← All Roles

Desktop Analytics Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorydevices
Assignment Modeallowed
Built-inYes
Template ID38a96431-2bdf-4b4c-8b6e-5d3d8abac1a4

Description

Can access and manage Desktop management tools and services.

Details

Users in this role will have access to manage Desktop Analytics and Office Customization & Policy Services. For Desktop Analytics, this includes the ability to view asset inventory, create deployment plans, and view deployment and health status. For Office Customization & Policies Services, this role will enable users to manage Office polices.

Directory Actions4

  • microsoft.azure.serviceHealth/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.directory/authorizationPolicy/standard/read
  • microsoft.office365.desktopAnalytics/allEntities/allTasks

Graph API Permissions10

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • ChangeManagement.Read.All
  • Directory.Read.All
  • Policy.Read.All
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write