You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+19-9Lines changed: 19 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -83,6 +83,7 @@ This article lists the Azure AD built-in roles you can assign to allow managemen
83
83
> |[Modern Commerce User](#modern-commerce-user)| Can manage commercial purchases for a company, department or team. | d24aef57-1500-4070-84db-2666f29cf966 |
84
84
> |[Network Administrator](#network-administrator)| Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications. | d37c8bed-0711-4417-ba38-b4abe66ce4c2 |
85
85
> |[Office Apps Administrator](#office-apps-administrator)| Can manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish 'what's new' feature content to end-user's devices. | 2b745bdf-0803-4d80-aa65-822c4493daac |
86
+
> |[Organizational Messages Writer](#organizational-messages-writer)| Write, publish, manage, and review the organizational messages for end-users through Microsoft product surfaces. | 507f53e4-4e52-4077-abd3-d2e1558b6ea2 |
86
87
> |[Partner Tier1 Support](#partner-tier1-support)| Do not use - not intended for general use. | 4ba39ca4-527c-499a-b93d-d9b492c50246 |
87
88
> |[Partner Tier2 Support](#partner-tier2-support)| Do not use - not intended for general use. | e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8 |
88
89
> |[Password Administrator](#password-administrator)| Can reset passwords for non-administrators and Password Administrators. | 966707d0-3269-4727-9be2-8c3a10f19b9d |
@@ -885,7 +886,7 @@ Users with this role have read access to recipients and write access to the attr
885
886
> [!div class="mx-tableFixed"]
886
887
> | Actions | Description |
887
888
> | --- | --- |
888
-
> | microsoft.office365.exchange/allRecipients/allProperties/allTasks | Create and delete all recipients, and read and update all properties of recipients in Exchange Online |
889
+
> | microsoft.office365.exchange/recipients/allProperties/allTasks | Create and delete all recipients, and read and update all properties of recipients in Exchange Online |
889
890
> | microsoft.office365.exchange/migration/allProperties/allTasks | Manage all tasks related to migration of recipients in Exchange Online |
890
891
891
892
## External ID User Flow Administrator
@@ -1578,6 +1579,23 @@ Users in this role can manage Microsoft 365 apps' cloud settings. This includes
1578
1579
> | microsoft.office365.userCommunication/allEntities/allTasks | Read and update what's new messages visibility |
1579
1580
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1580
1581
1582
+
## Organizational Messages Writer
1583
+
1584
+
Assign the Organizational Messages Writer role to users who need to do the following tasks:
1585
+
1586
+
- Write, publish, and delete organizational messages using Microsoft 365 admin center or Microsoft Endpoint Manager
1587
+
- Manage organizational message delivery options using Microsoft 365 admin center or Microsoft Endpoint Manager
1588
+
- Read organizational message delivery results using Microsoft 365 admin center or Microsoft Endpoint Manager
1589
+
- Enable or disable permission options for organizational messages using Microsoft 365 admin center or Microsoft Endpoint Manager
1590
+
- View usage reports and most settings in the Microsoft 365 admin center, but can't make changes
1591
+
1592
+
> [!div class="mx-tableFixed"]
1593
+
> | Actions | Description |
1594
+
> | --- | --- |
1595
+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all aspects of Microsoft 365 organizational message center |
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1598
+
1581
1599
## Partner Tier1 Support
1582
1600
1583
1601
Do not use. This role has been deprecated and will be removed from Azure AD in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
@@ -2126,19 +2144,11 @@ Users in this role can manage all aspects of the Microsoft Teams workload via th
2126
2144
> | microsoft.teams/allEntities/allProperties/allTasks | Manage all resources in Teams |
> | microsoft.directory/crossTenantAccessPolicy/default/standard/read | Read basic properties of the default cross-tenant access policy |
2131
-
> | microsoft.directory/crossTenantAccessPolicy/default/b2bCollaboration/update | Update Azure AD B2B collaboration settings of the default cross-tenant access policy |
2132
-
> | microsoft.directory/crossTenantAccessPolicy/default/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of the default cross-tenant access policy |
2133
2148
> | microsoft.directory/crossTenantAccessPolicy/default/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of the default cross-tenant access policy |
2134
-
> | microsoft.directory/crossTenantAccessPolicy/default/tenantRestrictions/update | Update tenant restrictions of the default cross-tenant access policy |
> | microsoft.directory/crossTenantAccessPolicy/partners/standard/read | Read basic properties of cross-tenant access policy for partners |
2138
-
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bCollaboration/update | Update Azure AD B2B collaboration settings of cross-tenant access policy for partners |
2139
-
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of cross-tenant access policy for partners |
2140
2151
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
2141
-
> | microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update | Update tenant restrictions of cross-tenant access policy for partners |
0 commit comments