Dragon Administrator
Description
Manage all aspects of the Microsoft Dragon admin center.
Details
Users with this role can manage all aspects of the administrative experience in the Dragon admin center. This includes provisioning products, creating the organizational hierarchy, managing experiences in the embedded versions of the Dragon Copilot application within electronic health records (EHRs), overseeing healthcare groups, and configuring the Dragon Copilot application—such as managing settings, viewing analytics, and handling library objects. Additionally, users with this role can create, manage, and view support tickets for their organization in the Dragon admin center. They can also create, view, manage, and monitor billing plans for licenses purchased by their organization through the Dragon admin center (additional roles may be required).
Directory Actions8
microsoft.azure.serviceHealth/allEntities/allTasksmicrosoft.azure.supportTickets/allEntities/allTasksmicrosoft.healthPlatform/allEntities/allProperties/allTasksmicrosoft.office365.network/performance/allProperties/readmicrosoft.office365.serviceHealth/allEntities/allTasksmicrosoft.office365.supportTickets/allEntities/allTasksmicrosoft.office365.usageReports/allEntities/allProperties/readmicrosoft.office365.webPortal/allEntities/standard/read
Graph API Permissions12
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
ChangeManagement.Read.AllDirectory.Read.AllNetworkAccess-Reports.Read.AllReports.Read.AllReportSettings.Read.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.Write