Skip to content

Commit 57b26ba

Browse files
Merge pull request #216463 from rolyon/rolyon-aadroles-roles-oct
[Azure AD roles] Updates to roles and permissions for October
2 parents 5281086 + 14c30a7 commit 57b26ba

File tree

1 file changed

+12
-8
lines changed

1 file changed

+12
-8
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.workload: identity
1010
ms.subservice: roles
1111
ms.topic: reference
12-
ms.date: 09/26/2022
12+
ms.date: 10/30/2022
1313
ms.author: rolyon
1414
ms.reviewer: abhijeetsinha
1515
ms.custom: generated, it-pro, fasttrack-edit
@@ -86,7 +86,7 @@ This article lists the Azure AD built-in roles you can assign to allow managemen
8686
> | [Partner Tier1 Support](#partner-tier1-support) | Do not use - not intended for general use. | 4ba39ca4-527c-499a-b93d-d9b492c50246 |
8787
> | [Partner Tier2 Support](#partner-tier2-support) | Do not use - not intended for general use. | e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8 |
8888
> | [Password Administrator](#password-administrator) | Can reset passwords for non-administrators and Password Administrators. | 966707d0-3269-4727-9be2-8c3a10f19b9d |
89-
> [Permissions Management Administrator](#permissions-management-administrator) | Can manage all aspects of Permissions Management. | af78dc32-cf4d-46f9-ba4e-4428526346b5 |
89+
> | [Permissions Management Administrator](#permissions-management-administrator) | Manage all aspects of Entra Permissions Management. | af78dc32-cf4d-46f9-ba4e-4428526346b5 |
9090
> | [Power BI Administrator](#power-bi-administrator) | Can manage all aspects of the Power BI product. | a9ea8996-122f-4c74-9520-8edcd192826c |
9191
> | [Power Platform Administrator](#power-platform-administrator) | Can create and manage all aspects of Microsoft Dynamics 365, Power Apps and Power Automate. | 11648597-926c-4cf3-9c36-bcebb0ba8dcc |
9292
> | [Printer Administrator](#printer-administrator) | Can manage all aspects of printers and printer connectors. | 644ef478-e28f-4e28-b9dc-3fdde9aa0b1f |
@@ -1056,6 +1056,7 @@ Users with this role have access to all administrative features in Azure Active
10561056
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
10571057
> | microsoft.office365.messageCenter/securityMessages/read | Read security messages in Message Center in the Microsoft 365 admin center |
10581058
> | microsoft.office365.network/performance/allProperties/read | Read all network performance properties in the Microsoft 365 admin center |
1059+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all aspects of Microsoft 365 organizational message center |
10591060
> | microsoft.office365.protectionCenter/allEntities/allProperties/allTasks | Manage all aspects of the Security and Compliance centers |
10601061
> | microsoft.office365.search/content/manage | Create and delete content, and read and update all properties in Microsoft Search |
10611062
> | microsoft.office365.securityComplianceCenter/allEntities/allTasks | Create and delete all resources, and read and update standard properties in the Office 365 Security & Compliance Center |
@@ -1079,8 +1080,12 @@ Users with this role have access to all administrative features in Azure Active
10791080

10801081
Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Security center, Compliance center, Azure AD admin center, and Device Management admin center.
10811082

1083+
Users with this role **cannot** do the following:
1084+
1085+
- Cannot access the Purchase Services area in the Microsoft 365 admin center.
1086+
10821087
> [!NOTE]
1083-
> Global Reader role has a few limitations right now -
1088+
> Global Reader role has the following limitations:
10841089
>
10851090
>- [OneDrive admin center](https://admin.onedrive.com/) - OneDrive admin center does not support the Global Reader role
10861091
>- [Microsoft 365 admin center](https://admin.microsoft.com/Adminportal/Home#/homepage) - Global Reader can't read integrated apps. You won't find the **Integrated apps** tab under **Settings** in the left pane of Microsoft 365 admin center.
@@ -1091,9 +1096,6 @@ Users in this role can read settings and administrative information across Micro
10911096
> - [SharePoint](https://admin.microsoft.com/sharepoint) - Global Reader currently can't access SharePoint using PowerShell.
10921097
> - [Power Platform admin center](https://admin.powerplatform.microsoft.com) - Global Reader is not yet supported in the Power Platform admin center.
10931098
> - Microsoft Purview doesn't support the Global Reader role.
1094-
>
1095-
> These features are currently in development.
1096-
>
10971099
10981100
> [!div class="mx-tableFixed"]
10991101
> | Actions | Description |
@@ -1155,10 +1157,10 @@ Users in this role can read settings and administrative information across Micro
11551157
> | microsoft.commerce.billing/allEntities/allProperties/read | Read all resources of Office 365 billing |
11561158
> | microsoft.edge/allEntities/allProperties/read | Read all aspects of Microsoft Edge |
11571159
> | microsoft.insights/allEntities/allProperties/read | Read all aspects of Viva Insights |
1158-
> | microsoft.office365.exchange/allEntities/standard/read | Read all resources of Exchange Online |
11591160
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
11601161
> | microsoft.office365.messageCenter/securityMessages/read | Read security messages in Message Center in the Microsoft 365 admin center |
11611162
> | microsoft.office365.network/performance/allProperties/read | Read all network performance properties in the Microsoft 365 admin center |
1163+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 organizational message center |
11621164
> | microsoft.office365.protectionCenter/allEntities/allProperties/read | Read all properties in the Security and Compliance centers |
11631165
> | microsoft.office365.securityComplianceCenter/allEntities/read | Read standard properties in Microsoft 365 Security and Compliance Center |
11641166
> | microsoft.office365.usageReports/allEntities/allProperties/read | Read Office 365 usage reports |
@@ -1417,6 +1419,7 @@ This role can create and manage all security groups. However, Intune Administrat
14171419
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
14181420
> | microsoft.cloudPC/allEntities/allProperties/allTasks | Manage all aspects of Windows 365 |
14191421
> | microsoft.intune/allEntities/allTasks | Manage all aspects of Microsoft Intune |
1422+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 organizational message center |
14201423
> | microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Microsoft 365 service requests |
14211424
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
14221425
@@ -2063,6 +2066,7 @@ Users with this role have global permissions within Microsoft SharePoint Online,
20632066
> [!div class="mx-tableFixed"]
20642067
> | Actions | Description |
20652068
> | --- | --- |
2069+
> | microsoft.directory/groups/hiddenMembers/read | Read hidden members of Security groups and Microsoft 365 groups, including role-assignable groups |
20662070
> | microsoft.directory/groups.unified/create | Create Microsoft 365 groups, excluding role-assignable groups |
20672071
> | microsoft.directory/groups.unified/delete | Delete Microsoft 365 groups, excluding role-assignable groups |
20682072
> | microsoft.directory/groups.unified/restore | Restore Microsoft 365 groups from soft-deleted container, excluding role-assignable groups |
@@ -2206,7 +2210,7 @@ Users with this role can access tenant level aggregated data and associated insi
22062210
22072211
## User Administrator
22082212

2209-
Assign the User Administrator role to users who need to do the following:
2213+
Assign the User Administrator role to users who need to do the following:
22102214

22112215
| Permission | More information |
22122216
| --- | --- |

0 commit comments

Comments
 (0)