Skip to content

Commit 02d2146

Browse files
authored
Merge pull request #109792 from curtand/shaun0331
[Azure AD PIM] Restating support for EXCH and SHPT roles
2 parents f6183aa + 2366a12 commit 02d2146

File tree

1 file changed

+4
-4
lines changed
  • articles/active-directory/privileged-identity-management

1 file changed

+4
-4
lines changed

articles/active-directory/privileged-identity-management/pim-roles.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -11,15 +11,15 @@ ms.service: active-directory
1111
ms.topic: conceptual
1212
ms.workload: identity
1313
ms.subservice: pim
14-
ms.date: 10/23/2019
14+
ms.date: 03/31/2020
1515
ms.author: curtand
1616
ms.custom: pim ; H1Hack27Feb2017;oldportal;it-pro;
1717
ms.collection: M365-identity-device-management
1818
---
1919

2020
# Roles you can't manage in Privileged Identity Management
2121

22-
Azure Active Directory (Azure AD) Privileged Identity Management (PIM) enables you to manage all [Azure AD roles](../users-groups-roles/directory-assign-admin-roles.md) and all [Azure resource roles](../../role-based-access-control/built-in-roles.md). These roles also include your custom roles attached to your management groups, subscriptions, resource groups, and resources. However, there are few roles that you cannot manage. This article describes the roles you cannot manage in Privileged Identity Management.
22+
Azure Active Directory (Azure AD) Privileged Identity Management (PIM) enables you to manage all [Azure AD roles](../users-groups-roles/directory-assign-admin-roles.md) and all [Azure roles](../../role-based-access-control/built-in-roles.md). Azure roles can also include your custom roles attached to your management groups, subscriptions, resource groups, and resources. However, there are few roles that you cannot manage. This article describes the roles you can't manage in Privileged Identity Management.
2323

2424
## Classic subscription administrator roles
2525

@@ -33,10 +33,10 @@ For more information about the classic subscription administrator roles, see [Cl
3333

3434
## What about Office 365 admin roles?
3535

36-
Roles within Exchange Online or SharePoint Online, except for Exchange Administrator and SharePoint Administrator, are not represented in Azure AD and so cannot be managed in Privileged Identity Management. For more information about these Office 365 services, see [Office 365 admin roles](https://docs.microsoft.com/office365/admin/add-users/about-admin-roles).
36+
We support all Office365 roles in the Azure AD Roles and Administrators portal experience, such as Exchange Administrator and SharePoint Administrator, but we don't support specific roles within Exchange RBAC or SharePoint RBAC. For more information about these Office 365 services, see [Office 365 admin roles](https://docs.microsoft.com/office365/admin/add-users/about-admin-roles).
3737

3838
> [!NOTE]
39-
> SharePoint Administrator has administrative access to SharePoint Online through the SharePoint Online admin center, and can perform almost any task in SharePoint Online. Eligible users may experience delays using this role within SharePoint after activating in Privileged Identity Management.
39+
> Eligible users for SharePoint Administrator role as well as any roles trying to access the Microsoft Security and Compliance Center might experience delays of up to a few hours after activating their role. We are working with those teams to fix the issues.
4040
4141
## Next steps
4242

0 commit comments

Comments
 (0)