Skip to content

Commit ff770df

Browse files
committed
Organizational Messages Writer
1 parent a566983 commit ff770df

File tree

1 file changed

+19
-9
lines changed

1 file changed

+19
-9
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 19 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -83,6 +83,7 @@ This article lists the Azure AD built-in roles you can assign to allow managemen
8383
> | [Modern Commerce User](#modern-commerce-user) | Can manage commercial purchases for a company, department or team. | d24aef57-1500-4070-84db-2666f29cf966 |
8484
> | [Network Administrator](#network-administrator) | Can manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications. | d37c8bed-0711-4417-ba38-b4abe66ce4c2 |
8585
> | [Office Apps Administrator](#office-apps-administrator) | Can manage Office apps cloud services, including policy and settings management, and manage the ability to select, unselect and publish 'what's new' feature content to end-user's devices. | 2b745bdf-0803-4d80-aa65-822c4493daac |
86+
> | [Organizational Messages Writer](#organizational-messages-writer) | Write, publish, manage, and review the organizational messages for end-users through Microsoft product surfaces. | 507f53e4-4e52-4077-abd3-d2e1558b6ea2 |
8687
> | [Partner Tier1 Support](#partner-tier1-support) | Do not use - not intended for general use. | 4ba39ca4-527c-499a-b93d-d9b492c50246 |
8788
> | [Partner Tier2 Support](#partner-tier2-support) | Do not use - not intended for general use. | e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8 |
8889
> | [Password Administrator](#password-administrator) | Can reset passwords for non-administrators and Password Administrators. | 966707d0-3269-4727-9be2-8c3a10f19b9d |
@@ -885,7 +886,7 @@ Users with this role have read access to recipients and write access to the attr
885886
> [!div class="mx-tableFixed"]
886887
> | Actions | Description |
887888
> | --- | --- |
888-
> | microsoft.office365.exchange/allRecipients/allProperties/allTasks | Create and delete all recipients, and read and update all properties of recipients in Exchange Online |
889+
> | microsoft.office365.exchange/recipients/allProperties/allTasks | Create and delete all recipients, and read and update all properties of recipients in Exchange Online |
889890
> | microsoft.office365.exchange/migration/allProperties/allTasks | Manage all tasks related to migration of recipients in Exchange Online |
890891
891892
## External ID User Flow Administrator
@@ -1578,6 +1579,23 @@ Users in this role can manage Microsoft 365 apps' cloud settings. This includes
15781579
> | microsoft.office365.userCommunication/allEntities/allTasks | Read and update what's new messages visibility |
15791580
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
15801581
1582+
## Organizational Messages Writer
1583+
1584+
Assign the Organizational Messages Writer role to users who need to do the following tasks:
1585+
1586+
- Write, publish, and delete organizational messages using Microsoft 365 admin center or Microsoft Endpoint Manager
1587+
- Manage organizational message delivery options using Microsoft 365 admin center or Microsoft Endpoint Manager
1588+
- Read organizational message delivery results using Microsoft 365 admin center or Microsoft Endpoint Manager
1589+
- Enable or disable permission options for organizational messages using Microsoft 365 admin center or Microsoft Endpoint Manager
1590+
- View usage reports and most settings in the Microsoft 365 admin center, but can't make changes
1591+
1592+
> [!div class="mx-tableFixed"]
1593+
> | Actions | Description |
1594+
> | --- | --- |
1595+
> | microsoft.office365.organizationalMessages/allEntities/allProperties/allTasks | Manage all aspects of Microsoft 365 organizational message center |
1596+
> | microsoft.office365.usageReports/allEntities/standard/read | Read tenant-level aggregated Office 365 usage reports |
1597+
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
1598+
15811599
## Partner Tier1 Support
15821600

15831601
Do not use. This role has been deprecated and will be removed from Azure AD in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
@@ -2126,19 +2144,11 @@ Users in this role can manage all aspects of the Microsoft Teams workload via th
21262144
> | microsoft.teams/allEntities/allProperties/allTasks | Manage all resources in Teams |
21272145
> | microsoft.directory/crossTenantAccessPolicy/standard/read | Read basic properties of cross-tenant access policy |
21282146
> | microsoft.directory/crossTenantAccessPolicy/allowedCloudEndpoints/update | Update allowed cloud endpoints of cross-tenant access policy |
2129-
> | microsoft.directory/crossTenantAccessPolicy/basic/update | Update basic settings of cross-tenant access policy |
21302147
> | microsoft.directory/crossTenantAccessPolicy/default/standard/read | Read basic properties of the default cross-tenant access policy |
2131-
> | microsoft.directory/crossTenantAccessPolicy/default/b2bCollaboration/update | Update Azure AD B2B collaboration settings of the default cross-tenant access policy |
2132-
> | microsoft.directory/crossTenantAccessPolicy/default/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of the default cross-tenant access policy |
21332148
> | microsoft.directory/crossTenantAccessPolicy/default/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of the default cross-tenant access policy |
2134-
> | microsoft.directory/crossTenantAccessPolicy/default/tenantRestrictions/update | Update tenant restrictions of the default cross-tenant access policy |
21352149
> | microsoft.directory/crossTenantAccessPolicy/partners/create | Create cross-tenant access policy for partners |
2136-
> | microsoft.directory/crossTenantAccessPolicy/partners/delete | Delete cross-tenant access policy for partners |
21372150
> | microsoft.directory/crossTenantAccessPolicy/partners/standard/read | Read basic properties of cross-tenant access policy for partners |
2138-
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bCollaboration/update | Update Azure AD B2B collaboration settings of cross-tenant access policy for partners |
2139-
> | microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update | Update Azure AD B2B direct connect settings of cross-tenant access policy for partners |
21402151
> | microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update | Update cross-cloud Teams meeting settings of cross-tenant access policy for partners |
2141-
> | microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update | Update tenant restrictions of cross-tenant access policy for partners |
21422152
21432153
## Teams Communications Administrator
21442154

0 commit comments

Comments
 (0)