You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+20-3Lines changed: 20 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -83,6 +83,7 @@ This article lists the Azure AD built-in roles you can assign to allow managemen
83
83
> |[Modern Commerce User](#modern-commerce-user)| Can manage commercial purchases for a company, department or team. | d24aef57-1500-4070-84db-2666f29cf966 |
84
84
> |[Network Administrator](#network-administrator)| Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications. | d37c8bed-0711-4417-ba38-b4abe66ce4c2 |
85
85
> |[Office Apps Administrator](#office-apps-administrator)| Can manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish 'what's new' feature content to end-user's devices. | 2b745bdf-0803-4d80-aa65-822c4493daac |
86
+
> |[Organizational Messages Writer](#organizational-messages-writer)| Write, publish, manage, and review the organizational messages for end-users through Microsoft product surfaces. | 507f53e4-4e52-4077-abd3-d2e1558b6ea2 |
86
87
> |[Partner Tier1 Support](#partner-tier1-support)| Do not use - not intended for general use. | 4ba39ca4-527c-499a-b93d-d9b492c50246 |
87
88
> |[Partner Tier2 Support](#partner-tier2-support)| Do not use - not intended for general use. | e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8 |
88
89
> |[Password Administrator](#password-administrator)| Can reset passwords for non-administrators and Password Administrators. | 966707d0-3269-4727-9be2-8c3a10f19b9d |
@@ -1056,7 +1057,7 @@ Users with this role have access to all administrative features in Azure Active
1056
1057
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
1057
1058
> | microsoft.office365.messageCenter/securityMessages/read | Read security messages in Message Center in the Microsoft 365 admin center |
1058
1059
> | microsoft.office365.network/performance/allProperties/read | Read all network performance properties in the Microsoft 365 admin center |
1059
-
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all aspects of Microsoft 365 organizational message center|
1060
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all authoring aspects of Microsoft 365 Organizational Messages|
1060
1061
> | microsoft.office365.protectionCenter/allEntities/allProperties/allTasks | Manage all aspects of the Security and Compliance centers |
1061
1062
> | microsoft.office365.search/content/manage | Create and delete content, and read and update all properties in Microsoft Search |
1062
1063
> | microsoft.office365.securityComplianceCenter/allEntities/allTasks | Create and delete all resources, and read and update standard properties in the Office 365 Security & Compliance Center |
@@ -1160,7 +1161,7 @@ Users with this role **cannot** do the following:
1160
1161
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
1161
1162
> | microsoft.office365.messageCenter/securityMessages/read | Read security messages in Message Center in the Microsoft 365 admin center |
1162
1163
> | microsoft.office365.network/performance/allProperties/read | Read all network performance properties in the Microsoft 365 admin center |
1163
-
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 organizational message center|
1164
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 Organizational Messages|
1164
1165
> | microsoft.office365.protectionCenter/allEntities/allProperties/read | Read all properties in the Security and Compliance centers |
1165
1166
> | microsoft.office365.securityComplianceCenter/allEntities/read | Read standard properties in Microsoft 365 Security and Compliance Center |
@@ -1419,7 +1420,7 @@ This role can create and manage all security groups. However, Intune Administrat
1419
1420
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
1420
1421
> | microsoft.cloudPC/allEntities/allProperties/allTasks | Manage all aspects of Windows 365 |
1421
1422
> | microsoft.intune/allEntities/allTasks | Manage all aspects of Microsoft Intune |
1422
-
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 organizational message center|
1423
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 Organizational Messages|
1423
1424
> | microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Microsoft 365 service requests |
1424
1425
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1425
1426
@@ -1578,6 +1579,22 @@ Users in this role can manage Microsoft 365 apps' cloud settings. This includes
1578
1579
> | microsoft.office365.userCommunication/allEntities/allTasks | Read and update what's new messages visibility |
1579
1580
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1580
1581
1582
+
## Organizational Messages Writer
1583
+
1584
+
Assign the Organizational Messages Writer role to users who need to do the following tasks:
1585
+
1586
+
- Write, publish, and delete organizational messages using Microsoft 365 admin center or Microsoft Endpoint Manager
1587
+
- Manage organizational message delivery options using Microsoft 365 admin center or Microsoft Endpoint Manager
1588
+
- Read organizational message delivery results using Microsoft 365 admin center or Microsoft Endpoint Manager
1589
+
- View usage reports and most settings in the Microsoft 365 admin center, but can't make changes
1590
+
1591
+
> [!div class="mx-tableFixed"]
1592
+
> | Actions | Description |
1593
+
> | --- | --- |
1594
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all authoring aspects of Microsoft 365 Organizational Messages |
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1597
+
1581
1598
## Partner Tier1 Support
1582
1599
1583
1600
Do not use. This role has been deprecated and will be removed from Azure AD in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
0 commit comments