Skip to content

Commit 04d9d63

Browse files
Update directory-assign-admin-roles.md
Added Compliance Data Administrator
1 parent 4f16433 commit 04d9d63

File tree

1 file changed

+25
-2
lines changed

1 file changed

+25
-2
lines changed

articles/active-directory/users-groups-roles/directory-assign-admin-roles.md

Lines changed: 25 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ The following administrator roles are available:
8686
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | View all Intune audit data
8787
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br> Can view all the built-in reports under Data Management
8888

89-
<!--* **[Compliance Data Administrator](#compliance-data-administrator)**: Users with this role have permissions to protect and track data in the Microsoft 365 compliance center, Microsoft 365 admin center, and Azure. Users can also manage all features within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365.
89+
* **[Compliance Data Administrator](#compliance-data-administrator)**: Users with this role have permissions to protect and track data in the Microsoft 365 compliance center, Microsoft 365 admin center, and Azure. Users can also manage all features within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365.
9090

9191
In | Can do
9292
----- | ----------
@@ -95,7 +95,7 @@ The following administrator roles are available:
9595
[Office 365 Security & Compliance Center](https://support.office.com/article/About-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d) | Manage data governance<br>Perform legal and data investigation<br>Manage Data Subject Request
9696
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | View all Intune audit data
9797
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br> Can view all the built-in reports under Data Management
98-
-->
98+
9999
* **[Conditional Access Administrator](#conditional-access-administrator)**: Users with this role have the ability to manage Azure Active Directory conditional access settings.
100100
> [!NOTE]
101101
> To deploy Exchange ActiveSync conditional access policy in Azure, the user must also be a Global Administrator.
@@ -538,6 +538,28 @@ Can read and manage compliance configuration and reports in Azure AD and Office
538538
| microsoft.office365.skypeForBusiness/allEntities/allTasks | Manage all aspects of Skype for Business Online. |
539539
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
540540

541+
### Compliance Data Administrator
542+
Creates and manages compliance content.
543+
544+
> [!NOTE]
545+
> This role has additional permissions outside of Azure Active Directory. For more information, see role description above.
546+
>
547+
>
548+
549+
| **Actions** | **Description** |
550+
| --- | --- |
551+
| microsoft.aad.cloudAppSecurity/allEntities/allTasks | Read and configure Microsoft Cloud App Security. |
552+
| microsoft.azure.informationProtection/allEntities/allTasks | Manage all aspects of Azure Information Protection. |
553+
| microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health. |
554+
| microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets. |
555+
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
556+
| microsoft.office365.complianceManager/allEntities/allTasks | Manage all aspects of Office 365 Compliance Manager |
557+
| microsoft.office365.exchange/allEntities/allTasks | Manage all aspects of Exchange Online. |
558+
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
559+
| microsoft.office365.sharepoint/allEntities/allTasks | Create and delete all resources, and read and update standard properties in microsoft.office365.sharepoint. |
560+
| microsoft.office365.skypeForBusiness/allEntities/allTasks | Manage all aspects of Skype for Business Online. |
561+
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
562+
541563
### Conditional Access Administrator
542564
Can manage conditional access capabilities.
543565

@@ -1187,6 +1209,7 @@ Cloud Application Administrator | Cloud application administrator | 158c047a-c90
11871209
Cloud Device Administrator | Cloud device administrator | 7698a772-787b-4ac8-901f-60d6b08affd2
11881210
Company Administrator | Global administrator | 62e90394-69f5-4237-9190-012177145e10
11891211
Compliance Administrator | Compliance administrator | 17315797-102d-40b4-93e0-432062caca18
1212+
Compliance Data Administrator | Compliance data administrator | e6d1a23a-da11-4be4-9570-befc86d067a7
11901213
Conditional Access Administrator | Conditional Access administrator | b1be1c3e-b65d-4f19-8427-f6fa0d97feb9
11911214
CRM Service Administrator | Dynamics 365 administrator | 44367163-eba1-44c3-98af-f5787879f96a
11921215
Customer LockBox Access Approver | Customer Lockbox access approver | 5c4f9dcd-47dc-4cf7-8c9a-9e4207cbfc91

0 commit comments

Comments
 (0)