Skip to content

Commit 168528b

Browse files
authored
Merge pull request #100023 from curtand/task0102
[Azure AD roles] update for global reader
2 parents 8a48c1e + f47c0ea commit 168528b

File tree

1 file changed

+9
-10
lines changed

1 file changed

+9
-10
lines changed

articles/active-directory/users-groups-roles/roles-delegate-by-task.md

Lines changed: 9 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -50,11 +50,11 @@ Create, read, update, and delete sign-in user flows | Global Administrator |
5050
Create, read, update, and delete sign-up user flow |Global Administrator |
5151
Create, read, update, and delete user attributes | Global Administrator |
5252
Create, read, update, and delete users | Global Administrator ([see documentation](https://docs.microsoft.com/azure/active-directory-b2c/active-directory-b2c-faqs))
53-
Read all configuration | Global Administrator |
54-
Read B2C audit logs | Global Administrator ([see documentation](https://docs.microsoft.com/azure/active-directory-b2c/active-directory-b2c-faqs)) |
53+
Read all configuration | Global reader |
54+
Read B2C audit logs | Global reader ([see documentation](https://docs.microsoft.com/azure/active-directory-b2c/active-directory-b2c-faqs)) |
5555

5656
> [!NOTE]
57-
> Azure AD B2C global administrators do not have the same permissions as Azure AD global administrators. If you have Azure AD B2C global administrator privileges, make sure that you are in an Azure AD B2C directory and not an Azure AD directory.
57+
> Azure AD B2C Global readers do not have the same permissions as Azure AD global administrators. If you have Azure AD B2C global administrator privileges, make sure that you are in an Azure AD B2C directory and not an Azure AD directory.
5858
5959
## Company branding
6060

@@ -74,7 +74,7 @@ Configure company properties | Global Administrator |
7474
Task | Least privileged role | Additional roles
7575
---- | --------------------- | ----------------
7676
Passthrough authentication | Global Administrator |
77-
Read all configuration | Global Administrator |
77+
Read all configuration | Global reader |
7878
Seamless single sign-on | Global Administrator |
7979

8080
## Connect Health
@@ -94,7 +94,6 @@ View metrics and alerts | Reader ([see documentation](https://docs.microsoft.com
9494
View metrics and alerts | Reader ([see documentation](https://docs.microsoft.com/azure/active-directory/fundamentals/users-default-permissions?context=azure/active-directory/users-groups-roles/context/ugr-context)) | Contributor, Owner
9595
View sync service metrics and alerts | Reader ([see documentation](https://docs.microsoft.com/azure/active-directory/fundamentals/users-default-permissions?context=azure/active-directory/users-groups-roles/context/ugr-context)) | Contributor, Owner
9696

97-
9897
## Custom domain names
9998

10099
Task | Least privileged role | Additional roles
@@ -224,9 +223,9 @@ Configure one-time bypass | Global Administrator |
224223
Configure phone call settings | Global Administrator |
225224
Configure providers | Global Administrator |
226225
Configure server settings | Global Administrator |
227-
Read activity report | Global Administrator |
228-
Read all configuration | Global Administrator |
229-
Read server status | Global Administrator |
226+
Read activity report | Global reader |
227+
Read all configuration | Global reader |
228+
Read server status | Global reader |
230229

231230
## Organizational relationships
232231

@@ -235,7 +234,7 @@ Task | Least privileged role | Additional roles
235234
Manage identity providers | Global Administrator |
236235
Manage settings | Global Administrator |
237236
Manage terms of use | Global Administrator |
238-
Read all configuration | Global Administrator |
237+
Read all configuration | Global reader |
239238

240239
## Password reset
241240

@@ -271,7 +270,7 @@ Read all configuration | Default user role ([see documentation](https://docs.mic
271270
Task | Least privileged role | Additional roles
272271
---- | --------------------- | ----------------
273272
Configure authentication methods | Global Administrator |
274-
Read all configuration | Global Administrator |
273+
Read all configuration | Global reader |
275274

276275
## Security - Conditional Access
277276

0 commit comments

Comments
 (0)