Privileged Roles Permissions
In brief
The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.
What Entra admins need to know
Use this updated guidance when evaluating role permissions and assignments.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
| Usage Summary Reports Reader | | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | | All other built-in and custom roles | | | | | :white_check_mark: | :white_check_mark: |
Security OperatorAdministrator, Security Operator, and Entra SOC Identity Responder are limited to non-administrative user accounts and can't perform actions on privileged accounts.
| Usage Summary Reports Reader | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | | All other built-in and custom roles | | | :white_check_mark: | :white_check_mark: |
Security OperatorAdministrator, Security Operator, and Entra SOC Identity Responder are limited to non-administrative user accounts and can't perform actions on privileged accounts.
Next steps
@@ -481,7 +481,7 @@ The following table is for roles assigned at the scope of a tenant. For roles as | Usage Summary Reports Reader | | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | | All other built-in and custom roles | | | | | :white_check_mark: | :white_check_mark: | -Security Operator and Entra SOC Identity Responder are limited to non-administrative user accounts and can't perform actions on privileged accounts.+Security Administrator, Security Operator, and Entra SOC Identity Responder are limited to non-administrative user accounts and can't perform actions on privileged accounts. > [!IMPORTANT] > The [Partner Tier2 Support](permissions-reference.md#partner-tier2-support) role can reset passwords and invalidate refresh tokens for all non-administrators and administrators (including Global Administrators). The [Partner Tier1 Support](permissions-reference.md#partner-tier1-support) role can reset passwords and invalidate refresh tokens for only non-administrators. These roles should not be used because they are deprecated.@@ -531,7 +531,7 @@ The following table is for roles assigned at the scope of a tenant. For roles as | Usage Summary Reports Reader | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | | All other built-in and custom roles | | | :white_check_mark: | :white_check_mark: | -Security Operator and Entra SOC Identity Responder are limited to non-administrative user accounts and can't perform actions on privileged accounts.+Security Administrator, Security Operator, and Entra SOC Identity Responder are limited to non-administrative user accounts and can't perform actions on privileged accounts. ## Next steps 