Built-in roles
Built-in assistant administrator roles provide immediate access to a set of commonly used powers. You can extend your current security configuration by using these default roles to delegate power to specific user accounts or other groups.
These roles contain the powers required to perform common administration tasks. For example, the DRA Administration role contains all the powers required to manage objects. To use these powers, however, the role must be associated with a user account or an assistant administrator group and the managed ActiveView.
Because built-in roles are part of the default delegation model, you can use the built-in roles to quickly delegate power and implement security These built-in roles address common tasks you can perform through the DRA user interfaces. The following sections describe each built-in role and summarize the powers associated with that role.
Microsoft Entra ID Management
- Entra ID Contact Administration
-
Provides all the powers required to create, modify, delete, and view properties of an Entra ID contact. You can assign this role to all assistant administrators who are responsible for managing Entra ID contacts.
- Entra ID Group Administration
-
Provides all the powers required to manage Entra ID groups and Entra ID membership.
- Entra ID User Administration
-
Provides all the powers required to create, modify, delete, enable, disable, and view properties of an Entra ID user. Assign this role to assistant administrators responsible for managing Entra ID users.
- Entra ID Guest User Administration
-
Provides all the powers required to manage an Entra ID guest user. Assign this role to assistant administrators responsible for managing an Entra ID guest user.
- Online Shared Mailbox Administration
-
Provides all the powers required to create, modify, delete and view properties of an Online Shared Mailbox. Assign this role to assistant administrators responsible for managing Online Shared Mailboxes.
Administration
- Contact Administration
-
Provides all the powers required to create a new contact, modify contact properties, or delete a contact. Assign this role to assistant administrators responsible for managing contacts.
- DRA Administration
-
Provides all powers to an assistant administrator. This role gives a user the permission to perform all administration tasks within DRA. This role is equivalent to the permissions of an administrator. An assistant administrator associated with the DRA Administration role can access all Directory and Resource Administrator nodes.
- gMSA Administration
-
Provides the powers required to create, modify, delete, and view properties of a group Managed Service Account (gMSA). You can assign this role to all assistant administrators who are responsible for managing a gMSA.
- Manage and Execute Custom Tools
-
Provides all the powers required to create, manage, and execute custom tools. Assign this role to assistant administrators responsible for managing custom tools.
- Manage Clone Exceptions
-
Provides all the powers required to create and manage clone exceptions.
- Manage Policies and Automation Triggers
-
Provides all the powers required to define policies and automation triggers. Assign this role to assistant administrators responsible for maintaining company policies and automating workflows.
- Manage Security Model
-
Provides all the powers required to define the Administration rules, including ActiveViews, assistant administrators, and roles. Assign this role to assistant administrators responsible for implementing and maintaining your security model.
- Manage Virtual Attributes
-
Provides all the powers required to create and manage virtual attributes. Assign this role to assistant administrators responsible for managing virtual attributes.
- OU Administration
-
Provides all the powers required to manage organizational units. Assign this role to assistant administrators responsible for managing the Active Directory structure.
- Public Folder Administration
-
Provides the powers to create, modify, delete, enable, or disable mail and view the properties of your Public Folder. You can assign this role to all assistant administrators who are responsible for managing Public Folder.
- Replicate Files
-
Provides all the powers required to upload, delete, and modify file information. Assign this role to assistant administrators responsible for replicating files from the primary Administration server to other Administration servers in the MMS and the DRA client computers.
- Reset Local Administrator Password
-
Provides all the powers to reset the local administrator account password and view the name of the computer administrator. Assign this role to assistant administrators responsible for managing the administrator accounts.
- Self Administration
-
Provides all the powers required to modify basic properties, such as telephone numbers, of your own user account. Assign this role to assistant administrators to allow them to manage their own personal information.
Advanced Query Management
- Execute Advanced Queries
-
Provides all the powers required to execute saved advanced queries. Assign this role to assistant administrators responsible for executing advanced queries.
- Manage Advanced Queries
-
Provides all the powers required to create, manage, and execute advanced queries. Assign this role to assistant administrators responsible for managing advanced queries.
Audit Management
- Audit All Objects
-
Provides all the powers required to view properties of objects, policies, and configurations across your enterprise. This role does not allow an assistant administrator to modify properties. Assign this role to assistant administrators responsible for auditing actions across your enterprise. Allows assistant administrators to view all nodes except the Custom Tools node.
- Audit Limited Account and Resource Properties
-
Provides powers for all object properties.
- Audit Resources
-
Provides all the powers required to view properties of managed resources. Assign this role to assistant administrators responsible for auditing resource objects.
- Audit Users and Groups
-
Provides all the powers needed to view user account and group properties, but no powers to modify these properties. Assign this role to assistant administrators responsible for auditing account properties.
Computer Management
- Computer Administration
-
Provides all the powers required to modify computer properties. This role allows assistant administrators to add, delete, and shut down computers, as well as synchronize domain controllers. Assign this role to assistant administrators responsible for managing computers in the ActiveView.
- Create and Delete Computer Accounts
-
Provides all the powers required to create and delete a computer account. Assign this role to assistant administrators responsible for managing computers.
- Manage Computer Properties
-
Provides all the powers required to manage all properties for a computer account. Assign this role to assistant administrators responsible for managing computers.
- View All Computer Properties
-
Provides all the powers required to view properties of a computer account. Assign this role to assistant administrators responsible for auditing computers.
Exchange Management
- Clone User with Mailbox
-
Provides all the powers required to clone an existing user account along with the account mailbox. Assign this role to assistant administrators responsible for managing user accounts.
To allow the assistant administrator to add the new user account to a group during the clone task, also assign the Manage Group Memberships role.
- Create and Delete Resource Mailbox
-
Provides all the powers required to create and delete a mailbox. Assign this role to assistant administrators responsible for managing mailboxes.
- Mailbox Administration
-
Provides all the powers required to manage Microsoft Exchange mailbox properties. If you use Microsoft Exchange, assign this role to assistant administrators responsible for managing Microsoft Exchange mailboxes.
- Manage Exchange Mailbox Rights
-
Provides all the powers required to manage security and rights for Microsoft Exchange mailboxes. If you use Microsoft Exchange, assign this role to assistant administrators responsible for managing Microsoft Exchange mailbox permissions.
- Manage Group Email
-
Provides all the powers required to view, enable, or disable the email address for a group. Assign this role to assistant administrators responsible for managing groups or email addresses for account objects.
- Manage Mailbox Move Requests
-
Provides all the powers required to manage mailbox move requests.
- Manage Resource Mailbox Properties
-
Provides all the powers required to manage all properties for a mailbox. Assign this role to assistant administrators responsible for managing mailboxes.
- Manage User Email
-
Provides all the powers required to view, enable, or disable the email address for a user account. Assign this role to assistant administrators responsible for managing user accounts or email addresses for account objects.
- Reset Unified Messaging PIN Properties
-
Provides all the powers required to reset Unified Messaging PIN properties for user accounts.
- Resource Mailbox Administration
-
Provides all the powers required to manage resource mailboxes.
- Shared Mailbox Administration
-
Provides all the powers required to create, modify, delete, and view the properties of your shared mailboxes. Assign this role to all assistant administrators responsible for managing shared mailboxes.
- View All Resource Mailbox Properties
-
Provides all the powers required to view properties for a resource mailbox. Assign this role to assistant administrators responsible for auditing resource mailboxes.
Group Management
- Create and Delete Groups
-
Provides all the powers required to create and delete a group. Assign this role to assistant administrators responsible for managing groups.
- Dynamic Group Administration
-
Provides all the powers required to manage Active Directory dynamic groups.
- Group Administration
-
Provides all the powers required to manage groups and group memberships, and view corresponding user properties. Assign this role to assistant administrators responsible for managing groups or account and resource objects that are managed through groups.
- Manage Dynamic Distribution Groups
-
Provides all the powers required to manage Microsoft Exchange dynamic distribution groups.
- Manage Group Membership Security
-
Provides all the powers required to designate who can view and modify Microsoft Windows group memberships through Microsoft Outlook
- Manage Group Memberships
-
Provides all the powers required to add and remove user accounts or groups from an existing group, and view the primary group of a user or computer account. Assign this role to assistant administrators responsible for managing groups or user accounts.
- Manage Group Properties
-
Provides all the powers required to manage all properties for a group. Assign this role to assistant administrators responsible for managing groups.
- Manage Temporary Group Assignments
-
Provides all the powers required to create and manage temporary group assignments. Assign this role to assistant administrators responsible for managing groups.
- Rename Group and Modify Description
-
Provides all the powers required to modify the name and description of a group. Assign this role to assistant administrators responsible for managing groups.
- View All Group Properties
-
Provides all the powers required to view properties for a group. Assign this role to assistant administrators responsible for auditing groups.
Reporting Management
- Manage Active Directory Collectors, DRA Collectors, and Management Reporting Collectors
-
Provides all the powers required to manage Active Directory Collectors, DRA Collectors, and Management Reporting Collectors for data collection. Assign this role to assistant administrators responsible for managing reporting configuration.
- Manage Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and Database Configuration
-
Provides all the powers required to manage Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and database configuration for data collection. Assign this role to assistant administrators responsible for managing reporting and database configuration.
- Manage UI Reporting
-
Provides all the powers required to generate and export Activity Detail reports for users, groups, contacts, computers, organizational units, powers, roles, ActiveViews, containers, published printers, and assistant administrators. Assign this role to assistant administrators responsible for generating reports.
- Manage Database Configuration
-
Provides all the powers required to manage database configuration for Management reports. Assign this role to assistant administrators responsible for managing reporting database configuration.
- View Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and Database Configuration Information
-
Provides all the powers required to view AD collectors, DRA collectors, management reporting collectors, and database configuration information.
Resource Management
- Create and Delete Resources
-
Provides all the powers required to create and delete shares and computer accounts, and clear event logs. Assign this role to assistant administrators responsible for managing resource objects and event logs.
- Manage Printers and Print Jobs
-
Provides all the powers required to manage printers, print queues, and print jobs. To manage print jobs associated with a user account, the print job and the user account must be included in the same ActiveView. Assign this role to assistant administrators responsible for maintaining printers and managing print jobs.
- Manage Resources for Managed Users
-
Provides all the powers required to manage resources associated with specific user accounts. The assistant administrator and the user accounts must be included in the same ActiveView. Assign this role to assistant administrators responsible for managing resource objects.
- Manage Services
-
Provides all the powers required to manage services. Assign this role to assistant administrators responsible for managing services.
- Manage Shared Folders
-
Provides all the powers required to manage shared folders. Assign this role to assistant administrators responsible for managing shared folders.
- Resource Administration
-
Provides all the powers required to modify properties of managed resources, including resources associated with any user account. Assign this role to assistant administrators responsible for managing resource objects.
- Start and Stop Resources
-
Provides all the powers required to pause, start, resume, or stop a service, start or stop a device or printer, shut down a computer, or synchronize your domain controllers. Also provides all the powers required to pause, resume, and start services, stop devices or print queues, and shut down computers. Assign this role to assistant administrators responsible for managing resource objects.
Server Management
- Built-in Scheduler - Internal Use Only
-
Provides powers to schedule when DRA refreshes the cache.
- Application Servers Administration
-
Provides the powers required to configure, view, and delete application server configurations.
- Configure Servers and Domains
-
Provides all the powers required to modify Administration server options and managed domains. Also provides powers necessary to configure and manage Microsoft Entra Tenants. Assign this role to assistant administrators responsible for monitoring and maintaining the Administration servers and managing Microsoft Entra Tenants.
- Unified Change History Server Administration
-
Provides the powers required to configure, view, and delete Unified Change History server configurations.
- Workflow Automation Server Administration
-
Provides the powers required to configure, view, and delete Workflow Automation server configurations.
User Account Management
- Create and Delete User Accounts
-
Provides all the powers required to create and delete a user account. Assign this role to assistant administrators responsible for managing user accounts.
- Help Desk Administration
-
Provides all the powers required to view user account properties, and to change passwords and password-related properties. This role also allows assistant administrators to disable, enable, and unlock user accounts. Assign this role to assistant administrators responsible for Help Desk duties associated with ensuring users have proper access to their accounts.
- Manage User Dial in Properties
-
Provides all the powers required to modify the dial in properties of user accounts. Assign this role to assistant administrators responsible for managing user accounts that have remote access to the enterprise.
- Manage User Password and Unlock Account
-
Provides all the powers required to reset the password, specify password settings, and unlock a user account. Assign this role to assistant administrators responsible for maintaining user account access.
- Manage User Properties
-
Provides all the powers required to manage all properties for a user account, including Microsoft Exchange mailbox properties. Assign this role to assistant administrators responsible for managing user accounts.
- Rename User and Modify Description
-
Provides all the powers required to modify the name and description of a user account. Assign this role to assistant administrators responsible for managing user accounts.
- Reset Password
-
Provides all the powers required to reset and modify passwords. Assign this role to assistant administrators responsible for password management.
- Reset Password and Unlock Account Using SPA
-
Provides all the powers required to use Secure Password Administrator to reset passwords and unlock user accounts.
- Transform a User
-
Provides all the powers required to add a user to or remove a user from groups found in a template account, including the ability to modify the user's properties while transforming the user.
- User Administration
-
Provides all the powers required to manage user accounts, associated Microsoft Exchange mailboxes, and group memberships. Assign this role to assistant administrators responsible for managing user accounts.
- View All User Properties
-
Provides all the powers required to view properties for a user account. Assign this role to assistant administrators responsible for auditing user accounts.
WTS Administration
- Manage WTS Environment Properties
-
Provides all the powers required to change the WTS environment properties for a user account. Assign this role to assistant administrators responsible for maintaining the WTS environment or managing user accounts.
- Manage WTS Remote Control Properties
-
Provides all the powers required to change the WTS remote control properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS access or managing user accounts.
- Manage WTS Session Properties
-
Provides all the powers required to change the WTS session properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS sessions or managing user accounts.
- Manage WTS Terminal Properties
-
Provides all the powers required to change the WTS terminal properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS terminal properties or managing user accounts.
- WTS Administration
-
Provides all the powers required to manage Windows Terminal Server (WTS) properties for user accounts in the ActiveView. If you use WTS, assign this role to assistant administrators responsible for maintaining the WTS properties of user accounts.