By default, Global Administrator and other administrator roles do not have permissions to read, define, or assign custom security attributes.
Attribute Assignment Administrator role - Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
Attributes can be assigned to the following entities:
Users: Attributes like name, email, job title, department, location, etc.
Groups: Attributes like description, membership rules, expiration policies.
Applications: Attributes like display name, description, sign-in
URL, etc.
Devices: Attributes like device type, operating system, serial number, etc.
Service Principals: Attributes like display name, description, application ID, etc.