You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/users-groups-roles/directory-assign-admin-roles.md
+21-18Lines changed: 21 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -105,7 +105,9 @@ The following administrator roles are available:
105
105
***[Customer Lockbox access approver](#customer-lockbox-access-approver)**: Manages [Customer Lockbox requests](https://docs.microsoft.com/office365/admin/manage/customer-lockbox-requests) in your organization. They receive email notifications for Customer Lockbox requests and can approve and deny requests from the Microsoft 365 admin center. They can also turn the Customer Lockbox feature on or off. Only global admins can reset the passwords of people assigned to this role.
106
106
<!-- This was announced in August of 2018. https://techcommunity.microsoft.com/t5/Security-Privacy-and-Compliance/Customer-Lockbox-Approver-Role-Now-Available/ba-p/223393-->
107
107
108
-
***[Device Administrators](#device-administrators)**: This role is available for assignment only as an additional local administrator in [Device settings](https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/DevicesMenuBlade/DeviceSettings/menuId/). Users with this role become local machine administrators on all Windows 10 devices that are joined to Azure Active Directory. They do not have the ability to manage devices objects in Azure Active Directory.
108
+
***[Desktop Analytics Administrator](#desktop-analytics-administrator)**: Users in this role can manage the Desktop Analytics and Office Customization & Policy services. For Desktop Analytics, this includes the ability to view asset inventory, create deployment plans, view deployment and health status. For Office Customization & Policy service, this role enables users to manage Office policies.
109
+
110
+
***[Device Administrator](#device-administrators)**: This role is available for assignment only as an additional local administrator in [Device settings](https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/DevicesMenuBlade/DeviceSettings/menuId/). Users with this role become local machine administrators on all Windows 10 devices that are joined to Azure Active Directory. They do not have the ability to manage devices objects in Azure Active Directory.
109
111
110
112
***[Directory Readers](#directory-readers)**: This is a role that should be assigned only to legacy applications that do not support the [Consent Framework](../develop/quickstart-v1-integrate-apps-with-azure-ad.md). Don't assign it to users.
111
113
@@ -405,22 +407,6 @@ Can perform common billing related tasks like updating payment information.
405
407
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
406
408
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
407
409
408
-
### Desktop Analytics Administrator
409
-
Can manage the Desktop Analytics and Office Customization & Policy services. For Desktop Analytics, this includes the ability to view asset inventory, create deployment plans, view deployment and health status. For Office Customization & Policy service, this role enables users to manage Office policies.
410
-
411
-
> [!NOTE]
412
-
> This role has additional permissions outside of Azure Active Directory. For more information, see role description above.
413
-
>
414
-
>
415
-
416
-
|**Actions**|**Description**|
417
-
| --- | --- |
418
-
| microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health. |
419
-
| microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets. |
420
-
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
421
-
| microsoft.office365.desktopAnalytics/allEntities/allTasks | Manage all aspects of Desktop Analytics. |
422
-
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
423
-
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
424
410
425
411
### Cloud Application Administrator
426
412
Can create and manage all aspects of app registrations and enterprise apps except App Proxy.
@@ -630,6 +616,23 @@ Can approve Microsoft support requests to access customer organizational data.
630
616
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
631
617
| microsoft.office365.lockbox/allEntities/allTasks | Manage all aspects of Office 365 Customer Lockbox |
632
618
619
+
### Desktop Analytics Administrator
620
+
Can manage the Desktop Analytics and Office Customization & Policy services. For Desktop Analytics, this includes the ability to view asset inventory, create deployment plans, view deployment and health status. For Office Customization & Policy service, this role enables users to manage Office policies.
621
+
622
+
> [!NOTE]
623
+
> This role has additional permissions outside of Azure Active Directory. For more information, see role description above.
624
+
>
625
+
>
626
+
627
+
|**Actions**|**Description**|
628
+
| --- | --- |
629
+
| microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health. |
630
+
| microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets. |
631
+
| microsoft.office365.webPortal/allEntities/basic/read | Read basic properties on all resources in microsoft.office365.webPortal. |
632
+
| microsoft.office365.desktopAnalytics/allEntities/allTasks | Manage all aspects of Desktop Analytics. |
633
+
| microsoft.office365.serviceHealth/allEntities/allTasks | Read and configure Office 365 Service Health. |
634
+
| microsoft.office365.supportTickets/allEntities/allTasks | Create and manage Office 365 support tickets. |
635
+
633
636
### Device Administrators
634
637
Users assigned to this role are added to the local administrators group on Azure AD-joined devices.
635
638
@@ -1301,7 +1304,6 @@ B2C User Flow Attribute Administrator | B2C User Flow Attribute Administrator |
0 commit comments