last sync: 2025-May-25 17:20:24 Etc/UTC

Hybrid Identity Administrator - 8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2
Entra Id Role definition

Display name Hybrid Identity Administrator
Id 8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2
Description Can manage Active Directory to Microsoft Entra cloud provisioning, Microsoft Entra Connect, and federation settings.
Detailed description Users in this role can create, manage, and deploy provisioning configuration setup from Active Directory to Microsoft Entra ID using Cloud Provisioning as well as manage federation settings. Users can also troubleshoot and monitor logs using this role.
Categories identity
isPrivileged True Privileged
EntraOps Tier Level ControlPlane
#Resource Actions unique 114
#Resource Actions Operations unique 117
#Resource Actions privileged 2
#Resource Actions direct 60
Resource Actions inherited True
#Resource Actions inherited 54
Resource Actions inherited from Directory Readers (88d8e3e3-8f55-4a1e-953a-9b9898b8876b)
#Resource Actions overlap direct&inherited 0
Resource Actions overlap direct&inherited
#Resource Actions inherited to 0 other Entra Id Roles
Resource Actions inherited to n/a
#Resource Actions conditioned 0
#Resource Actions unconditioned 114
#NameSpaces 7
NameSpaces microsoft.azure.serviceHealth: 1
microsoft.azure.supportTickets: 1
microsoft.directory: 108
microsoft.office365.messageCenter: 1
microsoft.office365.serviceHealth: 1
microsoft.office365.supportTickets: 1
microsoft.office365.webPortal: 1
Actions allTasks: 7
create: 3
delete: 4
disable: 1
enable: 1
manage: 9
other: 1
read: 64
restore: 1
update: 23
Operations actionVerbs DELETE: 7
GET: 64
n/a: 7
PATCH: 22
POST: 17
Resource Actions where Consent Policy applies 0
Resource Actions / Consent Policy n/a
JSON enriched
{29 items}
JSON raw (v1.0 endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
{12 items
  • @odata.context: "https://graph.microsoft.com/v1.0/$metadata#roleManagement/directory/roleDefinitions/$entity",
  • id: "8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2",
  • description: "Can manage Active Directory to Microsoft Entra cloud provisioning, Microsoft Entra Connect, and federation settings.",
  • displayName: "Hybrid Identity Administrator",
  • isBuiltIn: true,
  • isEnabled: true,
  • resourceScopes: [1 item
    • "/"
    ],
  • templateId: "8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2",
  • version: "1",
  • rolePermissions: [1 item
    • {2 items
      • allowedResourceActions: [60 items
        • "microsoft.azure.serviceHealth/allEntities/allTasks",
        • "microsoft.azure.supportTickets/allEntities/allTasks",
        • "microsoft.directory/applications/appRoles/update",
        • "microsoft.directory/applications/audience/update",
        • "microsoft.directory/applications/authentication/update",
        • "microsoft.directory/applications/basic/update",
        • "microsoft.directory/applications/create",
        • "microsoft.directory/applications/delete",
        • "microsoft.directory/applications/notes/update",
        • "microsoft.directory/applications/owners/update",
        • "microsoft.directory/applications/permissions/update",
        • "microsoft.directory/applications/policies/update",
        • "microsoft.directory/applications/synchronization/standard/read",
        • "microsoft.directory/applications/tag/update",
        • "microsoft.directory/applicationTemplates/instantiate",
        • "microsoft.directory/auditLogs/allProperties/read",
        • "microsoft.directory/cloudProvisioning/allProperties/allTasks",
        • "microsoft.directory/deletedItems.applications/delete",
        • "microsoft.directory/deletedItems.applications/restore",
        • "microsoft.directory/domains/allProperties/read",
        • "microsoft.directory/domains/federationConfiguration/basic/update",
        • "microsoft.directory/domains/federationConfiguration/create",
        • "microsoft.directory/domains/federationConfiguration/delete",
        • "microsoft.directory/domains/federationConfiguration/standard/read",
        • "microsoft.directory/domains/federation/update",
        • "microsoft.directory/hybridAuthenticationPolicy/allProperties/allTasks",
        • "microsoft.directory/onPremisesSynchronization/basic/update",
        • "microsoft.directory/onPremisesSynchronization/standard/read",
        • "microsoft.directory/organization/dirSync/update",
        • "microsoft.directory/passwordHashSync/allProperties/allTasks",
        • "microsoft.directory/provisioningLogs/allProperties/read",
        • "microsoft.directory/servicePrincipals/appRoleAssignedTo/update",
        • "microsoft.directory/servicePrincipals/audience/update",
        • "microsoft.directory/servicePrincipals/authentication/update",
        • "microsoft.directory/servicePrincipals/basic/update",
        • "microsoft.directory/servicePrincipals/create",
        • "microsoft.directory/servicePrincipals/delete",
        • "microsoft.directory/servicePrincipals/disable",
        • "microsoft.directory/servicePrincipals/enable",
        • "microsoft.directory/servicePrincipals/notes/update",
        • "microsoft.directory/servicePrincipals/owners/update",
        • "microsoft.directory/servicePrincipals/permissions/update",
        • "microsoft.directory/servicePrincipals/policies/update",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/credentials/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/jobs/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/schema/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/credentials/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/jobs/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/schema/manage",
        • "microsoft.directory/servicePrincipals/synchronizationCredentials/manage",
        • "microsoft.directory/servicePrincipals/synchronizationJobs/manage",
        • "microsoft.directory/servicePrincipals/synchronizationSchema/manage",
        • "microsoft.directory/servicePrincipals/synchronization/standard/read",
        • "microsoft.directory/servicePrincipals/tag/update",
        • "microsoft.directory/signInReports/allProperties/read",
        • "microsoft.directory/users/authorizationInfo/update",
        • "microsoft.office365.messageCenter/messages/read",
        • "microsoft.office365.serviceHealth/allEntities/allTasks",
        • "microsoft.office365.supportTickets/allEntities/allTasks",
        • "microsoft.office365.webPortal/allEntities/standard/read"
        ],
      • condition: null
      }
    ],
  • inheritsPermissionsFrom@odata.context: "https://graph.microsoft.com/v1.0/$metadata#roleManagement/directory/roleDefinitions('8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2')/inheritsPermissionsFrom",
  • inheritsPermissionsFrom: [1 item
    • {1 item
      • id: "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
      }
    ]
}
JSON raw (beta endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
{16 items
  • @odata.context: "https://graph.microsoft.com/beta/$metadata#roleManagement/directory/roleDefinitions/$entity",
  • id: "8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2",
  • assignmentMode: "allowed",
  • categories: "identity",
  • description: "Can manage Active Directory to Microsoft Entra cloud provisioning, Microsoft Entra Connect, and federation settings.",
  • displayName: "Hybrid Identity Administrator",
  • isBuiltIn: true,
  • isEnabled: true,
  • isPrivileged: true,
  • resourceScopes: [1 item
    • "/"
    ],
  • richDescription: "Users in this role can create, manage, and deploy provisioning configuration setup from Active Directory to Microsoft Entra ID using Cloud Provisioning as well as manage federation settings. Users can also troubleshoot and monitor logs using this role.",
  • templateId: "8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2",
  • version: "1",
  • rolePermissions: [1 item
    • {2 items
      • allowedResourceActions: [60 items
        • "microsoft.azure.serviceHealth/allEntities/allTasks",
        • "microsoft.azure.supportTickets/allEntities/allTasks",
        • "microsoft.directory/applications/appRoles/update",
        • "microsoft.directory/applications/audience/update",
        • "microsoft.directory/applications/authentication/update",
        • "microsoft.directory/applications/basic/update",
        • "microsoft.directory/applications/create",
        • "microsoft.directory/applications/delete",
        • "microsoft.directory/applications/notes/update",
        • "microsoft.directory/applications/owners/update",
        • "microsoft.directory/applications/permissions/update",
        • "microsoft.directory/applications/policies/update",
        • "microsoft.directory/applications/synchronization/standard/read",
        • "microsoft.directory/applications/tag/update",
        • "microsoft.directory/applicationTemplates/instantiate",
        • "microsoft.directory/auditLogs/allProperties/read",
        • "microsoft.directory/cloudProvisioning/allProperties/allTasks",
        • "microsoft.directory/deletedItems.applications/delete",
        • "microsoft.directory/deletedItems.applications/restore",
        • "microsoft.directory/domains/allProperties/read",
        • "microsoft.directory/domains/federationConfiguration/basic/update",
        • "microsoft.directory/domains/federationConfiguration/create",
        • "microsoft.directory/domains/federationConfiguration/delete",
        • "microsoft.directory/domains/federationConfiguration/standard/read",
        • "microsoft.directory/domains/federation/update",
        • "microsoft.directory/hybridAuthenticationPolicy/allProperties/allTasks",
        • "microsoft.directory/onPremisesSynchronization/basic/update",
        • "microsoft.directory/onPremisesSynchronization/standard/read",
        • "microsoft.directory/organization/dirSync/update",
        • "microsoft.directory/passwordHashSync/allProperties/allTasks",
        • "microsoft.directory/provisioningLogs/allProperties/read",
        • "microsoft.directory/servicePrincipals/appRoleAssignedTo/update",
        • "microsoft.directory/servicePrincipals/audience/update",
        • "microsoft.directory/servicePrincipals/authentication/update",
        • "microsoft.directory/servicePrincipals/basic/update",
        • "microsoft.directory/servicePrincipals/create",
        • "microsoft.directory/servicePrincipals/delete",
        • "microsoft.directory/servicePrincipals/disable",
        • "microsoft.directory/servicePrincipals/enable",
        • "microsoft.directory/servicePrincipals/notes/update",
        • "microsoft.directory/servicePrincipals/owners/update",
        • "microsoft.directory/servicePrincipals/permissions/update",
        • "microsoft.directory/servicePrincipals/policies/update",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/credentials/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/jobs/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToCloudTenant/schema/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/credentials/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/jobs/manage",
        • "microsoft.directory/servicePrincipals/synchronization.cloudTenantToExternalSystem/schema/manage",
        • "microsoft.directory/servicePrincipals/synchronizationCredentials/manage",
        • "microsoft.directory/servicePrincipals/synchronizationJobs/manage",
        • "microsoft.directory/servicePrincipals/synchronizationSchema/manage",
        • "microsoft.directory/servicePrincipals/synchronization/standard/read",
        • "microsoft.directory/servicePrincipals/tag/update",
        • "microsoft.directory/signInReports/allProperties/read",
        • "microsoft.directory/users/authorizationInfo/update",
        • "microsoft.office365.messageCenter/messages/read",
        • "microsoft.office365.serviceHealth/allEntities/allTasks",
        • "microsoft.office365.supportTickets/allEntities/allTasks",
        • "microsoft.office365.webPortal/allEntities/standard/read"
        ],
      • condition: null
      }
    ],
  • inheritsPermissionsFrom@odata.context: "https://graph.microsoft.com/beta/$metadata#roleManagement/directory/roleDefinitions('8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2')/inheritsPermissionsFrom",
  • inheritsPermissionsFrom: [1 item
    • {1 item
      • id: "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
      }
    ]
}