← All Roles

Attack Simulation Administrator

Enabled
Versionv1
Date Added2026-06-21
CategorysecurityAndCompliance
Assignment Modeallowed
Built-inYes
Template IDc430b396-e693-46cc-96f3-db01bf8bb62a

Description

Can create and manage all aspects of attack simulation campaigns.

Details

Users in this role can create and manage all aspects of attack simulation creation, launch/scheduling of a simulation, and the review of simulation results. Members of this role have this access for all simulations in the tenant.

Directory Actions3

  • microsoft.office365.protectionCenter/attackSimulator/payload/allProperties/allTasks
  • microsoft.office365.protectionCenter/attackSimulator/reports/allProperties/read
  • microsoft.office365.protectionCenter/attackSimulator/simulation/allProperties/allTasks

Graph API Permissions17

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • AttackSimulation.Read.All
  • AttackSimulation.ReadWrite.All
  • CustomDetection.Read.All
  • CustomDetection.ReadWrite.All
  • SecurityAlert.Read.All
  • SecurityAlert.ReadWrite.All
  • SecurityAnalyzedMessage.Read.All
  • SecurityAnalyzedMessage.ReadWrite.All
  • SecurityEvents.Read.All
  • SecurityEvents.ReadWrite.All
  • SecurityIncident.Read.All
  • SecurityIncident.ReadWrite.All
  • ThreatHunting.Read.All
  • ThreatIntelligence.Read.All
  • ThreatSubmission.Read.All
  • ThreatSubmission.ReadWrite.All
  • ThreatSubmissionPolicy.ReadWrite.All