last sync: 2025-Jun-01 17:01:33 Etc/UTC

Global Reader - f2ef992c-3afb-46b9-b7cf-a126ee74c451
Entra Id Role definition

Display name Global Reader
Id f2ef992c-3afb-46b9-b7cf-a126ee74c451
Description Can read everything that a Global Administrator can, but not update anything.
Detailed description Users with this role can read everything that a Global Administrator can, but not update anything.
Categories readOnly
isPrivileged True Privileged
EntraOps Tier Level ControlPlane
#Resource Actions unique 152
#Resource Actions Operations unique 152
#Resource Actions privileged 2
#Resource Actions direct 98
Resource Actions inherited True
#Resource Actions inherited 54
Resource Actions inherited from Directory Readers (88d8e3e3-8f55-4a1e-953a-9b9898b8876b)
#Resource Actions overlap direct&inherited 0
Resource Actions overlap direct&inherited
#Resource Actions inherited to 0 other Entra Id Roles
Resource Actions inherited to n/a
#Resource Actions conditioned 0
#Resource Actions unconditioned 152
#NameSpaces 29
NameSpaces microsoft.azure.serviceHealth: 1
microsoft.backup: 1
microsoft.cloudPC: 1
microsoft.commerce.billing: 2
microsoft.directory: 120
microsoft.edge: 1
microsoft.graph.dataConnect: 1
microsoft.hardware.support: 3
microsoft.insights: 1
microsoft.microsoft365.organizationalData: 1
microsoft.networkAccess: 1
microsoft.office365.copilot: 1
microsoft.office365.fileStorageContainers: 1
microsoft.office365.messageCenter: 2
microsoft.office365.network: 1
microsoft.office365.organizationalMessages: 1
microsoft.office365.protectionCenter: 1
microsoft.office365.securityComplianceCenter: 1
microsoft.office365.serviceHealth: 1
microsoft.office365.usageReports: 1
microsoft.office365.webPortal: 1
microsoft.office365.yammer: 1
microsoft.permissionsManagement: 1
microsoft.teams: 1
microsoft.virtualVisits: 1
microsoft.viva.glint: 1
microsoft.viva.goals: 1
microsoft.viva.pulse: 1
microsoft.windows.updatesDeployments: 1
Actions allTasks: 2
other: 1
read: 148
restrictedRead: 1
Operations actionVerbs GET: 149
n/a: 2
POST: 1
Resource Actions where Consent Policy applies 0
Resource Actions / Consent Policy n/a
JSON enriched
{29 items}
JSON raw (v1.0 endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
{12 items
  • @odata.context: "https://graph.microsoft.com/v1.0/$metadata#roleManagement/directory/roleDefinitions/$entity",
  • id: "f2ef992c-3afb-46b9-b7cf-a126ee74c451",
  • description: "Can read everything that a Global Administrator can, but not update anything.",
  • displayName: "Global Reader",
  • isBuiltIn: true,
  • isEnabled: true,
  • resourceScopes: [1 item
    • "/"
    ],
  • templateId: "f2ef992c-3afb-46b9-b7cf-a126ee74c451",
  • version: "1",
  • rolePermissions: [1 item
    • {2 items
      • allowedResourceActions: [98 items
        • "microsoft.azure.serviceHealth/allEntities/allTasks",
        • "microsoft.backup/allEntities/allProperties/read",
        • "microsoft.cloudPC/allEntities/allProperties/read",
        • "microsoft.commerce.billing/allEntities/allProperties/read",
        • "microsoft.commerce.billing/purchases/standard/read",
        • "microsoft.directory/accessReviews/allProperties/read",
        • "microsoft.directory/accessReviews/definitions/allProperties/read",
        • "microsoft.directory/adminConsentRequestPolicy/allProperties/read",
        • "microsoft.directory/administrativeUnits/allProperties/read",
        • "microsoft.directory/appConsent/appConsentRequests/allProperties/read",
        • "microsoft.directory/applications/allProperties/read",
        • "microsoft.directory/applications/synchronization/standard/read",
        • "microsoft.directory/auditLogs/allProperties/read",
        • "microsoft.directory/authorizationPolicy/standard/read",
        • "microsoft.directory/bitlockerKeys/key/read",
        • "microsoft.directory/bulkJobs/standard/read",
        • "microsoft.directory/cloudAppSecurity/allProperties/read",
        • "microsoft.directory/conditionalAccessPolicies/allProperties/read",
        • "microsoft.directory/connectorGroups/allProperties/read",
        • "microsoft.directory/connectors/allProperties/read",
        • "microsoft.directory/contacts/allProperties/read",
        • "microsoft.directory/crossTenantAccessPolicy/default/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/identitySynchronization/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/standard/read",
        • "microsoft.directory/customAuthenticationExtensions/allProperties/read",
        • "microsoft.directory/deviceLocalCredentials/standard/read",
        • "microsoft.directory/deviceManagementPolicies/standard/read",
        • "microsoft.directory/deviceRegistrationPolicy/standard/read",
        • "microsoft.directory/devices/allProperties/read",
        • "microsoft.directory/directoryRoles/allProperties/read",
        • "microsoft.directory/directoryRoleTemplates/allProperties/read",
        • "microsoft.directory/domains/allProperties/read",
        • "microsoft.directory/domains/federationConfiguration/standard/read",
        • "microsoft.directory/entitlementManagement/allProperties/read",
        • "microsoft.directory/externalUserProfiles/standard/read",
        • "microsoft.directory/groups/allProperties/read",
        • "microsoft.directory/groupSettings/allProperties/read",
        • "microsoft.directory/groupSettingTemplates/allProperties/read",
        • "microsoft.directory/identityProtection/allProperties/read",
        • "microsoft.directory/lifecycleWorkflows/workflows/allProperties/read",
        • "microsoft.directory/loginOrganizationBranding/allProperties/read",
        • "microsoft.directory/multiTenantOrganization/joinRequest/standard/read",
        • "microsoft.directory/multiTenantOrganization/standard/read",
        • "microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read",
        • "microsoft.directory/multiTenantOrganization/tenants/standard/read",
        • "microsoft.directory/namedLocations/standard/read",
        • "microsoft.directory/oAuth2PermissionGrants/allProperties/read",
        • "microsoft.directory/onPremisesSynchronization/standard/read",
        • "microsoft.directory/organization/allProperties/read",
        • "microsoft.directory/pendingExternalUserProfiles/standard/read",
        • "microsoft.directory/permissionGrantPolicies/standard/read",
        • "microsoft.directory/policies/allProperties/read",
        • "microsoft.directory/privilegedIdentityManagement/allProperties/read",
        • "microsoft.directory/provisioningLogs/allProperties/read",
        • "microsoft.directory/roleAssignments/allProperties/read",
        • "microsoft.directory/roleDefinitions/allProperties/read",
        • "microsoft.directory/scopedRoleMemberships/allProperties/read",
        • "microsoft.directory/serviceAction/getAvailableExtentionProperties",
        • "microsoft.directory/servicePrincipalCreationPolicies/standard/read",
        • "microsoft.directory/servicePrincipals/allProperties/read",
        • "microsoft.directory/servicePrincipals/synchronization/standard/read",
        • "microsoft.directory/signInReports/allProperties/read",
        • "microsoft.directory/subscribedSkus/allProperties/read",
        • "microsoft.directory/users/allProperties/read",
        • "microsoft.directory/users/authenticationMethods/standard/restrictedRead",
        • "microsoft.directory/verifiableCredentials/configuration/allProperties/read",
        • "microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/read",
        • "microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read",
        • "microsoft.edge/allEntities/allProperties/read",
        • "microsoft.graph.dataConnect/allEntities/allProperties/read",
        • "microsoft.hardware.support/shippingAddress/allProperties/read",
        • "microsoft.hardware.support/shippingStatus/allProperties/read",
        • "microsoft.hardware.support/warrantyClaims/allProperties/read",
        • "microsoft.insights/allEntities/allProperties/read",
        • "microsoft.microsoft365.organizationalData/allEntities/allProperties/read",
        • "microsoft.networkAccess/allEntities/allProperties/read",
        • "microsoft.office365.copilot/allEntities/allProperties/read",
        • "microsoft.office365.fileStorageContainers/allEntities/allProperties/read",
        • "microsoft.office365.messageCenter/messages/read",
        • "microsoft.office365.messageCenter/securityMessages/read",
        • "microsoft.office365.network/performance/allProperties/read",
        • "microsoft.office365.organizationalMessages/allEntities/allProperties/read",
        • "microsoft.office365.protectionCenter/allEntities/allProperties/read",
        • "microsoft.office365.securityComplianceCenter/allEntities/read",
        • "microsoft.office365.serviceHealth/allEntities/allTasks",
        • "microsoft.office365.usageReports/allEntities/allProperties/read",
        • "microsoft.office365.webPortal/allEntities/standard/read",
        • "microsoft.office365.yammer/allEntities/allProperties/read",
        • "microsoft.permissionsManagement/allEntities/allProperties/read",
        • "microsoft.teams/allEntities/allProperties/read",
        • "microsoft.virtualVisits/allEntities/allProperties/read",
        • "microsoft.viva.glint/allEntities/allProperties/read",
        • "microsoft.viva.goals/allEntities/allProperties/read",
        • "microsoft.viva.pulse/allEntities/allProperties/read",
        • "microsoft.windows.updatesDeployments/allEntities/allProperties/read"
        ],
      • condition: null
      }
    ],
  • inheritsPermissionsFrom@odata.context: "https://graph.microsoft.com/v1.0/$metadata#roleManagement/directory/roleDefinitions('f2ef992c-3afb-46b9-b7cf-a126ee74c451')/inheritsPermissionsFrom",
  • inheritsPermissionsFrom: [1 item
    • {1 item
      • id: "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
      }
    ]
}
JSON raw (beta endpoint)
GET /roleManagement/directory/roleDefinitions/{id}
{16 items
  • @odata.context: "https://graph.microsoft.com/beta/$metadata#roleManagement/directory/roleDefinitions/$entity",
  • id: "f2ef992c-3afb-46b9-b7cf-a126ee74c451",
  • assignmentMode: "allowed",
  • categories: "readOnly",
  • description: "Can read everything that a Global Administrator can, but not update anything.",
  • displayName: "Global Reader",
  • isBuiltIn: true,
  • isEnabled: true,
  • isPrivileged: true,
  • resourceScopes: [1 item
    • "/"
    ],
  • richDescription: "Users with this role can read everything that a Global Administrator can, but not update anything.",
  • templateId: "f2ef992c-3afb-46b9-b7cf-a126ee74c451",
  • version: "1",
  • rolePermissions: [1 item
    • {2 items
      • allowedResourceActions: [98 items
        • "microsoft.azure.serviceHealth/allEntities/allTasks",
        • "microsoft.backup/allEntities/allProperties/read",
        • "microsoft.cloudPC/allEntities/allProperties/read",
        • "microsoft.commerce.billing/allEntities/allProperties/read",
        • "microsoft.commerce.billing/purchases/standard/read",
        • "microsoft.directory/accessReviews/allProperties/read",
        • "microsoft.directory/accessReviews/definitions/allProperties/read",
        • "microsoft.directory/adminConsentRequestPolicy/allProperties/read",
        • "microsoft.directory/administrativeUnits/allProperties/read",
        • "microsoft.directory/appConsent/appConsentRequests/allProperties/read",
        • "microsoft.directory/applications/allProperties/read",
        • "microsoft.directory/applications/synchronization/standard/read",
        • "microsoft.directory/auditLogs/allProperties/read",
        • "microsoft.directory/authorizationPolicy/standard/read",
        • "microsoft.directory/bitlockerKeys/key/read",
        • "microsoft.directory/bulkJobs/standard/read",
        • "microsoft.directory/cloudAppSecurity/allProperties/read",
        • "microsoft.directory/conditionalAccessPolicies/allProperties/read",
        • "microsoft.directory/connectorGroups/allProperties/read",
        • "microsoft.directory/connectors/allProperties/read",
        • "microsoft.directory/contacts/allProperties/read",
        • "microsoft.directory/crossTenantAccessPolicy/default/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/identitySynchronization/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationIdentitySynchronization/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/partners/templates/multiTenantOrganizationPartnerConfiguration/standard/read",
        • "microsoft.directory/crossTenantAccessPolicy/standard/read",
        • "microsoft.directory/customAuthenticationExtensions/allProperties/read",
        • "microsoft.directory/deviceLocalCredentials/standard/read",
        • "microsoft.directory/deviceManagementPolicies/standard/read",
        • "microsoft.directory/deviceRegistrationPolicy/standard/read",
        • "microsoft.directory/devices/allProperties/read",
        • "microsoft.directory/directoryRoles/allProperties/read",
        • "microsoft.directory/directoryRoleTemplates/allProperties/read",
        • "microsoft.directory/domains/allProperties/read",
        • "microsoft.directory/domains/federationConfiguration/standard/read",
        • "microsoft.directory/entitlementManagement/allProperties/read",
        • "microsoft.directory/externalUserProfiles/standard/read",
        • "microsoft.directory/groups/allProperties/read",
        • "microsoft.directory/groupSettings/allProperties/read",
        • "microsoft.directory/groupSettingTemplates/allProperties/read",
        • "microsoft.directory/identityProtection/allProperties/read",
        • "microsoft.directory/lifecycleWorkflows/workflows/allProperties/read",
        • "microsoft.directory/loginOrganizationBranding/allProperties/read",
        • "microsoft.directory/multiTenantOrganization/joinRequest/standard/read",
        • "microsoft.directory/multiTenantOrganization/standard/read",
        • "microsoft.directory/multiTenantOrganization/tenants/organizationDetails/read",
        • "microsoft.directory/multiTenantOrganization/tenants/standard/read",
        • "microsoft.directory/namedLocations/standard/read",
        • "microsoft.directory/oAuth2PermissionGrants/allProperties/read",
        • "microsoft.directory/onPremisesSynchronization/standard/read",
        • "microsoft.directory/organization/allProperties/read",
        • "microsoft.directory/pendingExternalUserProfiles/standard/read",
        • "microsoft.directory/permissionGrantPolicies/standard/read",
        • "microsoft.directory/policies/allProperties/read",
        • "microsoft.directory/privilegedIdentityManagement/allProperties/read",
        • "microsoft.directory/provisioningLogs/allProperties/read",
        • "microsoft.directory/roleAssignments/allProperties/read",
        • "microsoft.directory/roleDefinitions/allProperties/read",
        • "microsoft.directory/scopedRoleMemberships/allProperties/read",
        • "microsoft.directory/serviceAction/getAvailableExtentionProperties",
        • "microsoft.directory/servicePrincipalCreationPolicies/standard/read",
        • "microsoft.directory/servicePrincipals/allProperties/read",
        • "microsoft.directory/servicePrincipals/synchronization/standard/read",
        • "microsoft.directory/signInReports/allProperties/read",
        • "microsoft.directory/subscribedSkus/allProperties/read",
        • "microsoft.directory/users/allProperties/read",
        • "microsoft.directory/users/authenticationMethods/standard/restrictedRead",
        • "microsoft.directory/verifiableCredentials/configuration/allProperties/read",
        • "microsoft.directory/verifiableCredentials/configuration/contracts/allProperties/read",
        • "microsoft.directory/verifiableCredentials/configuration/contracts/cards/allProperties/read",
        • "microsoft.edge/allEntities/allProperties/read",
        • "microsoft.graph.dataConnect/allEntities/allProperties/read",
        • "microsoft.hardware.support/shippingAddress/allProperties/read",
        • "microsoft.hardware.support/shippingStatus/allProperties/read",
        • "microsoft.hardware.support/warrantyClaims/allProperties/read",
        • "microsoft.insights/allEntities/allProperties/read",
        • "microsoft.microsoft365.organizationalData/allEntities/allProperties/read",
        • "microsoft.networkAccess/allEntities/allProperties/read",
        • "microsoft.office365.copilot/allEntities/allProperties/read",
        • "microsoft.office365.fileStorageContainers/allEntities/allProperties/read",
        • "microsoft.office365.messageCenter/messages/read",
        • "microsoft.office365.messageCenter/securityMessages/read",
        • "microsoft.office365.network/performance/allProperties/read",
        • "microsoft.office365.organizationalMessages/allEntities/allProperties/read",
        • "microsoft.office365.protectionCenter/allEntities/allProperties/read",
        • "microsoft.office365.securityComplianceCenter/allEntities/read",
        • "microsoft.office365.serviceHealth/allEntities/allTasks",
        • "microsoft.office365.usageReports/allEntities/allProperties/read",
        • "microsoft.office365.webPortal/allEntities/standard/read",
        • "microsoft.office365.yammer/allEntities/allProperties/read",
        • "microsoft.permissionsManagement/allEntities/allProperties/read",
        • "microsoft.teams/allEntities/allProperties/read",
        • "microsoft.virtualVisits/allEntities/allProperties/read",
        • "microsoft.viva.glint/allEntities/allProperties/read",
        • "microsoft.viva.goals/allEntities/allProperties/read",
        • "microsoft.viva.pulse/allEntities/allProperties/read",
        • "microsoft.windows.updatesDeployments/allEntities/allProperties/read"
        ],
      • condition: null
      }
    ],
  • inheritsPermissionsFrom@odata.context: "https://graph.microsoft.com/beta/$metadata#roleManagement/directory/roleDefinitions('f2ef992c-3afb-46b9-b7cf-a126ee74c451')/inheritsPermissionsFrom",
  • inheritsPermissionsFrom: [1 item
    • {1 item
      • id: "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
      }
    ]
}