← All Roles

Knowledge Manager

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration
Assignment Modeallowed
Built-inYes
Template ID744ec460-397e-42ad-a462-8b3f9747a02c

Description

Has access to topic management dashboard and can manage content.

Details

Users in this role can create and manage content, like topics and acronyms. These users are primarily responsible for the quality and structure of knowledge. This user has full rights to topic management actions to confirm a topic, approve edits, or delete a topic. This role can also manage taxonomies as part of the term store management tool and create content centers.

Directory Actions11

  • microsoft.directory/groups.security/basic/update
  • microsoft.directory/groups.security/create
  • microsoft.directory/groups.security/createAsOwner
  • microsoft.directory/groups.security/delete
  • microsoft.directory/groups.security/members/update
  • microsoft.directory/groups.security/owners/update
  • microsoft.office365.knowledge/contentUnderstanding/analytics/allProperties/read
  • microsoft.office365.knowledge/knowledgeNetwork/topicVisibility/allProperties/allTasks
  • microsoft.office365.sharePoint/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions16

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • Directory.Read.All
  • Files.Read.All
  • Files.ReadWrite.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • SharePointCrossTenantMigration.Manage.All
  • SharePointTenantSettings.Read.All
  • SharePointTenantSettings.ReadWrite.All
  • Sites.FullControl.All
  • Sites.Manage.All
  • Sites.Read.All
  • Sites.ReadWrite.All
  • TermStore.Read.All
  • TermStore.ReadWrite.All