Skip to content

Commit 53127d6

Browse files
authored
Merge pull request #74047 from abhijeetsinha/patch-8
Update directory-assign-admin-roles.md
2 parents 63f1a9f + 3fe7f6e commit 53127d6

File tree

1 file changed

+23
-2
lines changed

1 file changed

+23
-2
lines changed

articles/active-directory/users-groups-roles/directory-assign-admin-roles.md

Lines changed: 23 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -208,7 +208,7 @@ Additionally, the user can access reports related to adoption & usage of Kaizala
208208
[Azure Security Center](https://docs.microsoft.com/azure/role-based-access-control/built-in-roles) | Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations
209209
[Office 365 service health](https://docs.microsoft.com/office365/enterprise/view-service-health) | View the health of Office 365 services
210210

211-
<!--* **[Security operator](#security-operator)**: Users with this role can manage alerts and have global read-only access on security-related feature, including all information in Microsoft 365 security center, Azure Active Directory, Identity Protection, Privileged Identity Management, as well as the ability to read Azure Active Directory sign-in reports and audit logs, and in Office 365 Security & Compliance Center.
211+
* **[Security operator](#security-operator)**: Users with this role can manage alerts and have global read-only access on security-related feature, including all information in Microsoft 365 security center, Azure Active Directory, Identity Protection, Privileged Identity Management and Office 365 Security & Compliance Center. More information about Office 365 permissions is available at [Permissions in the Office 365 Security & Compliance Center](https://docs.microsoft.com/en-us/office365/securitycompliance/permissions-in-the-security-and-compliance-center).
212212

213213
In | Can do
214214
--- | ---
@@ -220,7 +220,8 @@ Additionally, the user can access reports related to adoption & usage of Kaizala
220220
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | All permissions of the Security Reader role
221221
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | All permissions of the Security Reader role
222222
[Office 365 service health](https://docs.microsoft.com/office365/enterprise/view-service-health) | View the health of Office 365 services
223-
-->
223+
<!--* **[Security Operator](#security-operator)**: Users with this role can manage alerts and have global read-only access on security-related feature, including all information in Microsoft 365 security center, Azure Active Directory, Identity Protection, Privileged Identity Management.-->
224+
224225
* **[Security Reader](#security-reader)**: Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 security center, Azure Active Directory, Identity Protection, Privileged Identity Management, as well as the ability to read Azure Active Directory sign-in reports and audit logs, and in Office 365 Security & Compliance Center. More information about Office 365 permissions is available at [Permissions in the Office 365 Security & Compliance Center](https://support.office.com/article/Permissions-in-the-Office-365-Security-Compliance-Center-d10608af-7934-490a-818e-e68f17d0e9c1).
225226

226227
In | Can do
@@ -1079,6 +1080,25 @@ Can read security information and reports, and manage configuration in Azure AD
10791080
| microsoft.office365.protectionCenter/allEntities/update | Update all resources in microsoft.office365.protectionCenter. |
10801081
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
10811082

1083+
### Security Operator
1084+
Creates and manages security events.
1085+
1086+
> [!NOTE]
1087+
> This role has additonal permissions outside of Azure Active Directory. For more information, see role description above.
1088+
>
1089+
>
1090+
1091+
| **Actions** | **Description** |
1092+
| --- | --- |
1093+
| microsoft.aad.cloudAppSecurity/allEntities/allTasks | Read and configure Microsoft Cloud App Security. |
1094+
| microsoft.aad.identityProtection/allEntities/read | Read all resources in microsoft.aad.identityProtection. |
1095+
| microsoft.aad.privilegedIdentityManagement/allEntities/read | Read all resources in microsoft.aad.privilegedIdentityManagement. |
1096+
| microsoft.azure.advancedThreatProtection/allEntities/read | Read and configure Azure AD Advanced Threat Protection. |
1097+
| microsoft.intune/allEntities/allTasks | Manage all aspects of Intune. |
1098+
| microsoft.office365.securityComplianceCenter/allEntities/allTasks | Read and configure Security & Compliance Center. |
1099+
| microsoft.office365.usageReports/allEntities/read | Read Office 365 usage reports. |
1100+
| microsoft.windows.defenderAdvancedThreatProtection/allEntities/read | Read and configure Windows Defender Advanced Threat Protection. |
1101+
10821102
### Security Reader
10831103
Can read security information and reports in Azure AD and Office 365.
10841104

@@ -1293,6 +1313,7 @@ Reports Reader | Reports reader | 4a5d8f65-41da-4de4-8968-e035b65339cf
12931313
Search Administrator | Search administrator | 0964bb5e-9bdb-4d7b-ac29-58e794862a40
12941314
Search Editor | Search editor | 8835291a-918c-4fd7-a9ce-faa49f0cf7d9
12951315
Security Administrator | Security administrator | 194ae4cb-b126-40b2-bd5b-6091b380977d
1316+
Security Operator | Security operator | 5f2222b1-57c3-48ba-8ad5-d4759f1fde6f
12961317
Security Reader | Security reader | 5d6b6bb7-de71-4623-b4af-96380a352509
12971318
Service Support Administrator | Service administrator | f023fd81-a637-4b56-95fd-791ac0226033
12981319
SharePoint Service Administrator | Sharepoint administrator | f28a1f50-f6e7-4571-818b-6a12f2af6b6c

0 commit comments

Comments
 (0)