What changed on this day
260 changes were tracked across 6 Microsoft Entra products. The leading updates include Configure Microsoft Entra for increased security (Preview); Security Administrator; Security Administrator.
Daily.Entra.News260 changes were tracked across 6 Microsoft Entra products. The leading updates include Configure Microsoft Entra for increased security (Preview); Security Administrator; Security Administrator.
Microsoft 365 Migration Administrator
This is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
This is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
A Microsoft Entra documentation page was updated: Microsoft 365 Migration Administrator.
Global Administrator
Global Reader
This article lists the Microsoft Entra built-in roles you can assign to allow management of Microsoft Entra resources. For information about how to assign roles, see [Assign Microsoft Entra roles](manage-roles-portal.md). If you are looking for roles to manage Azure resources, see [Azure built-in roles](/azure/role-based-access-control/built-in-roles).
User Administrator
Hybrid Identity Administrator
Directory Readers
Partner Tier2 Support
Intune Administrator
Directory Writers
Partner Tier1 Support
Windows 365 Administrator
Privileged Role Administrator
SharePoint Administrator
Teams Administrator
Exchange Administrator
Helpdesk Administrator
Groups Administrator
Yammer Administrator
role
IoT Device Administrator
AI Administrator
Dynamics 365 Business Central Administrator
Microsoft Graph Data Connect Administrator
role
Guest Inviter
Microsoft Hardware Warranty Administrator
SharePoint Embedded Administrator
Teams Telephony Administrator
Attribute Assignment Administrator
Knowledge Administrator
Microsoft Hardware Warranty Specialist
role
role
Viva Glint Tenant Administrator
Viva Pulse Administrator
Virtual Visits Administrator
Microsoft 365 Backup Administrator
User Experience Success Manager
Attribute Assignment Reader
Insights Analyst
Knowledge Manager
Teams Communications Administrator
Viva Goals Administrator
Skype for Business Administrator
Attack Payload Author
Attack Simulation Administrator
Insights Administrator
License Administrator
Service Support Administrator
People Administrator
role
Attribute Definition Administrator
Attribute Definition Reader
Assign the Dynamics 365 Administrator role to users who need to manage all aspects of Dynamics 365 services, including configuration, user management, and support tickets.
Extended Directory User Administrator
Fabric Administrator
Modern Commerce Administrator
Organizational Data Source Administrator
Power Platform Administrator
role
role
Teams Communications Support Specialist
Domain Name Administrator
Edge Administrator
role
Teams Communications Support Engineer
Desktop Analytics Administrator
Insights Business Leader
Permissions Management Administrator
Kaizala Administrator
Printer Technician
Search Administrator
Search Editor
Tenant Creator
Exchange Recipient Administrator
Message Center Privacy Reader
Message Center Reader
Microsoft Entra Joined Device Local Administrator
Teams Devices Administrator
author: shlipsey3
Azure DevOps Administrator
Microsoft Entra Domain Services supports TLS versions 1.0 and 1.1, but they're disabled by default.
role
role
Teams Reader
Printer Administrator
Windows Update Deployment Administrator
This is a [privileged role](../privileged-roles-permissions.md). Assign the User Administrator role to users who need to do the following:
To enable group writeback, you must have:
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can enable, disable, and delete devices in Microsoft Entra ID and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.
manager: CelesteDG
author: MicrosoftGuyJFlo
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage role assignments in Microsoft Entra ID, as well as within Microsoft Entra Privileged Identity Management. They can create and manage groups that can be assigned to Microsoft Entra roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units.
> [!IMPORTANT]
A Microsoft Entra documentation page was updated: Ai Administrator.
A Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
A Microsoft Entra documentation page was updated: Azure Devops Administrator.
A Microsoft Entra documentation page was updated: Billing Administrator.
A Microsoft Entra documentation page was updated: Compliance Administrator.
A Microsoft Entra documentation page was updated: Compliance Data Administrator.
A Microsoft Entra documentation page was updated: Customer Lockbox Access Approver.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
A Microsoft Entra documentation page was updated: Directory Readers.
A Microsoft Entra documentation page was updated: Dynamics 365 Administrator.
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
A Microsoft Entra documentation page was updated: Edge Administrator.
A Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
A Microsoft Entra documentation page was updated: Fabric Administrator.
A Microsoft Entra documentation page was updated: Groups Administrator.
A Microsoft Entra documentation page was updated: Guest Inviter.
A Microsoft Entra documentation page was updated: Insights Administrator.
A Microsoft Entra documentation page was updated: Insights Analyst.
A Microsoft Entra documentation page was updated: Insights Business Leader.
A Microsoft Entra documentation page was updated: Iot Device Administrator.
A Microsoft Entra documentation page was updated: Kaizala Administrator.
A Microsoft Entra documentation page was updated: Knowledge Administrator.
A Microsoft Entra documentation page was updated: Knowledge Manager.
A Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
A Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
A Microsoft Entra documentation page was updated: Microsoft Entra Joined Device Local Administrator.
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
A Microsoft Entra documentation page was updated: Network Administrator.
A Microsoft Entra documentation page was updated: Office Apps Administrator.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
A Microsoft Entra documentation page was updated: Organizational Messages Approver.
A Microsoft Entra documentation page was updated: Organizational Messages Writer.
A Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
A Microsoft Entra documentation page was updated: Printer Administrator.
A Microsoft Entra documentation page was updated: Printer Technician.
A Microsoft Entra documentation page was updated: Search Administrator.
A Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
A Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
A Microsoft Entra documentation page was updated: Teams Devices Administrator.
A Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
A Microsoft Entra documentation page was updated: Tenant Creator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
A Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
A Microsoft Entra documentation page was updated: Viva Goals Administrator.
A Microsoft Entra documentation page was updated: Viva Pulse Administrator.
A Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
A Microsoft Entra documentation page was updated: Yammer Administrator.
Microsoft Entra seamless single sign-on (Seamless SSO) is a legacy authentication feature designed to provide passwordless access for domain-joined devices that are not hybrid Microsoft Entra ID joined. Seamless SSO relies on Kerberos authentication and is primarily beneficial for older operating systems like Windows 7 and Windows 8.1, which do not support Primary Refresh Tokens (PRT). If these legacy systems are no longer present in the environment, continuing to use Seamless SSO introduces unnecessary complexity and potential security exposure. Threat actors could exploit misconfigured or stale Kerberos tickets, or compromise the `AZUREADSSOACC` computer account in Active Directory, which holds the Kerberos decryption key used by Microsoft Entra ID. Once compromised, attackers could impersonate users, bypass modern authentication controls, and gain unauthorized access to cloud resources. Disabling Seamless SSO in environments where it is no longer needed reduces the attack surface and enforces the use of modern, token-based authentication mechanisms that offer stronger protections.
Authentication Administrator
Privileged Authentication Administrator
Authentication Policy Administrator
Authentication Extensibility Administrator
The `getPreferredAuthConfiguration` method requires the Microsoft Authenticator app to be installed on the device. If the Microsoft Authenticator app isn't installed, the method returns `None`.
This is a [privileged role](../privileged-roles-permissions.md). Assign the Privileged Authentication Administrator role to users who need to do the following:
This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:
author: justinha
Users with this role **cannot** do the following:
This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Extensibility Administrator role to users who need to do the following tasks:
A Microsoft Entra documentation page was updated: Authentication Table Include.
Password Administrator
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Microsoft Entra Connect deployments vary from a single forest Express mode installation to complex deployments that are synced across multiple forests by using custom synchronization rules. Because of the large number of configuration options and mechanisms, it's essential to understand what settings are in effect and be able to quickly deploy a server with an identical configuration. This feature introduces the ability to catalog the configuration of a specific synchronization server and import the settings into a new deployment. You can compare different synchronization settings snapshots to easily visualize the differences between two servers or the same server over time.
author: justinha
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage (read, add, verify, update, and delete) domain names. They can also read directory information about users, groups, and applications, as these objects possess domain dependencies. For on-premises environments, users with this role can configure domain names for federation so that associated users are always authenticated on-premises. These users can then sign into Microsoft Entra based services with their on-premises passwords via single sign-on. Federation settings need to be synced via Microsoft Entra Connect, so users also have permissions to manage Microsoft Entra Connect.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).
author: MicrosoftGuyJFlo
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).
> [!NOTE]
author: MicrosoftGuyJFlo
author: aanjusingh
- Results are logged in the **Conditional Access** and **Report-only** tabs of the Sign-in log details.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).
Attribute Log Reader
Attribute Log Administrator
Usage Summary Reports Reader
Reports Reader
The following table is a list of events that are logged with the new auditing feature. To view the events, use the Event Viewer and view the Application log.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview compliance portal, Azure portal, and Device Management admin center.
Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
A Microsoft Entra documentation page was updated: Reports Reader.
A Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
This example includes custom security attributes that you could add to your tenant. Use the attribute set `HRConfidentialData` and then add the following attributes to:
Attribute Provisioning Administrator
Attribute Provisioning Reader
Directory Synchronization Accounts
This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Administrator role to users who need to do the following tasks:
This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Reader role to users who need to do the following tasks:
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
Security Administrator
Security Reader
Security Operator
A Microsoft Entra documentation page was updated: Cloud App Security Administrator.
Azure Information Protection Administrator
role
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
Microsoft Entra ID will update the guest authentication experience for B2B collaboration starting July 2025, completing by December 2025. Guest users will sign in via their home organization’s sign-in page, enhancing usability and reducing confusion. No administrative action is required, but review your B2B configuration.
role
The default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).
A Microsoft Entra documentation page was updated: Organizational Branding Administrator.
Application Administrator
role
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role have the same permissions as the Application Administrator role, excluding the ability to manage application proxy. This role grants the ability to create and manage all aspects of enterprise applications and application registrations. Users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
Identity Governance Administrator
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
Application Developer
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create application registrations when the "Users can register applications" setting is set to No. This role also grants permission to consent on one's own behalf when the "Users can consent to apps accessing company data on their behalf" setting is set to No. Users assigned to this role are added as owners when creating new application registrations.
To enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Microsoft Entra or an administrator creates a single tenant non-Microsoft application in Microsoft Entra ID and uses one of the following relevant certificate management options for the credentials.
To configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have the ability to manage Microsoft Entra Conditional Access settings.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create, manage and deploy provisioning configuration setup from Active Directory to Microsoft Entra ID using Cloud Provisioning as well as manage Microsoft Entra Connect, pass-through authentication (PTA), password hash synchronization (PHS), seamless single sign-on (seamless SSO), and federation settings. Does not have access to manage Microsoft Entra Connect Health. Users can also troubleshoot and monitor logs using this role.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, as well as the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Lifecycle Workflows Administrator
This is a [privileged role](../privileged-roles-permissions.md). Assign the Lifecycle Workflows Administrator role to users who need to do the following tasks:
External Identity Provider Administrator
B2C IEF Keyset Administrator
B2C IEF Policy Administrator
External ID User Flow Administrator
External ID User Flow Attribute Administrator
> [!VIDEO https://www.youtube.com/embed/_CD3shvqpx4?si=cYvAO8CyXuI9YPiS]
A Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:
This is a [privileged role](../privileged-roles-permissions.md). User can create and manage policy keys and secrets for token encryption, token signatures, and claim encryption/decryption. By adding new keys to existing key containers, this limited administrator can roll over secrets as needed without impacting existing applications. This user can see the full content of these secrets and their expiration dates even after their creation.
Effective July 1, 2025, external users will lose access to content shared via SharePoint One Time Passcode (OTP) before enabling Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B. Resharing is required to restore access. Notify users and update internal documentation accordingly.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.
Global Secure Access Administrator
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
A Microsoft Entra documentation page was updated: Global Secure Access Administrator.
1. Choose the right connector group with the connector deployed in the service endpoint subnet.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Global Secure Access Log Reader
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.