last sync: 2025-Apr-29 17:09:03 Etc/UTC

Directory Writers - 9360feb5-f418-4baa-8175-e2a00bac4301
Entra Id Role definition

Display name Directory Writers
Id 9360feb5-f418-4baa-8175-e2a00bac4301
Description Can read and write basic directory information. For granting access to applications, not intended for users.
Detailed description Users in this role can read and update basic information of users, groups, and service principals. Assign this role only to applications that don't support the Consent Framework. It should not be assigned to any users.
Categories identity
isPrivileged True Privileged
EntraOps Tier Level ControlPlane
#Resource Actions unique 96
#Resource Actions Operations unique 102
#Resource Actions privileged 7
#Resource Actions direct 42
Resource Actions inherited True
#Resource Actions inherited 54
Resource Actions inherited from Directory Readers (88d8e3e3-8f55-4a1e-953a-9b9898b8876b)
#Resource Actions overlap direct&inherited 0
Resource Actions overlap direct&inherited
#Resource Actions inherited to 0 other Entra Id Roles
Resource Actions inherited to n/a
#Resource Actions conditioned 0
#Resource Actions unconditioned 96
#NameSpaces 1
NameSpaces microsoft.directory: 96
Actions assignLicense: 2
create: 5
delete: 1
disable: 1
enable: 1
manage: 9
other: 2
read: 54
reprocessLicenseAssignment: 2
update: 19
Operations actionVerbs DELETE: 6
GET: 54
PATCH: 15
POST: 26
PUT: 1
Resource Actions where Consent Policy applies 0
Resource Actions / Consent Policy n/a
JSON enriched
JSON raw (v1.0 endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
JSON raw (beta endpoint)
GET /roleManagement/directory/roleDefinitions/{id}