Skip to content

Commit 6a8b0ba

Browse files
authored
Merge pull request #77325 from abhijeetsinha/patch-14
Update directory-assign-admin-roles.md
2 parents 53127d6 + 04d9d63 commit 6a8b0ba

File tree

1 file changed

+25
-2
lines changed

1 file changed

+25
-2
lines changed

articles/active-directory/users-groups-roles/directory-assign-admin-roles.md

Lines changed: 25 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ The following administrator roles are available:
8888
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | View all Intune audit data
8989
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br> Can view all the built-in reports under Data Management
9090

91-
<!--* **[Compliance Data Administrator](#compliance-data-administrator)**: Users with this role have permissions to protect and track data in the Microsoft 365 compliance center, Microsoft 365 admin center, and Azure. Users can also manage all features within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365.
91+
* **[Compliance Data Administrator](#compliance-data-administrator)**: Users with this role have permissions to protect and track data in the Microsoft 365 compliance center, Microsoft 365 admin center, and Azure. Users can also manage all features within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365.
9292

9393
In | Can do
9494
----- | ----------
@@ -97,7 +97,7 @@ The following administrator roles are available:
9797
[Office 365 Security & Compliance Center](https://support.office.com/article/About-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d) | Manage data governance<br>Perform legal and data investigation<br>Manage Data Subject Request
9898
[Intune](https://docs.microsoft.com/intune/role-based-access-control) | View all Intune audit data
9999
[Cloud App Security](https://docs.microsoft.com/cloud-app-security/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br> Can view all the built-in reports under Data Management
100-
-->
100+
101101
* **[Conditional Access Administrator](#conditional-access-administrator)**: Users with this role have the ability to manage Azure Active Directory conditional access settings.
102102
> [!NOTE]
103103
> To deploy Exchange ActiveSync conditional access policy in Azure, the user must also be a Global Administrator.
@@ -564,6 +564,28 @@ Can read and manage compliance configuration and reports in Azure AD and Office
564564
| microsoft.office365.skypeForBusiness/allEntities/allTasks | Manage all aspects of Skype for Business Online. |
565565
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
566566

567+
### Compliance Data Administrator
568+
Creates and manages compliance content.
569+
570+
> [!NOTE]
571+
> This role has additional permissions outside of Azure Active Directory. For more information, see role description above.
572+
>
573+
>
574+
575+
| **Actions** | **Description** |
576+
| --- | --- |
577+
| microsoft.aad.cloudAppSecurity/allEntities/allTasks | Read and configure Microsoft Cloud App Security. |
578+
| microsoft.azure.informationProtection/allEntities/allTasks | Manage all aspects of Azure Information Protection. |
579+
| microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health. |
580+
| microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets. |
581+
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
582+
| microsoft.office365.complianceManager/allEntities/allTasks | Manage all aspects of Office 365 Compliance Manager |
583+
| microsoft.office365.exchange/allEntities/allTasks | Manage all aspects of Exchange Online. |
584+
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
585+
| microsoft.office365.sharepoint/allEntities/allTasks | Create and delete all resources, and read and update standard properties in microsoft.office365.sharepoint. |
586+
| microsoft.office365.skypeForBusiness/allEntities/allTasks | Manage all aspects of Skype for Business Online. |
587+
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
588+
567589
### Conditional Access Administrator
568590
Can manage conditional access capabilities.
569591

@@ -1284,6 +1306,7 @@ Cloud Application Administrator | Cloud application administrator | 158c047a-c90
12841306
Cloud Device Administrator | Cloud device administrator | 7698a772-787b-4ac8-901f-60d6b08affd2
12851307
Company Administrator | Global administrator | 62e90394-69f5-4237-9190-012177145e10
12861308
Compliance Administrator | Compliance administrator | 17315797-102d-40b4-93e0-432062caca18
1309+
Compliance Data Administrator | Compliance data administrator | e6d1a23a-da11-4be4-9570-befc86d067a7
12871310
Conditional Access Administrator | Conditional Access administrator | b1be1c3e-b65d-4f19-8427-f6fa0d97feb9
12881311
CRM Service Administrator | Dynamics 365 administrator | 44367163-eba1-44c3-98af-f5787879f96a
12891312
Customer LockBox Access Approver | Customer Lockbox access approver | 5c4f9dcd-47dc-4cf7-8c9a-9e4207cbfc91

0 commit comments

Comments
 (0)