← All Roles

Security Operator

PrivilegedEnabled
Versionv1
Date Added2026-06-21
CategorysecurityAndCompliance
Assignment Modeallowed
Built-inYes
Template ID5f2222b1-57c3-48ba-8ad5-d4759f1fde6f

Description

Creates and manages security events.

Details

Users with this role can manage alerts and have global read-only access on security-related feature, including all information in Microsoft 365 security center, Microsoft Entra ID Protection, Privileged Identity Management.

Directory Actions18

  • microsoft.azure.advancedThreatProtection/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.directory/auditLogs/allProperties/read
  • microsoft.directory/authorizationPolicy/standard/read
  • microsoft.directory/bulkJobs/standard/read
  • microsoft.directory/cloudAppSecurity/allProperties/allTasks
  • microsoft.directory/identityProtection/allProperties/allTasks
  • microsoft.directory/privilegedIdentityManagement/allProperties/read
  • microsoft.directory/provisioningLogs/allProperties/read
  • microsoft.directory/signInReports/allProperties/read
  • microsoft.directory/users/disable
  • microsoft.directory/users/enable
  • microsoft.directory/users/invalidateAllRefreshTokens
  • microsoft.directory/users/password/update
  • microsoft.intune/allEntities/read
  • microsoft.office365.securityComplianceCenter/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.windows.defenderAdvancedThreatProtection/allEntities/allTasks

Graph API Permissions100

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • AttackSimulation.Read.All
  • AttackSimulation.ReadWrite.All
  • AuditLog.Read.All
  • AuditLogsQuery-Entra.Read.All
  • AuditLogsQuery.Read.All
  • CloudApp-Discovery.Read.All
  • ContentActivity.Read
  • ContentActivity.Write
  • CustomDetection.Read.All
  • CustomDetection.ReadWrite.All
  • DeviceManagementApps.Read.All
  • DeviceManagementConfiguration.Read.All
  • DeviceManagementManagedDevices.Read.All
  • DeviceManagementRBAC.Read.All
  • DeviceManagementScripts.Read.All
  • DeviceManagementServiceConfig.Read.All
  • Directory.Read.All
  • eDiscovery.Read.All
  • eDiscovery.ReadWrite.All
  • IdentityRiskEvent.Read.All
  • IdentityRiskEvent.ReadWrite.All
  • IdentityRiskyAgent.Read.All
  • IdentityRiskyAgent.ReadWrite.All
  • IdentityRiskyServicePrincipal.Read.All
  • IdentityRiskyServicePrincipal.ReadWrite.All
  • IdentityRiskyUser.Read.All
  • IdentityRiskyUser.ReadWrite.All
  • LicenseAssignment.Read.All
  • LicenseAssignment.ReadWrite.All
  • Policy.Read.All
  • Policy.Read.IdentityProtection
  • Policy.ReadWrite.IdentityProtection
  • PrivilegedAccess-CustomExt.Read.All
  • PrivilegedAccess.Read.AzureAD
  • PrivilegedAccess.Read.AzureADGroup
  • PrivilegedAssignmentSchedule.Read.AzureADGroup
  • PrivilegedAssignmentSchedule.Read.EntraAppRole
  • PrivilegedEligibilitySchedule.Read.AzureADGroup
  • PrivilegedEligibilitySchedule.Read.EntraAppRole
  • ProvisioningLog.Read.All
  • RecordsManagement.Read.All
  • RecordsManagement.ReadWrite.All
  • RiskPreventionProviders.Read.All
  • RiskPreventionProviders.ReadWrite.All
  • RoleManagement.Read.Defender
  • RoleManagement.Read.Directory
  • RoleManagement.ReadWrite.Defender
  • RoleManagementAlert.Read.Directory
  • RoleManagementPolicy.Read.AzureADGroup
  • RoleManagementPolicy.Read.Directory
  • RoleManagementPolicy.Read.EntraAppRole
  • SecurityAlert.Read.All
  • SecurityAlert.ReadWrite.All
  • SecurityEvents.Read.All
  • SecurityEvents.ReadWrite.All
  • SecurityIdentitiesAccount.Read.All
  • SecurityIdentitiesActions.ReadWrite.All
  • SecurityIdentitiesAutoConfig.Read.All
  • SecurityIdentitiesAutoConfig.ReadWrite.All
  • SecurityIdentitiesHealth.Read.All
  • SecurityIdentitiesHealth.ReadWrite.All
  • SecurityIdentitiesMigration.Read.All
  • SecurityIdentitiesMigration.ReadWrite.All
  • SecurityIdentitiesSensors.Read.All
  • SecurityIdentitiesSensors.ReadWrite.All
  • SecurityIdentitiesUserActions.Read.All
  • SecurityIdentitiesUserActions.ReadWrite.All
  • SecurityIncident.Read.All
  • SecurityIncident.ReadWrite.All
  • SensitivityLabel.Read
  • SensitivityLabels.Read.All
  • SignInIdentifier.Read.All
  • SignInIdentifier.ReadWrite.All
  • SubjectRightsRequest.Read.All
  • SubjectRightsRequest.ReadWrite.All
  • ThreatHunting.Read.All
  • ThreatIntelligence.Read.All
  • ThreatSubmission.Read.All
  • ThreatSubmission.ReadWrite.All
  • User-ConvertToInternal.ReadWrite.All
  • User-LifeCycleInfo.Read.All
  • User-LifeCycleInfo.ReadWrite.All
  • User-Mail.ReadWrite.All
  • User-OnPremisesSyncBehavior.ReadWrite.All
  • User-PasswordProfile.ReadWrite.All
  • User.Create
  • User.DeleteRestore.All
  • User.EnableDisableAccount.All
  • User.Export.All
  • User.Invite.All
  • User.ManageIdentities.All
  • User.Read.All
  • User.ReadBasic.All
  • User.ReadWrite.All
  • User.RevokeSessions.All
  • UserAuthenticationMethod.Read.All
  • UserAuthenticationMethod.ReadWrite.All
  • UserAuthMethod-External.ReadWrite.All
  • UserAuthMethod-HardwareOATH.ReadWrite.All
  • UserAuthMethod-TAP.ReadWrite.All