← All Roles

Privileged Authentication Administrator

PrivilegedEnabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template ID7be44c8a-adaf-4e2a-84d6-ab2649e08a13

Attack path

Privileged Authentication Administrator can manage authentication methods for any user, including Global Administrators. An attacker could remove a target administrator's legitimate methods, issue a Temporary Access Pass or register an attacker-controlled authentication method, and then sign in as that user after resetting or otherwise obtaining the password. This bypasses the protection normally provided by the victim's multifactor authentication and creates a direct path from the compromised role to full tenant control.

Description

Can access to view, set and reset authentication method information for any user (admin or non-admin).

Details

Users with this role can view the current authentication method information and set or reset non-password credentials for all users, including global administrators. Privileged Authentication Administrators can force users to re-register against existing non-password credential (e.g. MFA, FIDO) and revoke 'remember MFA on the device', prompting for MFA on the next login of all users.

Directory Actions20

ActionCondition
microsoft.azure.serviceHealth/allEntities/allTasksnull
microsoft.azure.supportTickets/allEntities/allTasksnull
microsoft.directory/deletedItems.users/restorenull
microsoft.directory/users/authenticationMethods/basic/updatenull
microsoft.directory/users/authenticationMethods/createnull
microsoft.directory/users/authenticationMethods/deletenull
microsoft.directory/users/authenticationMethods/standard/readnull
microsoft.directory/users/authorizationInfo/updatenull
microsoft.directory/users/basic/updatenull
microsoft.directory/users/deletenull
microsoft.directory/users/disablenull
microsoft.directory/users/enablenull
microsoft.directory/users/invalidateAllRefreshTokensnull
microsoft.directory/users/manager/updatenull
microsoft.directory/users/password/updatenull
microsoft.directory/users/restorenull
microsoft.directory/users/userPrincipalName/updatenull
microsoft.office365.serviceHealth/allEntities/allTasksnull
microsoft.office365.supportTickets/allEntities/allTasksnull
microsoft.office365.webPortal/allEntities/standard/readnull

Graph API Permissions34

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • ChangeManagement.Read.All
  • Directory.Read.All
  • LicenseAssignment.Read.All
  • LicenseAssignment.ReadWrite.All
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write
  • SignInIdentifier.Read.All
  • SignInIdentifier.ReadWrite.All
  • User-ConvertToInternal.ReadWrite.All
  • User-LifeCycleInfo.Read.All
  • User-LifeCycleInfo.ReadWrite.All
  • User-Mail.ReadWrite.All
  • User-OnPremisesSyncBehavior.ReadWrite.All
  • User-PasswordProfile.ReadWrite.All
  • User.Create
  • User.DeleteRestore.All
  • User.EnableDisableAccount.All
  • User.Export.All
  • User.Invite.All
  • User.ManageIdentities.All
  • User.Read.All
  • User.ReadBasic.All
  • User.ReadWrite.All
  • User.RevokeSessions.All
  • UserAuthenticationMethod.Read.All
  • UserAuthenticationMethod.ReadWrite.All
  • UserAuthMethod-External.ReadWrite.All
  • UserAuthMethod-HardwareOATH.ReadWrite.All
  • UserAuthMethod-TAP.ReadWrite.All