Skip to content

Commit 380a52c

Browse files
authored
Update remediate-malicious-email-delivered-office-365.md
"Email & collaboration metadata (read)" this permission is neecded if you use unified rbac It only States its needed for view and download mail message and content but it´s definetly needed for hard delete to work. since it´s not modifier in the security portal to be required, please update documentation
1 parent 1718f0c commit 380a52c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-office-365/remediate-malicious-email-delivered-office-365.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,7 @@ Open any remediation item to view details about it, including its remediation na
106106

107107
**Delete sender's copy**: Also try to soft delete the message from the sender's Sent Items folder if the sender is the organization.
108108

109-
- **Hard delete**: Purge the deleted message. Admins can recover hard deleted items using single-item recovery. For more information about hard deleted and soft deleted items, see [Soft-deleted and hard-deleted items](/compliance/assurance/assurance-exchange-online-data-deletion#soft-deleted-and-hard-deleted-items).
109+
- **Hard delete**: Purge the deleted message. Admins can recover hard deleted items using single-item recovery. For more information about hard deleted and soft deleted items, see [Soft-deleted and hard-deleted items](/compliance/assurance/assurance-exchange-online-data-deletion#soft-deleted-and-hard-deleted-items). If you use unified RBAC you also need this Permission: "Email & collaboration metadata (read)" for hard delete to work.
110110

111111
> [!NOTE]
112112
> In U.S. Government organizations (Microsoft 365 GCC, GCC High, and DoD) admins can take the actions **Soft delete**, **Move to junk folder**, **Move to deleted items**, **Hard delete**, and **Move to inbox**. The actions **Delete sender's copy** and **Move to inbox** from quarantine folder aren't available. Also, the action logs are available only at <https://security.microsoft.com/threatincidents>, not in the **Action Center** at <https://security.microsoft.com/action-center>.

0 commit comments

Comments
 (0)