Built from the preset permissions that the built-in Microsoft Entra roles also use, and assignable to the whole tenant, an administrative unit or one object. Each user it is assigned to needs Microsoft Entra ID P1; Azure custom roles are a separate thing.
Also called Microsoft Entra custom role.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Custom role in context, with comparison tables and the common traps.
Terms in this definition
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Microsoft Entra roles
Administrative roles at tenant level, User Administrator for example, that manage objects in Entra but confer no rights over Azure resources, which Azure RBAC handles separately.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
- Administrative unit
Used to confine a role assignment to a subset of a Microsoft Entra directory, such as just one region's users for a local helpdesk. A unit holds users, groups or devices; units cannot be nested, and including a group does not make its individual members part of the scope.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Microsoft Entra ID P1
Premium tier of Microsoft Entra ID, bundled with Microsoft 365 Business Premium, that unlocks capabilities like Conditional Access.
- Azure custom roles
Roles you author yourself in Azure RBAC, listing your own permitted actions, for cases no built-in role covers; a tenant can hold as many as 5,000.
Related terms
- AssignableScopes
Property of a role definition stating at which management groups, subscriptions, resource groups or resources a custom role may be assigned.
- Container Apps Operator
Built-in role presented as operational only, yet the Microsoft.App/containerApps/*/action wildcard it carries covers listSecrets, letting it read secrets too. Leaving that permission out requires a custom role.
- Get-AzRoleDefinition
An Az cmdlet for retrieving a role definition. Piping its output into
ConvertTo-Jsonproduces a starting file for building a custom role. - Intune custom role
An Intune RBAC role you assemble from selected permissions so administrators get only what they need. Built-in roles are read-only, but you can copy one and edit the copy as a custom role.
- New-AzRoleDefinition
Cmdlet that defines a custom role, taking either a role object or a JSON file supplied with
-InputFile.