← All Roles

Billing Administrator

Enabled
Versionv2
Last Updated2026-06-24
Categoryother
Assignment Modeallowed
Built-inYes
Template IDb0f54661-2d74-4c50-afa3-1ec803f12efe

Description

Can perform common billing related tasks like updating payment information.

Details

Makes purchases, manages subscriptions, manages support tickets, and monitors service health.

Directory Actions7

  • microsoft.azure.serviceHealth/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.commerce.billing/allEntities/allProperties/allTasks
  • microsoft.directory/organization/basic/update
  • microsoft.office365.serviceHealth/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions11

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • ChangeManagement.Read.All
  • Directory.Read.All
  • Organization.Read.All
  • Organization.ReadWrite.All
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write