AI Administrator
PrivilegedEnabled
Description
Manage all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365.
Details
Assign the AI Administrator role to users who need to do the following tasks:
- Manage all aspects of Microsoft 365 Copilot
- Manage AI-related enterprise services, extensibility, and copilot agents from the Integrated apps page in the Microsoft 365 admin center
- Manage admin consent request policies in Microsoft Entra ID
- Approve and publish line-of-business copilot agents
- Allow users to install an app or install an app for users in the organization if the app does not require permission
- Read and configure Azure and Microsoft 365 service health dashboards
- View usage reports, adoption insights, and organizational insight
- Create and manage support tickets in Azure and the Microsoft 365 admin center
- Manage the full lifecycle of agent identities, agent identity blueprints, agent identity blueprint principals, and agent users including restoration of deleted items
Directory Actions70
| Action | Condition |
|---|---|
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | null |
microsoft.directory/agentIdentities/allProperties/read | null |
microsoft.directory/agentIdentities/appRoleAssignedTo/update | null |
microsoft.directory/agentIdentities/authentication/update | null |
microsoft.directory/agentIdentities/basic/update | null |
microsoft.directory/agentIdentities/create | null |
microsoft.directory/agentIdentities/delete | null |
microsoft.directory/agentIdentities/disable | null |
microsoft.directory/agentIdentities/enable | null |
microsoft.directory/agentIdentities/owners/update | null |
microsoft.directory/agentIdentities/tag/update | null |
microsoft.directory/agentIdentityBlueprintPrincipals/allProperties/read | null |
microsoft.directory/agentIdentityBlueprintPrincipals/appRoleAssignedTo/update | null |
microsoft.directory/agentIdentityBlueprintPrincipals/authentication/update | null |
microsoft.directory/agentIdentityBlueprintPrincipals/basic/update | null |
microsoft.directory/agentIdentityBlueprintPrincipals/create | null |
microsoft.directory/agentIdentityBlueprintPrincipals/delete | null |
microsoft.directory/agentIdentityBlueprintPrincipals/disable | null |
microsoft.directory/agentIdentityBlueprintPrincipals/enable | null |
microsoft.directory/agentIdentityBlueprintPrincipals/owners/update | null |
microsoft.directory/agentIdentityBlueprintPrincipals/tag/update | null |
microsoft.directory/agentIdentityBlueprints/allProperties/read | null |
microsoft.directory/agentIdentityBlueprints/allProperties/update | null |
microsoft.directory/agentIdentityBlueprints/appRoles/update | null |
microsoft.directory/agentIdentityBlueprints/audience/update | null |
microsoft.directory/agentIdentityBlueprints/authentication/update | null |
microsoft.directory/agentIdentityBlueprints/basic/update | null |
microsoft.directory/agentIdentityBlueprints/create | null |
microsoft.directory/agentIdentityBlueprints/credentials/update | null |
microsoft.directory/agentIdentityBlueprints/delete | null |
microsoft.directory/agentIdentityBlueprints/owners/update | null |
microsoft.directory/agentIdentityBlueprints/permissions/update | null |
microsoft.directory/agentIdentityBlueprints/tag/update | null |
microsoft.directory/agentUsers/assignLicense | null |
microsoft.directory/agentUsers/basic/update | null |
microsoft.directory/agentUsers/create | null |
microsoft.directory/agentUsers/delete | null |
microsoft.directory/agentUsers/disable | null |
microsoft.directory/agentUsers/enable | null |
microsoft.directory/agentUsers/invalidateAllRefreshTokens | null |
microsoft.directory/agentUsers/lifeCycleInfo/read | null |
microsoft.directory/agentUsers/lifeCycleInfo/update | null |
microsoft.directory/agentUsers/manager/update | null |
microsoft.directory/agentUsers/photo/update | null |
microsoft.directory/agentUsers/reprocessLicenseAssignment | null |
microsoft.directory/agentUsers/restore | null |
microsoft.directory/agentUsers/revokeSignInSessions | null |
microsoft.directory/agentUsers/sponsors/update | null |
microsoft.directory/agentUsers/usageLocation/update | null |
microsoft.directory/agentUsers/userPrincipalName/update | null |
microsoft.directory/deletedItems.agentIdentities/delete | null |
microsoft.directory/deletedItems.agentIdentities/restore | null |
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/delete | null |
microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/restore | null |
microsoft.directory/deletedItems.agentIdentityBlueprints/delete | null |
microsoft.directory/deletedItems.agentIdentityBlueprints/restore | null |
microsoft.directory/entitlementManagement/allProperties/read | null |
microsoft.directory/oAuth2PermissionGrants/allProperties/allTasks | null |
microsoft.directory/subscribedSkus/standard/read | null |
microsoft.directory/users/allProperties/read | null |
microsoft.office365.copilot/allEntities/allProperties/allTasks | null |
microsoft.office365.messageCenter/messages/read | null |
microsoft.office365.network/performance/allProperties/read | null |
microsoft.office365.search/content/manage | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.usageReports/allEntities/allProperties/read | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions54
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
AgentIdentity.Create.AllAgentIdentity.DeleteRestore.AllAgentIdentity.EnableDisable.AllAgentIdentity.Read.AllAgentIdentity.ReadWrite.AllAgentIdentityBlueprint.AddRemoveCreds.AllAgentIdentityBlueprint.CreateAgentIdentityBlueprint.DeleteRestore.AllAgentIdentityBlueprint.Read.AllAgentIdentityBlueprint.ReadWrite.AllAgentIdentityBlueprintPrincipal.CreateAgentIdentityBlueprintPrincipal.DeleteRestore.AllAgentIdentityBlueprintPrincipal.EnableDisable.AllAgentIdentityBlueprintPrincipal.Read.AllAgentIdentityBlueprintPrincipal.ReadWrite.AllAgentIdUser.ReadWrite.AllAgentIdUser.ReadWrite.IdentityParentedByAppRoleAssignment.ReadWrite.AllChangeManagement.Read.AllConsentRequest.Read.AllConsentRequest.ReadWrite.AllDelegatedPermissionGrant.Read.AllDelegatedPermissionGrant.ReadWrite.AllDirectory.Read.AllEntitlementManagement.Read.AllExternalConnection.Read.AllExternalConnection.ReadWrite.AllExternalConnection.ReadWrite.OwnedByExternalItem.Read.AllExternalItem.ReadWrite.AllExternalItem.ReadWrite.OwnedByLicenseAssignment.Read.AllNetworkAccess-Reports.Read.AllOrganization.Read.AllPolicy.Read.AllPolicy.Read.PermissionGrantPolicy.ReadWrite.ConsentRequestPolicy.ReadWrite.PermissionGrantReports.Read.AllReportSettings.Read.AllSearchConfiguration.Read.AllSearchConfiguration.ReadWrite.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.WriteSignInIdentifier.Read.AllUser-LifeCycleInfo.Read.AllUser.Read.AllUser.ReadBasic.AllUserAuthenticationMethod.Read.All