Attack Simulation Administrator
Description
Can create and manage all aspects of attack simulation campaigns.
Details
Users in this role can create and manage all aspects of attack simulation creation, launch/scheduling of a simulation, and the review of simulation results. Members of this role have this access for all simulations in the tenant.
Directory Actions3
microsoft.office365.protectionCenter/attackSimulator/payload/allProperties/allTasksmicrosoft.office365.protectionCenter/attackSimulator/reports/allProperties/readmicrosoft.office365.protectionCenter/attackSimulator/simulation/allProperties/allTasks
Graph API Permissions17
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
AttackSimulation.Read.AllAttackSimulation.ReadWrite.AllCustomDetection.Read.AllCustomDetection.ReadWrite.AllSecurityAlert.Read.AllSecurityAlert.ReadWrite.AllSecurityAnalyzedMessage.Read.AllSecurityAnalyzedMessage.ReadWrite.AllSecurityEvents.Read.AllSecurityEvents.ReadWrite.AllSecurityIncident.Read.AllSecurityIncident.ReadWrite.AllThreatHunting.Read.AllThreatIntelligence.Read.AllThreatSubmission.Read.AllThreatSubmission.ReadWrite.AllThreatSubmissionPolicy.ReadWrite.All