1600 - Supported Entra ID object attributes: Roles

Modified on Tue, 5 Aug at 1:09 PM

Page contents

Supported attributes

Supported relationships

 

Supported attributes

AttributeDescriptionBacked upRestorable
idThe unique identifier for the role. Read-only.YesNo
descriptionRole description. Read-only when isBuiltIn is true.YesNo
isBuiltInFlag indicating if the role is part of the default set included with the product or custom.YesNo
isEnabledFlag indicating if the role is enabled for assignment.YesNo
isPrivilegedFlag indicating if the role is privileged. Read-only. YesNo
rolePermissionsList of permissions included in the role.YesYes
templateIdCustom template identifier that can be set when isBuiltIn is false.YesYes
versionIndicates version of the role.YesYes
displayNameThe display name for role. Read-only. YesYes
visibilityControls whether the role is hidden or public.NoNo
inheritsPermissionsFromRead-only collection of role definitions that the given role definition inherits from. Only Microsoft Entra built-in roles (isBuiltIn is true) support this attribute. NoNo
resourceScopesList of the scopes or permissions the role definition applies to. Read-only when isBuiltIn is trueNoNo

 

Supported relationships

Role assignments

Note:

  • Directory roles (also called built-in Entra ID roles) are read-only and cannot be deleted from Entra ID. The attributes of these roles cannot be restored, but their assigned relationships can.
  • Custom roles can be modified and can be deleted from Entra ID. The attributes of these roles, as well as their assigned relationships, can be restored.
  • Read about the limitations of Entra ID object recovery in Article 1554.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article