← All Roles

Organizational Branding Administrator

Enabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template ID92ed04bf-c94a-4b82-9729-b799a7a4c178

Description

Manage all aspects of organizational branding in a tenant.

Details

Assign the Organizational Branding Administrator role to users who need to do the following tasks:

  • Manage all aspects of organizational branding in a tenant
  • Read, create, update, and delete branding themes
  • Manage the default branding theme and all branding localization themes

Directory Actions1

  • microsoft.directory/loginOrganizationBranding/allProperties/allTasks

Graph API Permissions2

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • OrganizationalBranding.Read.All
  • OrganizationalBranding.ReadWrite.All