← All Roles

Windows Update Deployment Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration,identity
Assignment Modeallowed
Built-inYes
Template ID32696413-001a-46ae-978c-ce0f6b3620d2

Description

Can create and manage all aspects of Windows Update deployments through the Windows Update for Business deployment service.

Details

Users in this role can create and manage all aspects of Windows Update deployments through the Windows Update for Business deployment service. The deployment service enables users to define settings for when and how updates are deployed and specify which updates are offered to groups of devices in their tenant. It also allows users to monitor the update progress.

Directory Actions1

  • microsoft.windows.updatesDeployments/allEntities/allProperties/allTasks

Graph API Permissions2

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • WindowsUpdates.Read.All
  • WindowsUpdates.ReadWrite.All