Security Reader
Description
Can read security information and reports in Microsoft Entra ID and Office 365.
Details
Users with this role have global read-only access, including all information in Microsoft Entra ID Protection, Privileged Identity Management, as well as the ability to read Microsoft Entra sign-in reports and audit logs. The role also grants read-only permission in Office 365 Security & Compliance Center
Directory Actions34
| Action | Condition |
|---|---|
microsoft.agentRegistry/allEntities/allProperties/read | null |
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.directory/accessReviews/definitions/allProperties/read | null |
microsoft.directory/auditLogs/allProperties/read | null |
microsoft.directory/authorizationPolicy/standard/read | null |
microsoft.directory/bitlockerKeys/key/read | null |
microsoft.directory/bulkJobs/standard/read | null |
microsoft.directory/conditionalAccessPolicies/owners/read | null |
microsoft.directory/conditionalAccessPolicies/policyAppliedTo/read | null |
microsoft.directory/conditionalAccessPolicies/standard/read | null |
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/standard/read | null |
microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read | null |
microsoft.directory/deviceLocalCredentials/standard/read | null |
microsoft.directory/domains/federationConfiguration/standard/read | null |
microsoft.directory/entitlementManagement/allProperties/read | null |
microsoft.directory/identityProtection/allProperties/read | null |
microsoft.directory/multiTenantOrganization/joinRequest/standard/read | null |
microsoft.directory/multiTenantOrganization/standard/read | null |
microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read | null |
microsoft.directory/multiTenantOrganization/tenants/standard/read | null |
microsoft.directory/namedLocations/standard/read | null |
microsoft.directory/policies/owners/read | null |
microsoft.directory/policies/policyAppliedTo/read | null |
microsoft.directory/policies/standard/read | null |
microsoft.directory/privilegedIdentityManagement/allProperties/read | null |
microsoft.directory/provisioningLogs/allProperties/read | null |
microsoft.directory/signInReports/allProperties/read | null |
microsoft.networkAccess/allEntities/allProperties/read | null |
microsoft.office365.protectionCenter/allEntities/standard/read | null |
microsoft.office365.protectionCenter/attackSimulator/payload/allProperties/read | null |
microsoft.office365.protectionCenter/attackSimulator/reports/allProperties/read | null |
microsoft.office365.protectionCenter/attackSimulator/simulation/allProperties/read | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions64
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
AccessReview.Read.AllAgentCard.Read.AllAgentCardManifest.Read.AllAgentCollection.Read.AllAgentInstance.Read.AllAgentRegistration.Read.AllAttackSimulation.Read.AllAuditLog.Read.AllAuditLogsQuery-Entra.Read.AllAuditLogsQuery.Read.AllBitlockerKey.ReadBasic.AllChangeManagement.Read.AllCrossTenantInformation.ReadBasic.AllCustomDetection.Read.AllDeviceLocalCredential.ReadBasic.AllDirectory.Read.AllDomain.Read.AllEntitlementManagement.Read.AllIdentityRiskEvent.Read.AllIdentityRiskyAgent.Read.AllIdentityRiskyServicePrincipal.Read.AllIdentityRiskyUser.Read.AllMultiTenantOrganization.Read.AllMultiTenantOrganization.ReadBasic.AllNetworkAccess-Reports.Read.AllNetworkAccess.Read.AllNetworkAccessBranch.Read.AllNetworkAccessPolicy.Read.AllPolicy.Read.AllPolicy.Read.AuthenticationMethodPolicy.Read.B2BManagementPolicyPolicy.Read.ConditionalAccessPolicy.Read.DeviceConfigurationPolicy.Read.IdentityProtectionPolicy.Read.PermissionGrantPrivilegedAccess-CustomExt.Read.AllPrivilegedAccess.Read.AzureADPrivilegedAccess.Read.AzureADGroupPrivilegedAssignmentSchedule.Read.AzureADGroupPrivilegedAssignmentSchedule.Read.EntraAppRolePrivilegedEligibilitySchedule.Read.AzureADGroupPrivilegedEligibilitySchedule.Read.EntraAppRoleProgramControl.Read.AllProvisioningLog.Read.AllRiskPreventionProviders.Read.AllRoleManagement.Read.DirectoryRoleManagementAlert.Read.DirectoryRoleManagementPolicy.Read.AzureADGroupRoleManagementPolicy.Read.DirectoryRoleManagementPolicy.Read.EntraAppRoleSecurityAlert.Read.AllSecurityAnalyzedMessage.Read.AllSecurityEvents.Read.AllSecurityIncident.Read.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.WriteThreatHunting.Read.AllThreatIntelligence.Read.AllThreatSubmission.Read.All