You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/permissions-management-quickstart-guide.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,7 +40,7 @@ If the above points are met, continue with:
40
40
41
41
1.[Enable Microsoft Entra Permissions Management in your organization](onboard-enable-tenant.md)
42
42
43
-
Ensure you are a *Global Administrator* or *Permissions Management Administrator*. Learn more about [Permissions Management roles and permissions](product-roles-permissions.md).
43
+
Ensure you're a *Global Administrator* or *Permissions Management Administrator*. Learn more about [Permissions Management roles and permissions](product-roles-permissions.md).
44
44
45
45
46
46
## Step 2: Onboard your multicloud environment
@@ -62,7 +62,7 @@ The controller gives you the choice to determine the level of access you grant t
62
62
63
63
> [!NOTE]
64
64
> If you don't enable the controller during onboarding, you have the option to enable it after onboarding is complete. To set the controller in Permissions Management after onboarding, see [Enable or disable the controller after onboarding](onboard-enable-controller-after-onboarding.md).
65
-
> For AWS environments, once you've enabled the controller, you *cannot* disable it.
65
+
> For AWS environments, once you have enabled the controller, you *cannot* disable it.
66
66
67
67
To set the controller settings during onboarding:
68
68
1. Select **Enable** to give read and write access to Permissions Management.
@@ -90,7 +90,7 @@ To configure data collection:
90
90
3. Click **Create configuration**.
91
91
92
92
### Onboard Amazon Web Services (AWS)
93
-
Since Permissions Management is hosted on Microsoft Entra, there are additional steps to take to onboard your AWS environment.
93
+
Since Permissions Management is hosted on Microsoft Entra, there are more steps to take to onboard your AWS environment.
94
94
95
95
To connect AWS to Permissions Management, you must create an Entra ID application in the Entra admin center tenant where Permissions Management is enabled. This Entra ID application is used to set up an OIDC connection to your AWS environment.
96
96
@@ -104,11 +104,11 @@ Account IDs and roles for:
104
104
- AWS OIDC account: An AWS member account designated by you to create and host the OIDC connection through an OIDC IdP
105
105
- AWS Logging account (optional but recommended)
106
106
- AWS Management account (optional but recommended)
107
-
- AWS member accounts to be monitored and managed by Permissions Management (for manual mode)
107
+
- AWS member accounts monitored and managed by Permissions Management (for manual mode)
108
108
109
109
To use **Automatic** or **Select** data collection modes, you must connect your AWS Management account.
110
110
111
-
During this step, you have the option to enable the controller by entering the name of the S3 bucket with AWS CloudTrail activity logs (found on AWS Trails).
111
+
During this step, you can enable the controller by entering the name of the S3 bucket with AWS CloudTrail activity logs (found on AWS Trails).
112
112
113
113
To onboard your AWS environment and configure data collection, see [Onboard an Amazon Web Services (AWS) account](onboard-aws.md).
114
114
@@ -160,9 +160,9 @@ To onboard your GCP environment and configure data collection, see [Onboard a GC
160
160
161
161
## Summary
162
162
163
-
Congratulations! You've finished configuring data collection for your environment(s), and the data collection process has begun.
163
+
Congratulations! You have finished configuring data collection for your environment(s), and the data collection process has begun.
164
164
165
-
The status column in your Permissions Management UI shows you which step of data collection you are at.
165
+
The status column in your Permissions Management UI shows you which step of data collection you're at.
166
166
167
167
168
168
-**Pending**: Permissions Management has not started detecting or onboarding yet.
title: Permissions Management required roles and permissions
3
3
description: Review roles and the level of permissions assigned in Microsoft Entra Permissions Management.
4
+
# customerintent: As a cloud administer, I want to understand Permissions Management role assignments, so that I can effectively assign the correct permissions to users.
4
5
services: active-directory
5
6
author: jenniferf-skc
6
7
manager: amycolannino
@@ -13,30 +14,30 @@ ms.author: jfields
13
14
---
14
15
15
16
16
-
# [Microsoft Entra Admin Center built-in roles](../azure/active-directory/roles/permissions-reference.md)
17
+
# Microsoft Entra admin center built-in roles
17
18
18
-
In Microsoft Entra and Microsoft Entra Permissions Management, assigned roles give users different levels of access to monitor and take action in multicloud environments. In the Microsoft Entra Admin Center, review a list of identities assigned to a privileged role and learn more about the level of permissions given to users assigned roles in your organization.
19
+
In Microsoft Azure and Microsoft Entra Permissions Management, assigned roles give users different levels of access to monitor and take action in multicloud environments. In the [Microsoft Entra admin center built-in roles](../roles/permissions-reference.md), review a list of identities assigned to a privileged role and learn more about the level of permissions given to users assigned roles in your organization.
19
20
20
21
-**Global Administrator**: Manages all aspects of Entra Admin Center and Microsoft services that use Entra Admin Center identities.
21
22
-**Billing Administrator**: Performs common billing related tasks like updating payment information.
22
23
-**Permissions Management Administrator**: Manages all aspects of Entra Permissions Management.
23
24
24
-
# Permissions Management roles and permissions levels
25
+
##Permissions Management roles and permissions levels
25
26
26
27
## Enabling Permissions Management
27
28
- To activate a trial or purchase a license, you must have *Global Administrator* or *Billing Administrator* permissions.
28
29
29
30
## Onboarding your Amazon Web Service (AWS), Microsoft Entra, or Google Cloud Platform (GCP) environments
30
31
31
32
- To configure data collection, you must have *Permissions Management Administrator* or *Global Administrator* permissions.
32
-
- A user with the ability to create a new app registration in Azure (needed to facilitate the OIDC connection) will be needed for AWS and GCP onboarding.
33
+
- A user with *Global Administrator* or *Permissions Management Administrator* role assignments is required for AWS and GCP onboarding.
33
34
34
35
## Notes on permissions and roles in Permissions Management
35
36
36
37
- Users can have the following permissions:
37
38
- Admin for all authorization system types
38
39
- Admin for selected authorization system types
39
-
- If a user is not an admin, they are assigned Entra Admin Center security group-based, fine-grained permissions for all or selected authorization system types:
40
+
- If a user isn't an admin, they're assigned Entra Admin Center security group-based, fine-grained permissions for all or selected authorization system types:
40
41
- Viewers: View only access to scoped cloud accounts. View the specified AWS accounts, Entra subscriptions, and GCP projects
41
42
- Controller: Modify Cloud Infrastructure Entitlement Management (CIEM) properties and use the Remediation dashboard.
42
43
- Approvers: Able to approve permission requests
@@ -46,21 +47,21 @@ In Microsoft Entra and Microsoft Entra Permissions Management, assigned roles gi
46
47
## Permissions Management actions and required roles
47
48
48
49
Remediation
49
-
- To view the Remediation tab, you must have Viewer, Controller, or Approver permissions.
50
-
- To make changes in the Remediation tab, you much have Controller or Approver permissions.
50
+
- To view the Remediation tab, you must have *Viewer*, *Controller*, or *Approver* permissions.
51
+
- To make changes in the **Remediation** tab, you must have *Controller* or *Approver* permissions.
51
52
52
53
Autopilot
53
-
- To view and make changes in the Autopilot tab, you must be a Permissions Management Administrator.
54
+
- To view and make changes in the **Autopilot** tab, you must be a *Permissions Management Administrator*.
54
55
55
56
Alert
56
-
- Any user (admin, non-admin) can create an alert.
57
+
- Any user (admin, nonadmin) can create an alert.
57
58
- Only the user who creates the alert can edit, rename, deactivate, or delete the alert.
58
59
59
60
Manage users or groups
60
61
- Only the owner of a group can add or remove a user from the group.
61
62
- Managing users and groups is only done in the Entra Admin Center.
62
63
63
64
64
-
# Next steps
65
+
##Next steps
65
66
66
67
- For information about managing roles, policies and permissions requests in your organization, see [View roles/policies and requests for permission in the Remediation dashboard](ui-remediation.md).
0 commit comments