StudyToCert

All certifications / SC-300 / Lessons

Microsoft Certified: Identity and Access Administrator Associate SC-300 (skills outline of April 27, 2026) · Domain 1: Implement and manage user identities

Microsoft Entra built-in roles, custom roles and least-privilege role assignment

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Microsoft Entra roles control who can manage the directory itself: users, groups, applications, authentication settings and so on. They are separate from Azure role-based access control (RBAC) roles such as Owner or Contributor, which control Azure resources like virtual machines and storage accounts. Mixing up the two systems is a classic exam trap, so keep the question in mind: is the admin managing identity objects, or Azure resources?

Microsoft provides many built-in Entra roles, each a fixed set of permissions. Global Administrator can do almost everything and should be rare; Microsoft recommends fewer than five. Privileged Role Administrator manages role assignments and Privileged Identity Management. User Administrator creates and manages users and groups and can reset passwords for many (but not all) users. Helpdesk Administrator resets passwords for non-administrators and a few limited roles. Authentication Administrator manages users' authentication methods for non-admins, while Privileged Authentication Administrator can do the same for any user, including Global Administrators. Other common roles include Security Administrator, Conditional Access Administrator, Groups Administrator, License Administrator, Application Administrator, Cloud Application Administrator (like Application Administrator but without application proxy rights) and Global Reader, a read-only view of almost everything.

Custom roles let you build a role from individual permissions when no built-in role fits. The set of permissions available for custom roles is narrower than the built-in catalog and is focused largely on application registrations and enterprise applications, with more areas added over time. Custom roles require a Microsoft Entra ID P1 license. You define the role once and then assign it at a scope.

A role assignment has three parts: the principal (a user, a service principal or a role-assignable group), the role definition, and the scope. The scope can be the whole tenant, an administrative unit, or a single resource such as one app registration. Assigning the Application Administrator role for just one app is far safer than assigning it tenant-wide.

Least privilege means giving each person the smallest role, at the narrowest scope, for the shortest time that lets them do the job. In practice: pick the most specific built-in role rather than defaulting to Global Administrator; scope roles to administrative units or single resources when possible; use Privileged Identity Management so assignments are eligible rather than permanently active; and review assignments regularly. You can assign roles to groups only if the group was created as role-assignable (the isAssignableToRole property), which must be set when the group is created and cannot be changed later. Only Global and Privileged Role Administrators (and the group's owners) can manage membership of such groups, which prevents lower-level admins from escalating privilege.

Key terms

Role definition
A collection of permissions, either built-in or custom, that can be assigned to a principal.
Role scope
The boundary where a role applies: the tenant, an administrative unit, or a single resource.
Role-assignable group
A group created with isAssignableToRole set to true so it can receive Entra role assignments; the setting is fixed at creation.
Global Reader
A built-in read-only role that can view most settings and data without making changes.
Least privilege
Granting only the permissions, scope and duration a person needs to perform a task.
Real-world example

A service desk team needs to reset forgotten passwords for regular staff. Instead of making them User Administrators, the identity admin assigns them the Helpdesk Administrator role through an eligible PIM assignment, so they can reset non-admin passwords after activating the role but cannot create users or reset a Global Administrator's password.

Exam tip: When a question asks for the least-privileged role, eliminate Global Administrator first, then choose the most narrowly focused role that still covers the task. Watch the difference between Authentication Administrator and Privileged Authentication Administrator: only the privileged one can manage methods for administrators.

Check yourself

What is the difference between Microsoft Entra roles and Azure RBAC roles?

Entra roles manage directory objects such as users, groups and apps; Azure RBAC roles manage Azure resources such as subscriptions, resource groups and VMs.

Can you convert an existing security group into a role-assignable group?

No. The isAssignableToRole property must be set when the group is created and cannot be changed afterward.

Which role should you assign to someone who only needs to reset passwords for non-administrative users?

Helpdesk Administrator (Password Administrator is an even narrower option), not User Administrator or Global Administrator.

Study SC-300 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-300 study plan