← All Roles

Attribute Definition Administrator

Enabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template ID8424c6f0-a189-499e-bbd0-26c1753c96d4

Description

Define and manage the definition of custom security attributes.

Details

Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.

Directory Actions2

  • microsoft.directory/attributeSets/allProperties/allTasks
  • microsoft.directory/customSecurityAttributeDefinitions/allProperties/allTasks

Graph API Permissions4

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • CustomSecAttributeAssignment.Read.All
  • CustomSecAttributeAssignment.ReadWrite.All
  • CustomSecAttributeDefinition.Read.All
  • CustomSecAttributeDefinition.ReadWrite.All