Microsoft Entra ID

Microsoft Entra built-in roles

In brief

Describes the Microsoft Entra built-in roles and permissions.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

| Teams Reader | Read everything in the Teams admin center, but not update anything. | 1076ac91-f3d9-41a7-a339-dcdf5f480acc | | Teams Telephony Administrator | Manage voice and telephony features and troubleshoot communication issues within the Microsoft Teams service. | aa38014f-0993-46e9-9b45-30501a20909d | | Tenant Creator | Create new Microsoft Entra or Azure AD B2C tenants. | 112ca1a2-15ad-4102-995e-45b0bc479a6a | | Tenant Governance Administrator | Manage all capabilities in the Microsoft Entra Tenant Governance service.
Privileged label icon.
| 1981f584-96e9-4a6f-95b0-f522373f8fae | | Tenant Governance Reader | Can read all tenant governance data. | e0a4caa6-fe82-443f-b92f-d87341d17b2e | | Tenant Governance Relationship Administrator | Can initiate governance relationships and terminate them. | b8e31d83-1534-480f-9b10-0338ded51b7e | | Tenant Governance Relationship Reader | Can read tenant governance relationships and relevant objects. | 124577f8-48ed-456a-839f-13b419002e33 |