last sync: 2025-Apr-29 17:09:03 Etc/UTC

Attack Payload Author - 9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f
Entra Id Role definition

Display name Attack Payload Author
Id 9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f
Description Can create attack payloads that an administrator can initiate later.
Detailed description Users in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation.
Categories securityAndCompliance
isPrivileged False
EntraOps Tier Level ManagementPlane
#Resource Actions unique 56
#Resource Actions Operations unique 56
#Resource Actions privileged 0
#Resource Actions direct 2
Resource Actions inherited True
#Resource Actions inherited 54
Resource Actions inherited from Directory Readers (88d8e3e3-8f55-4a1e-953a-9b9898b8876b)
#Resource Actions overlap direct&inherited 0
Resource Actions overlap direct&inherited
#Resource Actions inherited to 0 other Entra Id Roles
Resource Actions inherited to n/a
#Resource Actions conditioned 0
#Resource Actions unconditioned 56
#NameSpaces 2
NameSpaces microsoft.directory: 54
microsoft.office365.protectionCenter: 2
Actions allTasks: 1
read: 55
Operations actionVerbs GET: 55
n/a: 1
Resource Actions where Consent Policy applies 0
Resource Actions / Consent Policy n/a
JSON enriched
JSON raw (v1.0 endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
JSON raw (beta endpoint)
GET /roleManagement/directory/roleDefinitions/{id}