You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+12-8Lines changed: 12 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.workload: identity
10
10
ms.subservice: roles
11
11
ms.topic: reference
12
-
ms.date: 09/26/2022
12
+
ms.date: 10/30/2022
13
13
ms.author: rolyon
14
14
ms.reviewer: abhijeetsinha
15
15
ms.custom: generated, it-pro, fasttrack-edit
@@ -86,7 +86,7 @@ This article lists the Azure AD built-in roles you can assign to allow managemen
86
86
> |[Partner Tier1 Support](#partner-tier1-support)| Do not use - not intended for general use. | 4ba39ca4-527c-499a-b93d-d9b492c50246 |
87
87
> |[Partner Tier2 Support](#partner-tier2-support)| Do not use - not intended for general use. | e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8 |
88
88
> |[Password Administrator](#password-administrator)| Can reset passwords for non-administrators and Password Administrators. | 966707d0-3269-4727-9be2-8c3a10f19b9d |
89
-
> [Permissions Management Administrator](#permissions-management-administrator) | Can manage all aspects of Permissions Management. | af78dc32-cf4d-46f9-ba4e-4428526346b5 |
89
+
> |[Permissions Management Administrator](#permissions-management-administrator)|Manage all aspects of Entra Permissions Management. | af78dc32-cf4d-46f9-ba4e-4428526346b5 |
90
90
> |[Power BI Administrator](#power-bi-administrator)| Can manage all aspects of the Power BI product. | a9ea8996-122f-4c74-9520-8edcd192826c |
91
91
> |[Power Platform Administrator](#power-platform-administrator)| Can create and manage all aspects of Microsoft Dynamics 365, Power Apps and Power Automate. | 11648597-926c-4cf3-9c36-bcebb0ba8dcc |
92
92
> |[Printer Administrator](#printer-administrator)| Can manage all aspects of printers and printer connectors. | 644ef478-e28f-4e28-b9dc-3fdde9aa0b1f |
@@ -1056,6 +1056,7 @@ Users with this role have access to all administrative features in Azure Active
1056
1056
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
1057
1057
> | microsoft.office365.messageCenter/securityMessages/read | Read security messages in Message Center in the Microsoft 365 admin center |
1058
1058
> | microsoft.office365.network/performance/allProperties/read | Read all network performance properties in the Microsoft 365 admin center |
1059
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all aspects of Microsoft 365 organizational message center |
1059
1060
> | microsoft.office365.protectionCenter/allEntities/allProperties/allTasks | Manage all aspects of the Security and Compliance centers |
1060
1061
> | microsoft.office365.search/content/manage | Create and delete content, and read and update all properties in Microsoft Search |
1061
1062
> | microsoft.office365.securityComplianceCenter/allEntities/allTasks | Create and delete all resources, and read and update standard properties in the Office 365 Security & Compliance Center |
@@ -1079,8 +1080,12 @@ Users with this role have access to all administrative features in Azure Active
1079
1080
1080
1081
Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Security center, Compliance center, Azure AD admin center, and Device Management admin center.
1081
1082
1083
+
Users with this role **cannot** do the following:
1084
+
1085
+
- Cannot access the Purchase Services area in the Microsoft 365 admin center.
1086
+
1082
1087
> [!NOTE]
1083
-
> Global Reader role has a few limitations right now -
1088
+
> Global Reader role has the following limitations:
1084
1089
>
1085
1090
>-[OneDrive admin center](https://admin.onedrive.com/) - OneDrive admin center does not support the Global Reader role
1086
1091
>-[Microsoft 365 admin center](https://admin.microsoft.com/Adminportal/Home#/homepage) - Global Reader can't read integrated apps. You won't find the **Integrated apps** tab under **Settings** in the left pane of Microsoft 365 admin center.
@@ -1091,9 +1096,6 @@ Users in this role can read settings and administrative information across Micro
1091
1096
> -[SharePoint](https://admin.microsoft.com/sharepoint) - Global Reader currently can't access SharePoint using PowerShell.
1092
1097
> -[Power Platform admin center](https://admin.powerplatform.microsoft.com) - Global Reader is not yet supported in the Power Platform admin center.
1093
1098
> - Microsoft Purview doesn't support the Global Reader role.
1094
-
>
1095
-
> These features are currently in development.
1096
-
>
1097
1099
1098
1100
> [!div class="mx-tableFixed"]
1099
1101
> | Actions | Description |
@@ -1155,10 +1157,10 @@ Users in this role can read settings and administrative information across Micro
1155
1157
> | microsoft.commerce.billing/allEntities/allProperties/read | Read all resources of Office 365 billing |
1156
1158
> | microsoft.edge/allEntities/allProperties/read | Read all aspects of Microsoft Edge |
1157
1159
> | microsoft.insights/allEntities/allProperties/read | Read all aspects of Viva Insights |
1158
-
> | microsoft.office365.exchange/allEntities/standard/read | Read all resources of Exchange Online |
1159
1160
> | microsoft.office365.messageCenter/messages/read | Read messages in Message Center in the Microsoft 365 admin center, excluding security messages |
1160
1161
> | microsoft.office365.messageCenter/securityMessages/read | Read security messages in Message Center in the Microsoft 365 admin center |
1161
1162
> | microsoft.office365.network/performance/allProperties/read | Read all network performance properties in the Microsoft 365 admin center |
1163
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 organizational message center |
1162
1164
> | microsoft.office365.protectionCenter/allEntities/allProperties/read | Read all properties in the Security and Compliance centers |
1163
1165
> | microsoft.office365.securityComplianceCenter/allEntities/read | Read standard properties in Microsoft 365 Security and Compliance Center |
@@ -1417,6 +1419,7 @@ This role can create and manage all security groups. However, Intune Administrat
1417
1419
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
1418
1420
> | microsoft.cloudPC/allEntities/allProperties/allTasks | Manage all aspects of Windows 365 |
1419
1421
> | microsoft.intune/allEntities/allTasks | Manage all aspects of Microsoft Intune |
1422
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/read | Read all aspects of Microsoft 365 organizational message center |
1420
1423
> | microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Microsoft 365 service requests |
1421
1424
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1422
1425
@@ -2063,6 +2066,7 @@ Users with this role have global permissions within Microsoft SharePoint Online,
2063
2066
> [!div class="mx-tableFixed"]
2064
2067
> | Actions | Description |
2065
2068
> | --- | --- |
2069
+
> | microsoft.directory/groups/hiddenMembers/read | Read hidden members of Security groups and Microsoft 365 groups, including role-assignable groups |
2066
2070
> | microsoft.directory/groups.unified/create | Create Microsoft 365 groups, excluding role-assignable groups |
2067
2071
> | microsoft.directory/groups.unified/delete | Delete Microsoft 365 groups, excluding role-assignable groups |
2068
2072
> | microsoft.directory/groups.unified/restore | Restore Microsoft 365 groups from soft-deleted container, excluding role-assignable groups |
@@ -2206,7 +2210,7 @@ Users with this role can access tenant level aggregated data and associated insi
2206
2210
2207
2211
## User Administrator
2208
2212
2209
-
Assign the User Administrator role to users who need to do the following:
2213
+
Assign the User Administrator role to users who need to do the following:
0 commit comments