> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports/azure-entities/entra-id/role.md).

# Role

The **Role** entity represents an Azure Active Directory (Entra ID) directory role.

| Field                  | Type    | Possible Operators                                                 | Description                                        |
| ---------------------- | ------- | ------------------------------------------------------------------ | -------------------------------------------------- |
| Guid                   | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Unique identifier for the entity in Forestall      |
| ObjectID               | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Object ID of the role                     |
| FSName                 | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name used in Forestall                     |
| Description            | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Description of the role                            |
| DisplayName            | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name of the role in Azure AD               |
| Enabled                | BOOLEAN | True / False                                                       | Whether the role is enabled                        |
| IsAZPrivileged         | BOOLEAN | True / False                                                       | Whether the role grants privileged access in Azure |
| IsStealth              | BOOLEAN | True / False                                                       | Whether the role is a stealth (shadow) admin role  |
| IsAdmin                | BOOLEAN | True / False                                                       | Whether the role grants admin privileges           |
| IsBuiltIn              | BOOLEAN | True / False                                                       | Whether the role is a built-in Azure AD role       |
| RoleTemplateID         | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Template ID of the directory role                  |
| TenantID               | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Tenant ID the role belongs to             |
| RolePermissionsAllowed | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Permissions allowed by the role                    |
| AZTier                 | NUMBER  | Equal, Between, Smaller, Larger, Smaller or Equal, Larger or Equal | Azure tier classification assigned by Forestall    |
