← All Roles

Knowledge Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration
Assignment Modeallowed
Built-inYes
Template IDb5a8dcf3-09d5-43a9-a639-8e29ef291470

Description

Can configure knowledge, learning, and other intelligent features.

Details

Users in this role have full access to all knowledge, learning and intelligent features settings in the Microsoft 365 admin center. They have a general understanding of the suite of products, licensing details and responsibility to control access. They also can create and manage content, like topics, acronyms and learning resources. Additionally, these users can create content centers, monitor service health, and create service requests.

Directory Actions13

  • microsoft.directory/groups.security/basic/update
  • microsoft.directory/groups.security/create
  • microsoft.directory/groups.security/createAsOwner
  • microsoft.directory/groups.security/delete
  • microsoft.directory/groups.security/members/update
  • microsoft.directory/groups.security/owners/update
  • microsoft.office365.knowledge/contentUnderstanding/allProperties/allTasks
  • microsoft.office365.knowledge/knowledgeNetwork/allProperties/allTasks
  • microsoft.office365.knowledge/learningSources/allProperties/allTasks
  • microsoft.office365.protectionCenter/sensitivityLabels/allProperties/read
  • microsoft.office365.sharePoint/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions25

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • AttackSimulation.Read.All
  • CustomDetection.Read.All
  • Directory.Read.All
  • Files.Read.All
  • Files.ReadWrite.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • SecurityAlert.Read.All
  • SecurityAnalyzedMessage.Read.All
  • SecurityEvents.Read.All
  • SecurityIncident.Read.All
  • SharePointCrossTenantMigration.Manage.All
  • SharePointTenantSettings.Read.All
  • SharePointTenantSettings.ReadWrite.All
  • Sites.FullControl.All
  • Sites.Manage.All
  • Sites.Read.All
  • Sites.ReadWrite.All
  • TermStore.Read.All
  • TermStore.ReadWrite.All
  • ThreatHunting.Read.All
  • ThreatIntelligence.Read.All
  • ThreatSubmission.Read.All