You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,7 +43,7 @@ This article lists the Azure AD built-in roles you can assign to allow managemen
43
43
> |[B2C IEF Keyset Administrator](#b2c-ief-keyset-administrator)| Can manage secrets for federation and encryption in the Identity Experience Framework (IEF). | aaf43236-0c0d-4d5f-883a-6955382ac081 |
44
44
> |[B2C IEF Policy Administrator](#b2c-ief-policy-administrator)| Can create and manage trust framework policies in the Identity Experience Framework (IEF). | 3edaf663-341e-4475-9f94-5c398ef6c070 |
45
45
> |[Billing Administrator](#billing-administrator)| Can perform common billing related tasks like updating payment information. | b0f54661-2d74-4c50-afa3-1ec803f12efe |
46
-
> |[Cloud App Security Administrator](#cloud-app-security-administrator)| Can manage all aspects of the Cloud App Security product. | 892c5842-a9a6-463a-8041-72aa08ca3cf6 |
46
+
> |[Cloud App Security Administrator](#cloud-app-security-administrator)| Can manage all aspects of the Defender for Cloud Apps product. | 892c5842-a9a6-463a-8041-72aa08ca3cf6 |
47
47
> |[Cloud Application Administrator](#cloud-application-administrator)| Can create and manage all aspects of app registrations and enterprise apps except App Proxy. | 158c047a-c907-4556-b7ef-446551a6b5f7 |
48
48
> |[Cloud Device Administrator](#cloud-device-administrator)| Limited access to manage devices in Azure AD. | 7698a772-787b-4ac8-901f-60d6b08affd2 |
49
49
> |[Compliance Administrator](#compliance-administrator)| Can read and manage compliance configuration and reports in Azure AD and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |
@@ -450,12 +450,12 @@ Makes purchases, manages subscriptions, manages support tickets, and monitors se
450
450
451
451
## Cloud App Security Administrator
452
452
453
-
Users with this role have full permissions in Cloud App Security. They can add administrators, add Microsoft Cloud App Security (MCAS) policies and settings, upload logs, and perform governance actions.
453
+
Users with this role have full permissions in Defender for Cloud Apps. They can add administrators, add Microsoft Defender for Cloud Apps policies and settings, upload logs, and perform governance actions.
454
454
455
455
> [!div class="mx-tableFixed"]
456
456
> | Actions | Description |
457
457
> | --- | --- |
458
-
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Cloud App Security|
458
+
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps|
459
459
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
460
460
461
461
## Cloud Application Administrator
@@ -590,7 +590,7 @@ In | Can do
590
590
> | Actions | Description |
591
591
> | --- | --- |
592
592
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
593
-
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Cloud App Security|
593
+
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps|
594
594
> | microsoft.azure.informationProtection/allEntities/allTasks | Manage all aspects of Azure Information Protection |
595
595
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
596
596
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
@@ -928,7 +928,7 @@ Users with this role have access to all administrative features in Azure Active
928
928
> | microsoft.directory/users/authenticationMethods/basic/update | Update basic properties of authentication methods for users |
929
929
> | microsoft.directory/authorizationPolicy/allProperties/allTasks | Manage all aspects of authorization policy |
930
930
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
931
-
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Cloud App Security|
931
+
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps|
> | microsoft.directory/connectors/allProperties/read | Read all properties of application proxy connectors |
934
934
> | microsoft.directory/connectorGroups/create | Create application proxy connector groups |
@@ -1087,7 +1087,7 @@ Users in this role can read settings and administrative information across Micro
1087
1087
> | microsoft.directory/users/authenticationMethods/standard/restrictedRead | Read standard properties of authentication methods that do not include personally identifiable information for users |
1088
1088
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
1089
1089
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices |
1090
-
> | microsoft.directory/cloudAppSecurity/allProperties/read | Read all properties for Cloud app security|
1090
+
> | microsoft.directory/cloudAppSecurity/allProperties/read | Read all properties for Defender for Cloud Apps|
1091
1091
> | microsoft.directory/connectors/allProperties/read | Read all properties of application proxy connectors |
1092
1092
> | microsoft.directory/connectorGroups/allProperties/read | Read all properties of application proxy connector groups |
1093
1093
> | microsoft.directory/contacts/allProperties/read | Read all properties for contacts |
0 commit comments