You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/users-groups-roles/directory-assign-admin-roles.md
+25-2Lines changed: 25 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -88,7 +88,7 @@ The following administrator roles are available:
88
88
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | View all Intune audit data
89
89
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br> Can view all the built-in reports under Data Management
90
90
91
-
<!--* **[Compliance Data Administrator](#compliance-data-administrator)**: Users with this role have permissions to protect and track data in the Microsoft 365 compliance center, Microsoft 365 admin center, and Azure. Users can also manage all features within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365.
91
+
***[Compliance Data Administrator](#compliance-data-administrator)**: Users with this role have permissions to protect and track data in the Microsoft 365 compliance center, Microsoft 365 admin center, and Azure. Users can also manage all features within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365.
92
92
93
93
In | Can do
94
94
----- | ----------
@@ -97,7 +97,7 @@ The following administrator roles are available:
97
97
[Office 365 Security & Compliance Center](https://support.office.com/article/About-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d) | Manage data governance<br>Perform legal and data investigation<br>Manage Data Subject Request
98
98
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | View all Intune audit data
99
99
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br> Can view all the built-in reports under Data Management
100
-
-->
100
+
101
101
***[Conditional Access Administrator](#conditional-access-administrator)**: Users with this role have the ability to manage Azure Active Directory conditional access settings.
102
102
> [!NOTE]
103
103
> To deploy Exchange ActiveSync conditional access policy in Azure, the user must also be a Global Administrator.
@@ -564,6 +564,28 @@ Can read and manage compliance configuration and reports in Azure AD and Office
564
564
| microsoft.office365.skypeForBusiness/allEntities/allTasks | Manage all aspects of Skype for Business Online. |
565
565
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
566
566
567
+
### Compliance Data Administrator
568
+
Creates and manages compliance content.
569
+
570
+
> [!NOTE]
571
+
> This role has additional permissions outside of Azure Active Directory. For more information, see role description above.
572
+
>
573
+
>
574
+
575
+
|**Actions**|**Description**|
576
+
| --- | --- |
577
+
| microsoft.aad.cloudAppSecurity/allEntities/allTasks | Read and configure Microsoft Cloud App Security. |
578
+
| microsoft.azure.informationProtection/allEntities/allTasks | Manage all aspects of Azure Information Protection. |
579
+
| microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health. |
580
+
| microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets. |
581
+
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
582
+
| microsoft.office365.complianceManager/allEntities/allTasks | Manage all aspects of Office 365 Compliance Manager |
583
+
| microsoft.office365.exchange/allEntities/allTasks | Manage all aspects of Exchange Online. |
584
+
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
585
+
| microsoft.office365.sharepoint/allEntities/allTasks | Create and delete all resources, and read and update standard properties in microsoft.office365.sharepoint. |
586
+
| microsoft.office365.skypeForBusiness/allEntities/allTasks | Manage all aspects of Skype for Business Online. |
587
+
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
0 commit comments