Permissions Reference
In brief
The AI Administrator and AI Reader descriptions were updated from “Microsoft 365 Copilot” to “Microsoft Copilot.” Their role IDs remain unchanged.
What Entra admins need to know
Administrators will see the updated product name when reviewing these role permissions; no action is required.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
| Agent ID Administrator | Manage all aspects of agents in a tenant including identity lifecycle operations for agent blueprints, agent identity blueprint principals, agent identities, and agentic users.
| db506228-d27e-4b7d-95e5-295956d6615f | | Agent ID Developer | Create an agent identity blueprint and its agent identity blueprint principal in a tenant. User will be added as an owner of the created agent identity blueprint and its agent identity blueprint principal. | adb2368d-a9be-41b5-8667-d96778e081b0 | | Agent Registry Administrator | Manage all aspects of the Agent Registry service in Microsoft Entra ID | 6b942400-691f-4bf0-9d12-d8a254a2baf5 | | AI Administrator | Manage all aspects of Microsoft
365Copilot and AI-related enterprise services in Microsoft 365.| d2562ede-74db-457e-a7b6-544e236ebb61 | | AI Reader | Read all aspects of Microsoft
365Copilot and AI-related enterprise services in Microsoft 365.| 1fe13547-53f6-408d-ac04-7f8eed167b38 | | Application Administrator | Can create and manage all aspects of app registrations and enterprise apps.
| 9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3 | | Application Developer | Can create application registrations independent of the 'Users can register applications' setting.
| cf1c38e5-3621-4004-a7cb-879624dced7c | | Attack Payload Author | Can create attack payloads that an administrator can initiate later. | 9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f |
@@ -26,8 +26,8 @@ This article lists the permissions used by **built-in** roles. Only a subset of > | [Agent ID Administrator](#agent-id-administrator) | Manage all aspects of agents in a tenant including identity lifecycle operations for agent blueprints, agent identity blueprint principals, agent identities, and agentic users.<br/>[](privileged-roles-permissions.md) | db506228-d27e-4b7d-95e5-295956d6615f | > | [Agent ID Developer](#agent-id-developer) | Create an agent identity blueprint and its agent identity blueprint principal in a tenant. User will be added as an owner of the created agent identity blueprint and its agent identity blueprint principal. | adb2368d-a9be-41b5-8667-d96778e081b0 | > | [Agent Registry Administrator](#agent-registry-administrator) | Manage all aspects of the Agent Registry service in Microsoft Entra ID | 6b942400-691f-4bf0-9d12-d8a254a2baf5 |-> | [AI Administrator](#ai-administrator) | Manage all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365.<br/>[](privileged-roles-permissions.md) | d2562ede-74db-457e-a7b6-544e236ebb61 |-> | [AI Reader](#ai-reader) | Read all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365.<br/>[](privileged-roles-permissions.md) | 1fe13547-53f6-408d-ac04-7f8eed167b38 |+> | [AI Administrator](#ai-administrator) | Manage all aspects of Microsoft Copilot and AI-related enterprise services in Microsoft 365.<br/>[](privileged-roles-permissions.md) | d2562ede-74db-457e-a7b6-544e236ebb61 |+> | [AI Reader](#ai-reader) | Read all aspects of Microsoft Copilot and AI-related enterprise services in Microsoft 365.<br/>[](privileged-roles-permissions.md) | 1fe13547-53f6-408d-ac04-7f8eed167b38 | > | [Application Administrator](#application-administrator) | Can create and manage all aspects of app registrations and enterprise apps.<br/>[](privileged-roles-permissions.md) | 9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3 | > | [Application Developer](#application-developer) | Can create application registrations independent of the 'Users can register applications' setting.<br/>[](privileged-roles-permissions.md) | cf1c38e5-3621-4004-a7cb-879624dced7c | > | [Attack Payload Author](#attack-payload-author) | Can create attack payloads that an administrator can initiate later. | 9c6df0f2-1e7c-4dc3-b195-66dfbd24aa8f | 
