← All Roles

External Identity Provider Administrator

PrivilegedEnabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template IDbe2f45a1-457d-42af-a067-6ec1fa63bc45

Description

Can configure identity providers for use in direct federation.

Details

This administrator manages federation between Microsoft Entra tenants and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service id, assigned key containers). This user can enable the tenant to trust authentications from external identity providers. The resulting impact on end user experiences depends on the type of tenant: (1) Microsoft Entra tenants for employees and partners: The addition of a federation (e.g. with Gmail) will immediately impact all guest invitations not yet redeemed. (2) Azure Active Directory B2C tenants: The addition of a federation (e.g. with Facebook, or with another Microsoft Entra tenant) does not immediately impact end user flows until the identity provider is added as an option in a user flow (aka built-in policy). To change user flows, the limited role of "External ID user flow administrator" is required.

Directory Actions2

  • microsoft.directory/domains/federation/update
  • microsoft.directory/identityProviders/allProperties/allTasks

Graph API Permissions5

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • Domain-InternalFederation.ReadWrite.All
  • Domain.Read.All
  • Domain.ReadWrite.All
  • IdentityProvider.Read.All
  • IdentityProvider.ReadWrite.All