Microsoft Entra role for managing Microsoft 365 Copilot and other AI settings; holders may also consent on behalf of the whole tenant, Microsoft Graph application permissions excepted.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AI Administrator in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Microsoft 365 Copilot
Assistant built into Microsoft 365 apps that grounds its answers in an organisation's data via Microsoft Graph. Because it respects existing permissions, content that has been overshared can appear in responses.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
- Microsoft Graph
API giving access to Entra and Microsoft 365 data. Authorisation uses application or delegated permissions rather than Azure RBAC.
- Application permissions
Microsoft Entra permissions granted to the app itself and used without any signed-in user, which means they reach every user's data. For per-user access they are not least privilege.
Related terms
- Copilot security dashboard
Collects Purview signals about Copilot in one Microsoft 365 admin center page (Copilot > Overview > Security), offering shortcuts to set up DLP, deal with oversharing and tighten compliance. Global Readers may view it; an AI Administrator is needed to change anything.