Read User Roles

Get roles that are assigned to a user in Office 365.

The Read User Roles action card only reads roles that are activated in an Office 365 tenant.

Also, the card only reads default system roles. It doesn't read custom roles.


Field Definition Type Required


ID or Username

User ID or username of the Office 365 user. This is the user's User Principal Name (UPN). A UPN is formed by taking the username and domain and combining them with the @ separator.

For example, This could be the user's email address, but not always.



If the string for the UPN input begins with the $ character, remove the slash / after /users and enclose the UPN value in parentheses and single quotes. For example, /users('$'). See Known issues with Microsoft Graph.

To search for a B2B user using a UPN input value, encode the hash # character as %23. For example, /users/


Field Definition Type


The unique identifier for the user.


Display Name

Display name for the directory role.



Description for the directory role.


Role Template ID

ID of the directoryRoleTemplate on which this role is based.

The property must be specified when activating a directory role in a tenant with a POST operation. After the directory role has been activated, the property is read only.


For example:

"": "",
"id": "06265c7a-1373-4033-8d26-3a9a04226e15",
"deletedDateTime": null,
"description": "Can reset passwords for non-administrators and Helpdesk Administrators.",
"displayName": "Helpdesk Administrator",
"roleTemplateId": "729827e3-9c14-49f7-bb1b-9608f156bbb8"

Related topics

Azure Active Directory connector

Workflow elements

Guidance for Azure Active Directory connector

Azure Active Directory Management API overview