Administrator Roles Flashcards
(35 cards)
Application Administrator
Can administer enterprise applications, application registrations, and application proxy settings.
Application Developer
Can create application registrations.
Authentication Administrator
Can view current authentication method settings. Can set or reset non-password credentials. Can force MFA on next sign on.
Billing Administrator
Can purchase and manage subscriptions. Can manage support tickets and monitor service health.
Cloud Application Administrator
Can manage all aspects of enterprise applications and registrations, but cannot manage application proxy.
Cloud Device Administrator
Can enable, disable, and remove devices in Azure AD. Can view Windows 10 BitLocker Drive Encryption Keys through Azure portal.
Compliance Administrator
Manage features in the Microsoft 365 compliance Center, Microsoft 365 Admin Center and Microsoft 365 Security and Compliance Center.
Conditional Access Administrator
Administrative rights over Azure AD conditional access configuration.
Customer Lockbox access approver
Manage customer lockbox requests. Can also enable and disable the customer lockbox feature.
Device Administrators
Users assigned this role will become local administrators on all computers running Windows 10 that are joined to Azure AD.
Directory Readers
Role for applications that do not support consent framework. Should not be assigned to users.
Directory Synchronization Accounts
Assigned to the Azure AD Connect service and not used for user accounts.
Directory Writers
A legacy role assigned to applications that do not support the consent framework. Should only be assigned to applications and not user accounts.
Dynamics 365 Administrator/ CRM Administrator
Administrative access to Dynamics 365 Online
Exchange Administrator
Administrative Access to Exchange Online
Global Administrator/ Company Administrator
Administrative access to all Azure AD features. This includes administrative access to services that use Azure AD Identities including Microsoft 365 security center, Microsoft 365 compliance center, Exchange Online, SharePoint Online, and Skype for Business Online. The account used to sign up for the tenancy becomes the global admin. Global admins can reset the password of any user, including other global admins.
Guest Inviter
Can manage Azure AD B2B guest user invitations.
Information Protection Administrator
Has the ability to manage all aspects of Azure Information Protection including configuring labels, managing protection templates, and activating protection.
Intune Administrator
Has full administrative rights to Microsoft Intune
License Administrator
Can manage license assignments on users and groups. Cannot purchase or manage subscriptions.
Message Center Reader
Can monitor notification and Microsoft advisories in the Microsoft 365 Message Center.
Password Administrator / Helpdesk Administrator
Able to perform the following tasks for all users except those that have administrative roles:
- Change passwords
- Invalidate refresh tokens
- Manage service requests
- Monitor service health
Power BI Administrator
Has administrator permissions over Power BI
Privileged Role Administrator
Can manage all aspects of Azure AD Privileged Identity Management. Can manage role assignments in Azure AD.