Helpdesk Administrator
Attack path
Helpdesk Administrator cannot reset the passwords of users protected by higher-ranking administrative roles, but it can take over many non-administrative accounts. An attacker could reset a user whose ordinary account owns a privileged application, can approve a sensitive workflow, or has access to another system that grants administrative rights. Weak separation between day-to-day accounts and privileged ownership therefore creates an indirect escalation path, even though the role cannot directly reset a Global Administrator.
Description
Can reset passwords for non-administrators and Helpdesk Administrators.
Details
Users with this role can change passwords, invalidate refresh tokens, manage service requests, and monitor service health. Invalidating a refresh token forces the user to sign in again. Helpdesk administrators can reset passwords and invalidate refresh tokens of other users who are non-administrators or assigned the following roles only:
- Directory Readers
- Guest Inviter
- Helpdesk Administrator
- Message Center Reader
- Password Administrator
- Reports Reader
Directory Actions9
| Action | Condition |
|---|---|
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.directory/bitlockerKeys/key/read | null |
microsoft.directory/deviceLocalCredentials/standard/read | null |
microsoft.directory/users/invalidateAllRefreshTokens | null |
microsoft.directory/users/password/update | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions36
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
BitlockerKey.ReadBasic.AllChangeManagement.Read.AllDeviceLocalCredential.ReadBasic.AllDirectory.Read.AllLicenseAssignment.Read.AllLicenseAssignment.ReadWrite.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.WriteSignInIdentifier.Read.AllSignInIdentifier.ReadWrite.AllUser-ConvertToInternal.ReadWrite.AllUser-LifeCycleInfo.Read.AllUser-LifeCycleInfo.ReadWrite.AllUser-Mail.ReadWrite.AllUser-OnPremisesSyncBehavior.ReadWrite.AllUser-PasswordProfile.ReadWrite.AllUser.CreateUser.DeleteRestore.AllUser.EnableDisableAccount.AllUser.Export.AllUser.Invite.AllUser.ManageIdentities.AllUser.Read.AllUser.ReadBasic.AllUser.ReadWrite.AllUser.RevokeSessions.AllUserAuthenticationMethod.Read.AllUserAuthenticationMethod.ReadWrite.AllUserAuthMethod-External.ReadWrite.AllUserAuthMethod-HardwareOATH.ReadWrite.AllUserAuthMethod-TAP.ReadWrite.All