Administrative roles at tenant level, User Administrator for example, that manage objects in Entra but confer no rights over Azure resources, which Azure RBAC handles separately.
Also called directory roles.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104SC-500SC-900AB-900SC-300SC-401MD-102
Each book explains Microsoft Entra roles in context, with comparison tables and the common traps.
Terms in this definition
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
- User Administrator
A Microsoft Entra role able to create and manage users and every kind of group, assign licences, and reset passwords for limited administrators.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
Related terms
- Custom role
Built from the preset permissions that the built-in Microsoft Entra roles also use, and assignable to the whole tenant, an administrative unit or one object. Each user it is assigned to needs Microsoft Entra ID P1; Azure custom roles are a separate thing.
- Get-AzureADDirectoryRole
An AzureAD PowerShell cmdlet, now deprecated in favour of
Get-MgDirectoryRole, for working with Entra directory roles. It has nothing to do with Azure RBAC definitions. - Microsoft Entra custom roles
Directory roles you assemble from the permissions that support customisation. They can be assigned to the whole tenant or to one object, such as an app registration, but never to Azure resources.
- Role-assignable group
Entra group, requiring Entra ID P1, that can be given directory roles because it was created with
isAssignableToRole = true. Membership must be assigned, groups cannot nest, and the flag cannot be set afterwards. - Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- Workload-specific roles
Administrator roles that live in a particular service's own permission model, for example Exchange Online role groups or the role groups in Defender and Purview, as opposed to Microsoft Entra roles.