You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/users-groups-roles/directory-assign-admin-roles.md
+24Lines changed: 24 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -257,6 +257,10 @@ Users in this role can monitor all notifications in the Message Center, includin
257
257
258
258
Users in this role can monitor notifications and advisory health updates in [Office 365 Message center](https://support.office.com/article/Message-center-in-Office-365-38FB3333-BFCC-4340-A37B-DEDA509C2093) for their organization on configured services such as Exchange, Intune, and Microsoft Teams. Message Center Readers receive weekly email digests of posts, updates, and can share message center posts in Office 365. In Azure AD, users assigned to this role will only have read-only access on Azure AD services such as users and groups. This role has no access to view, create, or manage support tickets.
Users in this role can manage Office 365 apps' cloud settings. This includes managing cloud policies, self-service download management and the ability to view Office apps related report. This role additionally grants the ability to manage support tickets, and monitor service health within the main admin center. Users assigned to this role can also manage communication of new features in Office apps.
Do not use. This role has been deprecated and will be removed from Azure AD in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
@@ -1102,6 +1106,25 @@ Can read messages and updates for their organization in Office 365 Message Cente
1102
1106
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
1103
1107
| microsoft.office365.messageCenter/messages/read | Read messages in microsoft.office365.messageCenter. |
1104
1108
1109
+
### Office Apps Administrator permissions
1110
+
Can manage Office apps' cloud services, including policy and settings management, and manage the ability to select, unselect and publish "what's new" feature content to end-user’s devices.
1111
+
1112
+
> [!NOTE]
1113
+
> This role has additional permissions outside of Azure Active Directory. For more information, see role description above.
1114
+
>
1115
+
>
1116
+
1117
+
|**Actions**|**Description**|
1118
+
| --- | --- |
1119
+
| microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health. |
1120
+
| microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets. |
1121
+
| microsoft.office365.messageCenter/messages/read | Read messages in microsoft.office365.messageCenter. |
1122
+
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
1123
+
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
0 commit comments