| 
 Azure - Configuration Administrator   | 
 Grants the following permissions: 
- Read and write Azure tenants. 
 - Read and write Azure applications. 
 - Read Azure health check reports. 
 - Read Azure license reports. 
 - Read Azure roles reports. 
   | 
| 
 Azure - Contact Full Control   | 
 Grants the following permissions: 
- Add and enable new Azure contacts. 
 - View existing Azure contacts. 
 - Update the properties of existing Azure contacts. 
   | 
| 
 Azure - Full Control   | 
 Grants full permission to: 
 | 
| 
 Azure - Group Full Control   | 
 Grants the following permissions: 
- Add and enable new Azure groups. 
 - View existing Azure groups. 
 - Update the properties of existing Azure groups. 
   | 
| 
 Azure - Health Check, O365 Roles Report and License Report   | 
 Grants permission to access the Azure health check, M365 roles and license reports. 
NOTE: This Access Template must be applied on a Configuration container.   | 
| 
 Azure - Read All Attributes   | 
 Grants permission to read all Azure attributes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure - Read All Contact Attributes   | 
 Grants permission to read all Azure contact attributes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure - Read All Group Attributes   | 
 Grants the following permissions: 
 | 
| 
 Azure - Read All User Attributes   | 
 Grants permission to read all Azure user and guest user attributes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure - User Full Control   | 
 Grants the following permissions: 
 | 
| 
 Azure Cloud Contact - Create Objects   | 
 Grants permission to create cloud-only Azure contact accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud Contact - Delete Objects   | 
 Grants permission to delete cloud-only Azure contact accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud Contact - Full Control   | 
 Grants the following permissions: 
 | 
| 
 Azure Cloud Contact - Modify Objects   | 
 Grants permission to modify cloud-only Azure contact accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud Contact - Read All Attributes   | 
 Grants permission to read all cloud-only Azure contact attributes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud User - Create Objects   | 
 Grants permission to create cloud-only Azure user accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud User - Delete Objects   | 
 Grants permission to delete cloud-only Azure user accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud User - Full Control   | 
 Grants the following permissions: 
 | 
| 
 Azure Cloud User - Modify Objects   | 
 Grants permission to modify cloud-only Azure user accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Cloud User - Read All Attributes   | 
 Grants permission to read all cloud-only Azure user attributes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Distribution Groups - Create Objects   | 
 Grants permission to create Azure distribution groups. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Distribution Groups - Delete Objects   | 
 Grants permission to delete Azure distribution groups. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Distribution Groups - Full Control   | 
 Grants the following permissions: 
- Add and enable new Azure distribution groups. 
 - View existing Azure distribution groups. 
 - Update the properties of existing Azure distribution groups. 
   | 
| 
 Azure Distribution Groups - Modify Members   | 
 Grants permission to modify the members of Azure distribution groups. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Distribution Groups - Modify Objects   | 
 Grants the following permissions: 
 | 
| 
 Azure Distribution Groups - Read All Attributes   | 
 Grants the following permissions: 
 | 
| 
 Azure Dynamic Distribution Groups - Create Objects   | 
 Grants permission to create Azure dynamic distribution groups.  | 
| 
 Azure Dynamic Distribution Groups - Delete Objects   | 
 Grants permission to delete Azure dynamic distribution groups.  | 
| 
 Azure Dynamic Distribution Groups - Full Control   | 
 Grants the following permissions: 
- 
Add and enable new Azure dynamic distribution groups. 
 - 
View existing Azure dynamic distribution groups. 
 - 
Update the properties of existing Azure dynamic distribution groups.    | 
| 
 Azure Dynamic Distribution Groups - Modify Members   | 
 Grants permission to modify the members of Azure dynamic distribution groups.  | 
| 
 Azure Dynamic Distribution Groups - Modify Objects   | 
 Grants permission to list all Azure dynamic distribution groups and modify their properties.  | 
| 
 Azure Dynamic Distribution Groups - Full Control   | 
 Grants permission to list all Azure dynamic distribution groups and view their properties.  | 
| 
 Azure Guest User - Create Objects   | 
 Grants permission to create Azure guest user accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Guest User - Delete Objects   | 
 Grants permission to delete Azure guest user accounts. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Guest User - Full Control   | 
 Grants the following permissions: 
 | 
| 
 Azure Guest User - Modify Objects   | 
 Grants the following permissions: 
 | 
| 
 Azure Guest User - Read All Attributes   | 
 Grants the following permissions: 
 | 
| 
 Azure Health Check Report   | 
 Grants permission to access Azure health check reports. 
NOTE: This Access Template must be applied on a Configuration container.   | 
| 
 Azure License Report   | 
 Grants permission to access Azure license reports. 
NOTE: This Access Template must be applied on a Configuration container.   | 
| 
 Azure Microsoft365 Groups - Create Objects   | 
 Grants permission to create M365 groups. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Microsoft365 Groups - Full Control   | 
 Grants the following permissions: 
- Add and enable new Azure M365 groups. 
 - View existing Azure M365 groups. 
 - Update the properties of existing Azure M365 groups. 
   | 
| 
 Azure Microsoft365 Groups - Modify members   | 
 Grants permission to modify the membership list of M365 groups.  | 
| 
 Azure Microsoft365 Groups - Read All Attributes   | 
 Grants the following permissions: 
 | 
| 
 Azure O365 Roles Report   | 
 Grants permission to access M365 roles reports. 
NOTE: This Access Template must be applied on a Configuration container.   | 
| 
 Azure Resource Mailboxes - Create Objects   | 
 Grants permission to create Azure resource mailboxes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Resource Mailboxes - Delete Objects   | 
 Grants permission to delete Azure resource mailboxes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Resource Mailboxes - Full Control   | 
 Grants the following permissions: 
- 
Add and enable new Azure resource mailboxes. 
 - 
View existing Azure resource mailboxes. 
 - 
Update the properties of existing Azure resource mailboxes.    | 
| 
 Azure Resource Mailboxes - Modify Objects   | 
 Grants the following permissions: 
 | 
| 
 Azure Resource Mailboxes - Read All Attributes   | 
 Grants the following permissions: 
 | 
| 
 Azure Security Group - Create Objects   | 
 Grants permission to create Azure security groups. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Security Group - Delete Objects   | 
 Grants permission to delete Azure security groups. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Security Group - Full Control   | 
 Grants the following permissions: 
- 
Add and enable new Azure security groups. 
 - 
View existing Azure security groups. 
 - 
Update the properties of existing Azure security groups.    | 
| 
 Azure Security Group - Modify Members   | 
 Grants permission to modify the members of Azure security groups.  | 
| 
 Azure Security Group - Modify Objects   | 
 Grants the following permissions: 
 | 
| 
 Azure Security Group - Read All Attributes   | 
 Grants the following permissions: 
 | 
| 
 Azure Shared Mailboxes- Create Objects   | 
 Grants permission to create Azure shared mailboxes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Shared Mailboxes - Delete Objects   | 
 Grants permission to delete Azure shared mailboxes. 
NOTE: This AT provides no additional permissions.   | 
| 
 Azure Shared Mailboxes - Full Control   | 
 Grants the following permissions: 
- 
Add and enable new Azure shared mailboxes. 
 - 
View existing Azure shared mailboxes. 
 - 
Update the properties of existing Azure shared mailboxes.    | 
| 
 Azure Shared Mailboxes - Modify Members   | 
 Grants the following permissions: 
 | 
| 
 Azure Shared Mailboxes - Read All Attributes   | 
 Grants the following permissions: 
 |