← All Roles

Helpdesk Administrator

PrivilegedEnabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template ID729827e3-9c14-49f7-bb1b-9608f156bbb8

Description

Can reset passwords for non-administrators and Helpdesk Administrators.

Details

Users with this role can change passwords, invalidate refresh tokens, manage service requests, and monitor service health. Invalidating a refresh token forces the user to sign in again. Helpdesk administrators can reset passwords and invalidate refresh tokens of other users who are non-administrators or assigned the following roles only:

  • Directory Readers
  • Guest Inviter
  • Helpdesk Administrator
  • Message Center Reader
  • Password Administrator
  • Reports Reader

Directory Actions9

  • microsoft.azure.serviceHealth/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.directory/bitlockerKeys/key/read
  • microsoft.directory/deviceLocalCredentials/standard/read
  • microsoft.directory/users/invalidateAllRefreshTokens
  • microsoft.directory/users/password/update
  • microsoft.office365.serviceHealth/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions36

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • BitlockerKey.ReadBasic.All
  • ChangeManagement.Read.All
  • DeviceLocalCredential.ReadBasic.All
  • Directory.Read.All
  • LicenseAssignment.Read.All
  • LicenseAssignment.ReadWrite.All
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write
  • SignInIdentifier.Read.All
  • SignInIdentifier.ReadWrite.All
  • User-ConvertToInternal.ReadWrite.All
  • User-LifeCycleInfo.Read.All
  • User-LifeCycleInfo.ReadWrite.All
  • User-Mail.ReadWrite.All
  • User-OnPremisesSyncBehavior.ReadWrite.All
  • User-PasswordProfile.ReadWrite.All
  • User.Create
  • User.DeleteRestore.All
  • User.EnableDisableAccount.All
  • User.Export.All
  • User.Invite.All
  • User.ManageIdentities.All
  • User.Read.All
  • User.ReadBasic.All
  • User.ReadWrite.All
  • User.RevokeSessions.All
  • UserAuthenticationMethod.Read.All
  • UserAuthenticationMethod.ReadWrite.All
  • UserAuthMethod-External.ReadWrite.All
  • UserAuthMethod-HardwareOATH.ReadWrite.All
  • UserAuthMethod-TAP.ReadWrite.All