProperties/allTasks |
Manage access reviews of application role assignments in Microsoft Entra ID |
| microsoft.directory/accessReviews/definitions.directoryRoles/allProperties/read |
Read all properties of access reviews for Microsoft Entra role assignments |
| microsoft.directory/accessReviews/definitions.entitlementManagement/allProperties/allTasks |
Manage access reviews for access package assignments in entitlement management |
| microsoft.directory/accessReviews/definitions.groups/allProperties/read |
Read all properties of access reviews for membership in Security and Microsoft 365 groups, including role-assignable groups. |
| microsoft.directory/accessReviews/definitions.groups/allProperties/update |
Update all properties of access reviews for membership in Security and Microsoft 365 groups, excluding role-assignable groups. |
| microsoft.directory/accessReviews/definitions.groups/create |
Create access reviews for membership in Security and Microsoft 365 groups. |
| microsoft.directory/accessReviews/definitions.groups/delete |
Delete access reviews for membership in Security and Microsoft 365 groups. |
| microsoft.directory/contacts/basic/update |
Update basic properties on contacts |
| microsoft.directory/contacts/create |
Create contacts |
| microsoft.directory/contacts/delete |
Delete contacts |
| microsoft.directory/deletedItems.groups/restore |
Restore soft deleted groups to original state |
| microsoft.directory/deletedItems.users/restore |
Restore soft deleted users to original state |
| microsoft.directory/entitlementManagement/allProperties/allTasks |
Create and delete resources, and read and update all properties in Microsoft Entra entitlement management |
| microsoft.directory/groups.unified/assignedLabels/update |
Update the assigned labels property on Microsoft 365 groups of assigned membership type, excluding role-assignable groups |
| microsoft.directory/groups/assignLicense |
Assign product licenses to groups for group-based licensing |
| microsoft.directory/groups/basic/update |
Update basic properties on Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/classification/update |
Update the classification property on Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/create |
Create Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/delete |
Delete Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/dynamicMembershipRule/update |
Update the dynamic membership rule on Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/groupType/update |
Update properties that would affect the group type of Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/hiddenMembers/read |
Read hidden members of Security groups and Microsoft 365 groups, including role-assignable groups |
| microsoft.directory/groups/members/update |
Update members of Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/onPremWriteBack/update |
Update Microsoft Entra groups to be written back to on-premises with Microsoft Entra Connect |
| microsoft.directory/groups/owners/update |
Update owners of Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/groups/reprocessLicenseAssignment |
Reprocess license assignments for group-based licensing |
| microsoft.directory/groups/restore |
Restore groups from soft-deleted container |
| microsoft.directory/groups/settings/update |
Update settings of groups |
| microsoft.directory/groups/visibility/update |
Update the visibility property of Security groups and Microsoft 365 groups, excluding role-assignable groups |
| microsoft.directory/oAuth2PermissionGrants/allProperties/allTasks |
Create and delete OAuth 2.0 permission grants, and read and update all properties
 |
| microsoft.directory/onPremisesSynchronization/standard/read |
Read standard on-premises directory synchronization information |
| microsoft.directory/policies/standard/read |
Read basic properties on policies |
| microsoft.directory/servicePrincipals/appRoleAssignedTo/update |
Update service principal role assignments |
| microsoft.directory/users/assignLicense |
Manage user licenses |
| microsoft.directory/users/basic/update |
Update basic properties on users |
| microsoft.directory/users/convertExternalToInternalMemberUser |
Convert external user to internal user |
| microsoft.directory/users/create |
Add users
 |
| microsoft.directory/users/delete |
Delete users
 |
| microsoft.directory/users/disable |
Disable users
 |
| microsoft.directory/users/enable |
Enable users
 |
| microsoft.directory/users/invalidateAllRefreshTokens |
Force sign-out by invalidating user refresh tokens
 |
| microsoft.directory/users/inviteGuest |
Invite guest users |
| microsoft.directory/users/lifeCycleInfo/read |
Read lifecycle information of users, such as employeeLeaveDateTime
 |
| microsoft.directory/users/manager/update |
Update manager for users |
| microsoft.directory/users/password/update |
Reset passwords for all users
 |
| microsoft.directory/users/photo/update |
Update photo of users |
| microsoft.directory/users/reprocessLicenseAssignment |
Reprocess license assignments for users |
| microsoft.directory/users/restore |
Restore deleted users |
| microsoft.directory/users/sponsors/update |
Update sponsors of users |
| microsoft.directory/users/usageLocation/update |
Update usage location of users |
| microsoft.directory/users/userPrincipalName/update |
Update User Principal Name of users
 |
| microsoft.office365.serviceHealth/allEntities/allTasks |
Read and configure Service Health in the Microsoft 365 admin center |
| microsoft.office365.supportTickets/allEntities/allTasks |
Create and manage Microsoft 365 service requests |
| microsoft.office365.webPortal/allEntities/standard/read |
Read basic properties on all resources in the Microsoft 365 admin center |