Extended Directory User Administrator
Enabled
Description
Manage all aspects of external user profiles in the extended directory for Teams.
Directory Actions7
| Action | Condition |
|---|---|
microsoft.directory/externalUserProfiles/basic/update | null |
microsoft.directory/externalUserProfiles/delete | null |
microsoft.directory/externalUserProfiles/standard/read | null |
microsoft.directory/pendingExternalUserProfiles/basic/update | null |
microsoft.directory/pendingExternalUserProfiles/create | null |
microsoft.directory/pendingExternalUserProfiles/delete | null |
microsoft.directory/pendingExternalUserProfiles/standard/read | null |
Graph API Permissions4
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
ExternalUserProfile.Read.AllExternalUserProfile.ReadWrite.AllPendingExternalUserProfile.Read.AllPendingExternalUserProfile.ReadWrite.All