Global Secure Access Administrator

Entra ID · Security · EAM ControlPlane

Global Secure Access Administrator

Control PlaneEntraOps · EAMSecurity

Dado verificado em · Fonte

Role Actions
20
Control Plane
1
Management Plane
15
User Access
4
Template ID
ac434307-12b9-4fa1-a708-88bf58caabc1
Categoria
Security
EAM Tier
Control Plane (Tier 0)
Enterprise Access Model: Control Plane

Controle total do tenant. Comprometimento leva a takeover completo. Isole de planos inferiores.

Esta role é classificada como Control Plane porque 1 de 20 ações (5%) são desse tier — o tier da role acompanha sempre a ação de maior privilégio, não o conjunto.

1 Control Plane15 Management Plane4 User Access

Ação responsável:

microsoft.networkAccess/allEntities/allProperties/allTasks

Descrição

Create and manage all aspects of Global Secure Internet Access and Microsoft Global Secure Private Access, including managing access to public and private endpoints.

Role Definition (JSON)

{
"@odata.type": "#microsoft.graph.unifiedRoleDefinition",
"id": "ac434307-12b9-4fa1-a708-88bf58caabc1",
"displayName": "Global Secure Access Administrator",
"description": "Create and manage all aspects of Global Secure Internet Access and Microsoft Global Secure Private Access, including managing access to public and private endpoints.",
"isBuiltIn": true,
"isEnabled": true,
"isPrivileged": false,
"rolePermissions": [
{
"allowedResourceActions": [
"microsoft.networkAccess/allEntities/allProperties/allTasks",

Permissões completas

Todas as 20 role actions desta role, classificadas por tier do EAM.

Role ActionCategoriaTier
microsoft.networkAccess/allEntities/allProperties/allTasks
Global Secure Access ManagementTier 0
microsoft.azure.supportTickets/allEntities/allTasks
Support and Service HealthTier 1
microsoft.directory/applications/applicationProxy/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/auditLogs/allProperties/read
Security and ComplianceTier 1
microsoft.directory/conditionalAccessPolicies/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/connectorGroups/allProperties/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/connectors/allProperties/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/crossTenantAccessPolicy/default/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/crossTenantAccessPolicy/partners/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/crossTenantAccessPolicy/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/namedLocations/standard/read
Tenant Configuration (Reader)Tier 1
microsoft.directory/signInReports/allProperties/read
Security and ComplianceTier 1
microsoft.office365.messageCenter/messages/read
Microsoft 365 Support OperationsTier 1
microsoft.office365.serviceHealth/allEntities/allTasks
Microsoft 365 Support OperationsTier 1
microsoft.office365.supportTickets/allEntities/allTasks
Microsoft 365 Support OperationsTier 1
microsoft.office365.webPortal/allEntities/standard/read
Microsoft 365 Support OperationsTier 1
microsoft.directory/applicationPolicies/standard/read
Default memberTier 2
microsoft.directory/applications/owners/read
Default memberTier 2
microsoft.directory/applications/policies/read
Default memberTier 2
microsoft.directory/applications/standard/read
Default memberTier 2

20 de 20 role actions

PowerShell

Get-MgRoleManagementDirectoryRoleDefinition `
  -UnifiedRoleDefinitionId "ac434307-12b9-4fa1-a708-88bf58caabc1"

Microsoft Graph

GET https://graph.microsoft.com/v1.0/
  roleManagement/directory/
  roleDefinitions/ac434307-12b9-4fa1-a708-88bf58caabc1
Ver a documentação oficial na Microsoft Learn

Roles relacionadas