← All Roles

B2C IEF Keyset Administrator

PrivilegedEnabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template IDaaf43236-0c0d-4d5f-883a-6955382ac081

Description

Can manage secrets for federation and encryption in the Identity Experience Framework (IEF).

Details

User can create and manage policy keys and secrets for token encryption, token signatures, and claim encryption/decryption. By adding new keys to existing key containers, this limited administrator can rollover secrets as needed without impacting existing applications. This user can see the full content of these secrets and their expiration dates even after their creation. This is a sensitive role. The Keyset administrator role should be carefully audited and assigned with care during preproduction and production.

Directory Actions1

  • microsoft.directory/b2cTrustFrameworkKeySet/allProperties/allTasks

Graph API Permissions1

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • Policy.ReadWrite.TrustFramework