← All Roles

Teams Reader

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration,readOnly
Assignment Modeallowed
Built-inYes
Template ID1076ac91-f3d9-41a7-a339-dcdf5f480acc

Description

Read everything in the Teams admin center, but not update anything.

Details

Assign the Teams Reader role to users who need to do the following tasks:

  • Read settings and administrative information in the Teams admin center, but not perform any management actions
  • Read the Microsoft Call Quality Dashboard (CQD), but not access any troubleshooting capabilities

Directory Actions2

  • microsoft.office365.webPortal/allEntities/standard/read
  • microsoft.teams/allEntities/allProperties/read

Graph API Permissions16

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • Bookings.Read.All
  • Channel.ReadBasic.All
  • ChannelMember.Read.All
  • ChannelMessage.Read.All
  • ChannelSettings.Read.All
  • Directory.Read.All
  • RoleManagement.Read.CloudPC
  • Schedule.Read.All
  • Team.ReadBasic.All
  • TeamMember.Read.All
  • TeamsActivity.Read
  • TeamSettings.Read.All
  • TeamsResourceAccount.Read.All
  • TeamsTab.Read.All
  • TeamsTelephoneNumber.Read.All
  • TeamsUserConfiguration.Read.All