> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/azure-identities/entra-id/roles.md).

# Roles

The `Roles` page provides a list of enumerated roles in entire Azure. The list contains the `Object ID`, `Description`, `Privileged`, `Tier 0`,`Enabled` and `Built In`.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-8452269fdd773ca0008ae0dec1670c376d378abf%2Froles.png?alt=media" alt=""><figcaption><p>Roles</p></figcaption></figure>

## Roles Details

Details page contains the `Risk Score` of the role,`Exposure Point` and `Information` panes.

{% hint style="info" %}
You can analyze objects in the `Graph module` by clicking the `Visualize` button on the upper left side of the `Information Pane`.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-8a4a05b183785606e5b7ade44552c10ee60c7f48%2Fazure-identities-roles-image-1.png?alt=media" alt=""><figcaption><p>Roles Details</p></figcaption></figure>

## Information

`Information Pane` can contain different badges to highlight important attributes.

| Badge          | Description                                                                           |
| -------------- | ------------------------------------------------------------------------------------- |
| **Privileged** | Indicates that the object is Privileged.                                              |
| **Tier**       | Indicates that the object tier according to risk score and importance.                |
| **Enabled**    | Indicates that the object is enabled.                                                 |
| **Disabled**   | Indicates that the object is disabled.                                                |
| **Stealth**    | Indicates that the object can compromise admin objects with at least one attack path. |

`Information Pane` contains `Details`, `Role Permissions`, `Groups`, `Service Principals`, `Devices`, `Users`.

## Details

Details tab contains attributes below about organizational unit.

| Attribute            | Description                                                                                                                                     |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| **Name**             | The unique name of the role within the tenant, used for identification and assignment.                                                          |
| **Enabled**          | Indicates whether the role is currently active and available for assignments within the tenant.                                                 |
| **Display Name**     | The human-readable name of the role, shown in the Azure portal when managing role assignments.                                                  |
| **Is Built In**      | Specifies whether the role is a built-in system role provided by Microsoft, as opposed to a custom-defined role.                                |
| **Description**      | A summary of the role’s purpose and permissions. This role allows management of Microsoft 365 Copilot and other AI-related enterprise features. |
| **Tenant ID**        | The unique identifier (GUID) of the Azure AD tenant where this role exists and can be assigned.                                                 |
| **Object ID**        | A globally unique identifier (GUID) for the specific instance of the role in this tenant, used internally for role assignments.                 |
| **Role Template ID** | The unique identifier of the role definition template. For built-in roles, this is the same across all tenants.                                 |

## Role Permissions

Role permissions tab contains a list of role permissions that are in the given role. This list also contains `Privileged` column to identify the privilege levels of these role permission.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-9abc534c15cb06c4ff2d71295041edd3dc08f50d%2Fazure-identities-roles-image-2.png?alt=media" alt=""><figcaption><p>Role permissions</p></figcaption></figure>

## Groups

Groups tab contains a list of groups that has the roles. This list also contains `Enabled` and `On Prem Sync Enabled` columns to identify the status of these groups.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-8627ae249c117a4e95d767421b640904f03d8860%2Fazure-identities-roles-image-3.png?alt=media" alt=""><figcaption><p>Groups</p></figcaption></figure>

## Service Principals

Service Principals tab contains a list of service principals that has the roles. This list also contains `Enabled`, `App Display Name` , `Service Principal Type` columns to identify the status of these service principals.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-2e08609d80dfb9771f8fed3b392da39ffb953f15%2Fazure-identities-roles-image-4.png?alt=media" alt=""><figcaption><p>Service Principals</p></figcaption></figure>

## Devices

Devices tab contains a list of devices that has the roles. This list also contains `Account Enabled` and `On Prem Sync Enabled` columns to identify the status of these devices.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-f3834c2cc1090bd980c0e79c27d047b968496bb9%2Fazure-identities-roles-image-5.png?alt=media" alt=""><figcaption><p>Devices</p></figcaption></figure>

## Users

Users tab contains a list of users that has the roles. This list also contains `Enabled` and `On Prem Sync Enabled` columns to identify the status of these users.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-10972683fe230c6276bd4220db2f84ae0fbb3157%2Fazure-identities-roles-image-6.png?alt=media" alt=""><figcaption><p>Users</p></figcaption></figure>
