← All Roles

Agent ID Administrator

PrivilegedEnabled
Versionv4
Last Updated2026-06-27
Categoryidentity
Assignment Modeallowed
Built-inYes
Template IDdb506228-d27e-4b7d-95e5-295956d6615f

Description

Manage all aspects of agents in a tenant including identity lifecycle operations for agent blueprints, agent identity blueprint principals, agent identities, and agentic users.

Details

Assign the Agent ID Administrator role to users who need to do the following tasks:

  • Manage the full lifecycle of agent identities, agent identity blueprint principals, agent identity blueprints, and agent users in a tenant
  • Permanently delete and restore deleted agent identities, agent identity blueprint principals, agent identity blueprints, and agent users
  • Manage licenses, invalidate refresh tokens, and revoke sign-in sessions for agent users
  • Read all properties of audit logs and sign-in reports
  • Read standard properties of organization, policies, external user profiles, hidden group members, and bulk jobs for users
  • Create Microsoft 365 groups as owner
  • Read and configure Azure and Microsoft 365 service health and support tickets
  • Create and manage Azure and Microsoft 365 service health and support tickets

Directory Actions66

  • microsoft.azure.serviceHealth/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.directory/agentIdentities/allProperties/read
  • microsoft.directory/agentIdentities/appRoleAssignedTo/update
  • microsoft.directory/agentIdentities/authentication/update
  • microsoft.directory/agentIdentities/basic/update
  • microsoft.directory/agentIdentities/create
  • microsoft.directory/agentIdentities/delete
  • microsoft.directory/agentIdentities/disable
  • microsoft.directory/agentIdentities/enable
  • microsoft.directory/agentIdentities/owners/update
  • microsoft.directory/agentIdentities/tag/update
  • microsoft.directory/agentIdentityBlueprintPrincipals/allProperties/read
  • microsoft.directory/agentIdentityBlueprintPrincipals/appRoleAssignedTo/update
  • microsoft.directory/agentIdentityBlueprintPrincipals/authentication/update
  • microsoft.directory/agentIdentityBlueprintPrincipals/basic/update
  • microsoft.directory/agentIdentityBlueprintPrincipals/create
  • microsoft.directory/agentIdentityBlueprintPrincipals/delete
  • microsoft.directory/agentIdentityBlueprintPrincipals/disable
  • microsoft.directory/agentIdentityBlueprintPrincipals/enable
  • microsoft.directory/agentIdentityBlueprintPrincipals/owners/update
  • microsoft.directory/agentIdentityBlueprintPrincipals/tag/update
  • microsoft.directory/agentIdentityBlueprints/allProperties/read
  • microsoft.directory/agentIdentityBlueprints/allProperties/update
  • microsoft.directory/agentIdentityBlueprints/appRoles/update
  • microsoft.directory/agentIdentityBlueprints/audience/update
  • microsoft.directory/agentIdentityBlueprints/authentication/update
  • microsoft.directory/agentIdentityBlueprints/basic/update
  • microsoft.directory/agentIdentityBlueprints/create
  • microsoft.directory/agentIdentityBlueprints/credentials/update
  • microsoft.directory/agentIdentityBlueprints/delete
  • microsoft.directory/agentIdentityBlueprints/owners/update
  • microsoft.directory/agentIdentityBlueprints/permissions/update
  • microsoft.directory/agentIdentityBlueprints/tag/update
  • microsoft.directory/agentUsers/assignLicense
  • microsoft.directory/agentUsers/basic/update
  • microsoft.directory/agentUsers/create
  • microsoft.directory/agentUsers/delete
  • microsoft.directory/agentUsers/disable
  • microsoft.directory/agentUsers/enable
  • microsoft.directory/agentUsers/invalidateAllRefreshTokens
  • microsoft.directory/agentUsers/lifeCycleInfo/read
  • microsoft.directory/agentUsers/lifeCycleInfo/update
  • microsoft.directory/agentUsers/manager/update
  • microsoft.directory/agentUsers/photo/update
  • microsoft.directory/agentUsers/reprocessLicenseAssignment
  • microsoft.directory/agentUsers/restore
  • microsoft.directory/agentUsers/revokeSignInSessions
  • microsoft.directory/agentUsers/sponsors/update
  • microsoft.directory/agentUsers/usageLocation/update
  • microsoft.directory/agentUsers/userPrincipalName/update
  • microsoft.directory/auditLogs/allProperties/read
  • microsoft.directory/deletedItems.agentIdentities/delete
  • microsoft.directory/deletedItems.agentIdentities/restore
  • microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/delete
  • microsoft.directory/deletedItems.agentIdentityBlueprintPrincipals/restore
  • microsoft.directory/deletedItems.agentIdentityBlueprints/delete
  • microsoft.directory/deletedItems.agentIdentityBlueprints/restore
  • microsoft.directory/externalUserProfiles/standard/read
  • microsoft.directory/groups/hiddenMembers/read
  • microsoft.directory/groups.unified/createAsOwner
  • microsoft.directory/organization/standard/read
  • microsoft.directory/policies/standard/read
  • microsoft.directory/signInReports/allProperties/read
  • microsoft.office365.serviceHealth/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks

Graph API Permissions43

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • AgentIdentity.Create.All
  • AgentIdentity.DeleteRestore.All
  • AgentIdentity.EnableDisable.All
  • AgentIdentity.Read.All
  • AgentIdentity.ReadWrite.All
  • AgentIdentityBlueprint.AddRemoveCreds.All
  • AgentIdentityBlueprint.Create
  • AgentIdentityBlueprint.DeleteRestore.All
  • AgentIdentityBlueprint.Read.All
  • AgentIdentityBlueprint.ReadWrite.All
  • AgentIdentityBlueprintPrincipal.Create
  • AgentIdentityBlueprintPrincipal.DeleteRestore.All
  • AgentIdentityBlueprintPrincipal.EnableDisable.All
  • AgentIdentityBlueprintPrincipal.Read.All
  • AgentIdentityBlueprintPrincipal.ReadWrite.All
  • AgentIdUser.ReadWrite.All
  • AgentIdUser.ReadWrite.IdentityParentedBy
  • AuditLog.Read.All
  • AuditLogsQuery-Entra.Read.All
  • AuditLogsQuery.Read.All
  • ChangeManagement.Read.All
  • ExternalUserProfile.Read.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • GroupSettings.Read.All
  • Organization.Read.All
  • PendingExternalUserProfile.Read.All
  • Policy.Read.All
  • Policy.Read.AuthenticationMethod
  • Policy.Read.B2BManagementPolicy
  • Policy.Read.ConditionalAccess
  • Policy.Read.DeviceConfiguration
  • Policy.Read.IdentityProtection
  • Policy.Read.PermissionGrant
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write