last sync: 2025-Apr-29 17:09:03 Etc/UTC

Groups Administrator - fdd7a751-b60b-444a-984c-02652fe8fa1c
Entra Id Role definition

Display name Groups Administrator
Id fdd7a751-b60b-444a-984c-02652fe8fa1c
Description Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.
Detailed description Members of this role can create and manage groups, create and manage group settings like naming and expiration policies, and view groups activity and audit reports. It is important to understand that assigning a user to this role gives them the ability to manage all the groups in the tenants across various workloads like Teams, SharePoint, and Yammer in addition to Outlook. Also, the user will be able to manage the various group settings across various admin portals like Microsoft Admin Center and the Azure Portal, as well as workload specific ones like Teams and SharePoint admin centers.
Categories collaboration,identity
isPrivileged False
EntraOps Tier Level ControlPlane
#Resource Actions unique 77
#Resource Actions Operations unique 80
#Resource Actions privileged 0
#Resource Actions direct 23
Resource Actions inherited True
#Resource Actions inherited 54
Resource Actions inherited from Directory Readers (88d8e3e3-8f55-4a1e-953a-9b9898b8876b)
#Resource Actions overlap direct&inherited 0
Resource Actions overlap direct&inherited
#Resource Actions inherited to 0 other Entra Id Roles
Resource Actions inherited to n/a
#Resource Actions conditioned 0
#Resource Actions unconditioned 77
#NameSpaces 6
NameSpaces microsoft.azure.serviceHealth: 1
microsoft.azure.supportTickets: 1
microsoft.directory: 72
microsoft.office365.serviceHealth: 1
microsoft.office365.supportTickets: 1
microsoft.office365.webPortal: 1
Actions allTasks: 4
assignLicense: 1
create: 1
delete: 2
read: 56
reprocessLicenseAssignment: 1
restore: 2
update: 10
Operations actionVerbs DELETE: 4
GET: 56
n/a: 4
PATCH: 8
POST: 8
Resource Actions where Consent Policy applies 0
Resource Actions / Consent Policy n/a
JSON enriched
JSON raw (v1.0 endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
JSON raw (beta endpoint)
GET /roleManagement/directory/roleDefinitions/{id}