Privileged Authentication Administrator
Attack path
Privileged Authentication Administrator can manage authentication methods for any user, including Global Administrators. An attacker could remove a target administrator's legitimate methods, issue a Temporary Access Pass or register an attacker-controlled authentication method, and then sign in as that user after resetting or otherwise obtaining the password. This bypasses the protection normally provided by the victim's multifactor authentication and creates a direct path from the compromised role to full tenant control.
Description
Can access to view, set and reset authentication method information for any user (admin or non-admin).
Details
Users with this role can view the current authentication method information and set or reset non-password credentials for all users, including global administrators. Privileged Authentication Administrators can force users to re-register against existing non-password credential (e.g. MFA, FIDO) and revoke 'remember MFA on the device', prompting for MFA on the next login of all users.
Directory Actions20
| Action | Condition |
|---|---|
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.directory/deletedItems.users/restore | null |
microsoft.directory/users/authenticationMethods/basic/update | null |
microsoft.directory/users/authenticationMethods/create | null |
microsoft.directory/users/authenticationMethods/delete | null |
microsoft.directory/users/authenticationMethods/standard/read | null |
microsoft.directory/users/authorizationInfo/update | null |
microsoft.directory/users/basic/update | null |
microsoft.directory/users/delete | null |
microsoft.directory/users/disable | null |
microsoft.directory/users/enable | null |
microsoft.directory/users/invalidateAllRefreshTokens | null |
microsoft.directory/users/manager/update | null |
microsoft.directory/users/password/update | null |
microsoft.directory/users/restore | null |
microsoft.directory/users/userPrincipalName/update | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions34
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
ChangeManagement.Read.AllDirectory.Read.AllLicenseAssignment.Read.AllLicenseAssignment.ReadWrite.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.WriteSignInIdentifier.Read.AllSignInIdentifier.ReadWrite.AllUser-ConvertToInternal.ReadWrite.AllUser-LifeCycleInfo.Read.AllUser-LifeCycleInfo.ReadWrite.AllUser-Mail.ReadWrite.AllUser-OnPremisesSyncBehavior.ReadWrite.AllUser-PasswordProfile.ReadWrite.AllUser.CreateUser.DeleteRestore.AllUser.EnableDisableAccount.AllUser.Export.AllUser.Invite.AllUser.ManageIdentities.AllUser.Read.AllUser.ReadBasic.AllUser.ReadWrite.AllUser.RevokeSessions.AllUserAuthenticationMethod.Read.AllUserAuthenticationMethod.ReadWrite.AllUserAuthMethod-External.ReadWrite.AllUserAuthMethod-HardwareOATH.ReadWrite.AllUserAuthMethod-TAP.ReadWrite.All