Skip to content

Commit aa6604f

Browse files
committed
add note for UA role change
1 parent 233644a commit aa6604f

File tree

2 files changed

+7
-1
lines changed

2 files changed

+7
-1
lines changed

articles/active-directory/governance/entitlement-management-catalog-create.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,9 @@ A catalog is a container of resources and access packages. You create a catalog
2929

3030
**Prerequisite role:** Global administrator, Identity Governance administrator, User administrator, or Catalog creator
3131

32+
> [!NOTE]
33+
> The ability for a user in the user administrator to create catalogs or manage access packages in a catalog they do not own will be removed. If users in your organization have been using membership of this role for configuring catalogs, access packages or policies in entitlement management, please assign the **Identity Governance administrator** role to those users.
34+
3235
1. In the Azure portal, click **Azure Active Directory** and then click **Identity Governance**.
3336

3437
1. In the left menu, click **Catalogs**.

articles/active-directory/governance/entitlement-management-delegate.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -115,7 +115,10 @@ The following table lists the tasks that the entitlement management roles can do
115115

116116
## Required roles to add resources to a catalog
117117

118-
A Global administrator can add or remove any group (cloud-created security groups or cloud-created Microsoft 365 Groups), application, or SharePoint Online site in a catalog. A User administrator can add or remove any group or application in a catalog, except for a group configured as assignable to a directory role. Note that a user administrator can manage access packages in a catalog that includes groups configured as assignable to a directory role. For more information on role-assignable groups, reference [Create a role-assignable group in Azure Active Directory](../roles/groups-create-eligible.md).
118+
A Global administrator can add or remove any group (cloud-created security groups or cloud-created Microsoft 365 Groups), application, or SharePoint Online site in a catalog. A User administrator can add or remove any group or application in a catalog, except for a group configured as assignable to a directory role. For more information on role-assignable groups, reference [Create a role-assignable group in Azure Active Directory](../roles/groups-create-eligible.md).
119+
120+
> [!NOTE]
121+
> The ability for a user in the user administrator to create catalogs or manage access packages in a catalog they do not own will be removed. If users in your organization have been using membership of this role for configuring catalogs, access packages or policies in entitlement management, please assign the **Identity Governance administrator** role to those users.
119122
120123
For a user who isn't a global administrator, to add groups, applications, or SharePoint Online sites to a catalog, that user must have *both* an Azure AD directory role or ownership of the resource, and a and catalog owner entitlement management role for the catalog. The following table lists the role combinations that are required to add resources to a catalog. To remove resources from a catalog, you must have the same roles.
121124

0 commit comments

Comments
 (0)