# RBACMap - Complete Microsoft 365 RBAC Role Reference # https://rbacmap.com # Version: 5.10.0 | Last updated: 2026-05-24 # Total: 327 role nodes across 9 Microsoft 365 services # (325 documented below + 2 cross-service shortcuts on the M365 hub) # License: MIT | Created by Jacob Sheridan | Not affiliated with Microsoft # # This file is GENERATED by scripts/export-llms-full.ts from the in-app data. # Do not hand-edit. Run `npm run build:llms` after changing role data. > This is the complete role reference for RBACMap. For a summary, see https://rbacmap.com/llms.txt --- # TABLE OF CONTENTS 1. Microsoft Purview (108 roles, 18 categories) 2. Microsoft Entra ID (140 roles, 19 categories) 3. Exchange Online (18 roles, 6 categories) 4. Microsoft Intune (11 roles, 6 categories) 5. SharePoint & OneDrive (16 roles, 6 categories) 6. Microsoft Defender XDR (7 roles, 4 categories) 7. Microsoft Fabric (8 roles, 4 categories) 8. Microsoft Security Copilot (3 roles, 2 categories) 9. Microsoft Power Platform (14 roles, 3 categories) Each role includes: name, description, direct URL, privilege level, permissions, and (where modelled) use cases. Privilege is HIGH for roles flagged `highlight: true` in the data (tenant-wide or cross-service); everything else is Standard. =============================================================================== # 1. MICROSOFT PURVIEW (108 roles, 18 categories) # URL: https://rbacmap.com/services/purview/ =============================================================================== ## Category: Global & Security Roles ### Global Administrator URL: https://rbacmap.com/roles/global-admin/ Privilege: HIGH Description: Full administrative access to all Microsoft 365 and Purview features. However, Global Admin does NOT automatically grant access to certain Purview role groups. Permissions: Full Access - Full administrative access to all Microsoft 365 services, DLP Policies - Create and manage Microsoft Purview policies (DLP, retention, sensitivity labels), Security Settings - Configure compliance and security settings, Role Assignment - Assign roles and permissions to other users, Audit Logs - Access audit logs and compliance reports Use Cases: Initial Purview tenant setup and configuration, Emergency access for critical compliance issues, Cross-service compliance policy management ### Global Reader URL: https://rbacmap.com/roles/global-reader/ Privilege: HIGH Description: Read-only access across all Microsoft 365 and Purview features without the ability to make changes. Permissions: Tenant Settings - View all Microsoft 365 and Entra ID settings, Compliance Configuration - Read all compliance and security configurations, Reports - Access Purview reports and analytics, User Information - View user and group information, Audit Logs - Read audit logs and activity reports Use Cases: Compliance auditors needing visibility, Executive dashboards and reporting, External consultants reviewing compliance posture ### Security Administrator URL: https://rbacmap.com/roles/security-admin/ Privilege: HIGH Description: Manage security features across Microsoft 365 including Purview compliance, Defender, identity protection, and security policies without full Global Admin access. Permissions: Security Policies - Manage security policies and settings across Microsoft 365 and Azure, Purview Compliance - Configure and manage Microsoft Purview compliance features (DLP, retention, sensitivity labels), Microsoft Defender - Manage Microsoft Defender for Office 365, Endpoint, Identity, and Cloud Apps, Security Alerts - Create and manage security alerts and incidents, Conditional Access - Configure Conditional Access policies and identity protection, Threat Protection - Manage threat protection policies and security baselines, Security Reports - Access and manage security reports and dashboards, Information Protection - Configure information protection and data loss prevention, Insider Risk - Manage insider risk management and communication compliance policies, Alert Investigation - View and investigate security alerts across Microsoft 365, Workload Security - Manage security settings in Exchange, SharePoint, Teams, Audit Logs - Read audit logs and security events Use Cases: Chief Information Security Officer (CISO) managing security program, Security team managing DLP, information protection, and threat protection, Compliance team configuring security-related compliance policies, Security operations center (SOC) managing security incidents, IT security team implementing security baselines and policies, Managing Purview security features (DLP, insider risk, communication compliance) ### Security Reader URL: https://rbacmap.com/roles/security-reader/ Privilege: HIGH Description: Read-only access to security features, reports, and alerts across Microsoft 365 including Purview compliance monitoring. Permissions: Security Alerts - View security policies, alerts, and incidents across Microsoft 365, Compliance Reports - Read Purview compliance reports (DLP, retention, sensitivity labels, insider risk), Defender Dashboards - Access Microsoft Defender security dashboards and alerts, Threat Protection - View threat protection policies and security settings, Security Reports - Read security reports, analytics, and compliance dashboards, Conditional Access - View Conditional Access policies and identity protection settings, Audit Logs - Read audit logs and security events, Compliance Center - Access security and compliance center read-only features, DLP Incidents - View DLP policy matches and incidents, Classification Reports - Read information protection and classification reports, Insider Risk - View insider risk management and communication compliance dashboards, Secure Score - Access security score and secure score recommendations Use Cases: Security analysts monitoring threats and incidents, SOC team members reviewing security alerts and dashboards, Compliance auditors reviewing security posture, Executive leadership viewing security metrics and reports, External auditors assessing security controls, Help desk viewing security policies for troubleshooting, Security consultants assessing security configuration ### Compliance Administrator URL: https://rbacmap.com/roles/data-gov-2/ Privilege: Standard Description: Comprehensive Entra ID role with broad permissions across Microsoft Purview compliance features including DLP, retention, sensitivity labels, eDiscovery, and compliance management. Permissions: Retention Policies - Manage retention policies and labels across all Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams, Copilot), DLP Policies - Configure DLP policies across cloud apps, endpoints, on-premises repositories, and Exchange, Sensitivity Labels - Create and manage sensitivity labels and auto-labeling policies, Compliance Manager - Access Compliance Manager and manage assessments, improvement actions, and compliance scores, Information Barriers - Configure information barriers policies and organizational segments, Classifiers - Manage trainable classifiers, exact data match (EDM), and sensitive information types, Reports - View and export compliance reports, audit logs, and analytics dashboards, eDiscovery Standard - Manage eDiscovery (Standard) cases: search, hold, export mailboxes, sites, and Teams, Communication Compliance - Configure communication compliance policies and review alerts (view-only on messages), Insider Risk - Manage insider risk management policies and review alerts (view-only on content), Records Management - Configure records management labels, file plan, and disposition workflows, Alert Policies - Manage alert policies, activity alerts, and compliance notifications, Activity Explorer - Access Activity Explorer for user activity monitoring (list view only), Adaptive Scopes - Manage adaptive scopes for dynamic policy targeting, Copilot Retention - Configure retention for Microsoft 365 Copilot interactions and AI-generated content, Administrative Units - Manage administrative units for scoped retention and DLP policies Use Cases: Chief Compliance Officer or Compliance Manager with broad oversight responsibilities, Organizations needing a single Entra ID role for general compliance management across all Purview solutions, Smaller compliance teams where one person handles DLP, retention, sensitivity labels, and eDiscovery, Compliance consultants implementing comprehensive compliance programs for clients, Mid-sized organizations without specialized compliance roles (e.g., separate DLP and retention admins), Managing regulatory compliance for GDPR, HIPAA, SOX, SEC, FINRA, CCPA, FERPA, Configuring organization-wide data protection and governance policies, Coordinating compliance initiatives across legal, IT, and business stakeholder groups ### Compliance Data Administrator URL: https://rbacmap.com/roles/data-gov-3/ Privilege: Standard Description: Enhanced Entra ID role with all Compliance Administrator permissions PLUS device management, Content Explorer access, and advanced file activity tracking capabilities. Permissions: Compliance Admin - All Compliance Administrator permissions (DLP, retention, sensitivity labels, eDiscovery, Compliance Manager), Device Compliance - Manage device compliance policies for mobile devices and endpoints, Activity Explorer - Track and protect files using Activity Explorer with full file path and user details, Content Explorer - Access Content Explorer to view actual sensitive content and file details in-place, Device Onboarding - Configure device onboarding for Endpoint DLP across Windows, macOS, iOS, Android, Device DLP - Manage device-based DLP policies for USB, Bluetooth, removable media, network shares, File Activity - View file activity across all workloads: Exchange, SharePoint, OneDrive, Teams, Endpoint, Power BI, Evidence Download - Download evidence files from Endpoint DLP alerts and activity explorer, Classification Analytics - Access data classification analytics and sensitive information type distribution reports, DLP Simulation - Manage DLP policy test mode and simulation mode for auto-labeling, OCR Configuration - Configure advanced DLP rules for optical character recognition (OCR) in images, File Metadata - View detailed file metadata: sensitivity labels, retention labels, DLP matches, sharing permissions, Classifier Feedback - Access trainable classifier feedback explorer and review user feedback on ML classifications, Device Groups - Manage device groups and device-specific DLP policy exceptions, Endpoint DLP Settings - Configure advanced Endpoint DLP settings: browser monitoring, file path exclusions, unallowed apps Use Cases: Managing bring-your-own-device (BYOD) compliance programs with device-level DLP enforcement, Implementing Endpoint DLP across corporate laptops, mobile devices, and remote worker endpoints, Tracking sensitive file activities and movement across cloud and on-premises locations, Comprehensive data protection investigations requiring Content Explorer access to actual files, Organizations with hybrid environments requiring both cloud and endpoint protection, Investigating data exfiltration incidents with Activity Explorer file path tracking, Validating DLP policy effectiveness by viewing actual Content Explorer matches, Managing device compliance for regulated industries (healthcare, finance, government), Configuring advanced Endpoint DLP for removable media, network shares, and printer protection, Responding to data breach incidents requiring deep dive into file access and sharing patterns ### Quarantine Administrator URL: https://rbacmap.com/roles/quarantine-admin/ Privilege: Standard Description: Members can access all quarantine actions in Microsoft Defender for Office 365 and Exchange Online Protection. Can release, delete, preview, and manage quarantined messages and files. Permissions: Quarantine - Access all quarantine actions for messages and files, Release quarantined messages to intended recipients, Delete quarantined messages permanently, Preview quarantined message content, Allow or block senders from quarantined messages, Submit false positives and false negatives to Microsoft, Manage quarantine policies and notifications, Download quarantined messages and attachments Use Cases: Reviewing and releasing legitimate messages caught by spam or malware filters, Managing phishing quarantine for end-user reported messages, Investigating quarantined attachments for threat analysis, Configuring quarantine notification policies for users, Responding to mail flow incidents involving widespread quarantine, Managing bulk quarantine release during false positive events ### Purview Consumption Management URL: https://rbacmap.com/roles/purview-consumption-mgmt/ Privilege: Standard Description: Manage and view Purview consumption billing reports. Provides access to consumption-based licensing reports and usage analytics for Microsoft Purview services. Permissions: Purview Consumption Admin - View and manage consumption billing reports, Access Purview usage analytics and consumption metrics, View license utilization reports for Purview services, Monitor consumption-based billing for Purview features Use Cases: Monitoring Purview consumption costs and billing, Analyzing license utilization across compliance solutions, Budget planning for Purview service consumption, Reporting on Purview usage trends to finance teams ### Organization Management URL: https://rbacmap.com/roles/purview-org-mgmt/ Privilege: HIGH Description: Top-level Purview role group. Members can control permissions for accessing features in the Microsoft Purview, Defender, and compliance portals, and manage settings for device management, data loss prevention, reports, and preservation. This is the most powerful Purview role group — effectively a "compliance global admin." Permissions: Audit Logs - Search administrator audit log and view results, Case Management - Create and manage eDiscovery cases, Compliance Administrator - Full compliance configuration, Compliance Search - Run searches on mailboxes and sites, Device Management - Manage device compliance and policies, DLP Compliance Management - Configure data loss prevention policies, Hold - Place mailboxes and sites on hold, Manage Alerts - Configure and respond to security alerts, Quarantine - Manage quarantined messages and files, Retention Management - Configure retention policies and labels, Role Management - Add or remove members from role groups (THE critical permission), Security Administrator - Full security feature access, Sensitivity Label Administrator - Create and manage sensitivity labels, View-Only Audit Logs / Configuration / DLP / Recipients - Read-only views Use Cases: Initial Purview tenant setup and role group configuration, Cross-solution compliance program management, Emergency access for critical compliance incidents, Delegating permissions to other administrators ### Security Operator URL: https://rbacmap.com/roles/purview-security-operator/ Privilege: Standard Description: Members can manage security alerts, and also view reports and settings of security features. SOC operator role — focused on alert triage and response without broader security administration permissions. Permissions: Compliance Search - Run content searches across Microsoft 365, Data Security Investigation Contributor - Contribute to data security investigations, Manage Alerts - Triage and respond to security alerts, Purview Copilot Workspace Contributor - Use Copilot in security workflows, Security Reader - Read-only access to security features, Tag Contributor / Reader - Manage and read security tags, View-Only Manage Alerts - Read-only alert view Use Cases: Day-to-day SOC alert triage and response, Investigating security incidents without permission to change policies, Running compliance searches as part of incident response, Operating as Tier 1/2 SOC analyst with read access to security configuration ### Service Assurance User URL: https://rbacmap.com/roles/purview-service-assurance-user/ Privilege: Standard Description: Members can access the Service Assurance section in the Microsoft Purview portal. Service Assurance provides reports and documents that describe Microsoft's security practices for customer data stored in Microsoft 365, including SOC reports, ISO certifications, and penetration test results. Permissions: Service Assurance View - Access Service Trust Portal documents, Download SOC 1/2/3 audit reports, Access ISO 27001, 27017, 27018 certifications, View FedRAMP, HIPAA, GDPR compliance documentation, Access penetration testing summaries, View Microsoft data protection practices Use Cases: Customer due diligence and vendor risk assessments, Regulatory audit evidence gathering (SOC 2, ISO, HIPAA), Responding to customer security questionnaires, Internal compliance program documentation, Privacy impact assessments referencing Microsoft's practices ### AI Administrators URL: https://rbacmap.com/roles/purview-ai-admin/ Privilege: Standard Description: In addition to the capabilities of the AI Administrator role in Microsoft Entra, this group assigns read-only permissions for AI security insights in Microsoft Purview. Used for governing Microsoft 365 Copilot and AI-related enterprise services from a compliance perspective. Permissions: AI Administrator (Entra) - Manage Microsoft 365 Copilot configuration, Read AI security insights in Microsoft Purview, View DSPM for AI dashboards and reports, Access AI-related compliance signals, Configure AI governance policies (read in Purview, manage in Entra) Use Cases: Governing Microsoft 365 Copilot rollout, Monitoring AI usage and compliance signals, Coordinating AI compliance program with Purview Data Security teams, Responding to AI-related compliance audit requests ### Billing Administrator URL: https://rbacmap.com/roles/purview-billing-admin/ Privilege: Standard Description: Configure billing features in Microsoft Purview. Used for Purview consumption-based billing configuration (separate from broader Microsoft 365 billing administration). Permissions: Billing Admin - Configure Purview billing features, Manage consumption-based billing configuration, Configure billing alerts and thresholds, View billing reports and invoices Use Cases: Configuring Purview consumption-based features (e.g., eDiscovery Premium meters), Setting billing alerts to control unexpected costs, Aligning Purview billing with departmental cost centers, Coordinating Purview cost management with IT finance teams ### MailFlow Administrator URL: https://rbacmap.com/roles/purview-mailflow-admin/ Privilege: Standard Description: Members can monitor and view mail flow insights and reports in the Microsoft Defender portal. Read-focused role for understanding mail flow patterns, queues, and delivery issues without permission to modify transport configuration. Permissions: View mail flow reports in Defender portal, Access mail flow insights and trends, View message tracking logs, Monitor queue health and delivery metrics, Access top sender/recipient analytics Use Cases: Investigating mail delivery delays and queue buildup, Monitoring tenant-wide mail flow health, Identifying top senders/recipients for capacity planning, Diagnosing mail flow issues during incidents, Reporting on mail flow trends to leadership ## Category: eDiscovery ### eDiscovery Manager URL: https://rbacmap.com/roles/ediscovery-manager/ Privilege: Standard Description: Create and manage eDiscovery (Standard and Premium) cases with custodian management, review sets, legal hold notifications, advanced indexing, analytics, and ML-powered predictive coding. Permissions: Case Management - Create and manage eDiscovery (Standard) and eDiscovery (Premium) cases with full lifecycle, Case Members - Add and remove case members, assign reviewer roles, manage team access, Content Search - Perform content searches with KQL across Exchange, SharePoint, OneDrive, Teams, Microsoft 365 Groups, Legal Holds - Place and manage legal holds on mailboxes, sites, Teams, and OneDrive locations, Custodian Management - Manage custodians: add custodians, identify data sources, track acknowledgments, Hold Notifications - Send legal hold notifications and manage custodian communication workflows, Review Sets - Create and manage review sets for advanced document analysis and coding, Advanced Indexing - Use advanced indexing to ensure all content is searchable (process error remediation), Analytics - Run analytics: near-duplicate detection, email threading, conversation reconstruction, themes analysis, Predictive Coding - Create and train predictive coding models for ML-powered relevance ranking (eDiscovery Premium), Document Tagging - Tag documents, create review set queries, apply filters for responsive vs non-responsive, Export - Export search results, review set data, and case evidence with native/PDF formats, Preview - Preview and analyze search results, view metadata, and decrypt RMS-protected content, Case Settings - Configure case settings: analytics options, OCR for images, search permissions, Hold Monitoring - Monitor hold status, view hold errors, manage query-based holds for targeted preservation Use Cases: Legal department conducting internal investigations (fraud, misconduct, policy violations), Responding to litigation discovery requests with advanced review set workflows, HR investigations into employee misconduct with custodian communication tracking, Compliance investigations for regulatory requirements (FCPA, SOX, GDPR, CCPA), Managing multi-custodian complex litigation with hundreds of thousands of documents, Using predictive coding to reduce review costs on large document collections, Coordinating with outside counsel on eDiscovery production and exports, Regulatory investigations requiring proof of legal hold notification compliance, Preparing evidence for depositions, trials, or regulatory submissions, Managing privilege review workflows with tagging and analytics ### eDiscovery Administrator URL: https://rbacmap.com/roles/ediscovery-admin/ Privilege: Standard Description: All eDiscovery Manager permissions PLUS organization-wide access to all cases, global eDiscovery settings management, and hold report oversight across entire tenant. Permissions: Manager Permissions - ALL permissions of eDiscovery Manager (cases, searches, holds, review sets, analytics, predictive coding), All Cases Access - View, access, and manage ALL eDiscovery cases across entire organization (no case isolation limits), Global Settings - Configure organization-wide eDiscovery settings: analytics preferences, OCR settings, search permissions, Global Workflows - Manage custodian workflows and legal hold notification templates globally, Hold Reports - Access hold report (Premium) to view all holds across all cases tenant-wide, Case Management - Add, remove, or modify members in ANY case (including cases created by other managers), Case Deletion - Delete and close any eDiscovery case regardless of who created it, Case Override - Override case permissions and access privileged attorney-client materials in all cases, Indexing Management - Manage advanced indexing settings and reprocessing jobs organization-wide, Role Management - Configure eDiscovery role groups and assign eDiscovery permissions to other users, Activity Reports - View and export comprehensive eDiscovery activity reports and analytics across all cases, Troubleshooting - Troubleshoot and resolve eDiscovery issues across all cases and investigations, Storage Management - Manage eDiscovery storage quotas, limits, and performance optimization, Orphaned Cases - Access abandoned or orphaned cases when original managers leave organization Use Cases: General Counsel or Chief Legal Officer requiring oversight of all legal matters and litigation, Centralized eDiscovery operations center managing all legal discovery across organization, Emergency access to critical cases when original case manager is unavailable or has left company, Compliance audits of eDiscovery activities and legal hold compliance across all cases, Managing global eDiscovery program: templates, processes, best practices, training, Troubleshooting complex eDiscovery issues across multiple cases or custodians, Providing hold reports to executive leadership on litigation risk and preservation status, Managing eDiscovery during organizational restructuring, mergers, or acquisitions, Coordinating with outside counsel on high-stakes litigation requiring cross-case visibility, Ensuring consistent eDiscovery practices and quality control across legal team ### Data Investigator URL: https://rbacmap.com/roles/data-investigator/ Privilege: Standard Description: Perform searches and access review sets for investigation without case management capabilities. Permissions: Content Search - Perform content searches across Microsoft 365, Review Sets - Access and analyze review sets, Export - Export search results, Case Information - View case information, Document Tagging - Tag and annotate documents in review sets, Analytics - Run analytics on collected data Use Cases: Paralegals conducting research and document review, Junior investigators assisting with data analysis, External consultants brought in for specific investigations, IT staff helping with technical data retrieval ### Reviewer URL: https://rbacmap.com/roles/reviewer/ Privilege: Standard Description: Access review sets in eDiscovery cases to analyze collected data without search or export capabilities. Permissions: Document View - View documents in review sets, Document Tagging - Tag and annotate documents, Coding - Apply coding decisions, Review Set Queries - Create and use review set queries, Analytics - View case analytics and insights Use Cases: Contract attorneys reviewing documents for relevance, Subject matter experts providing technical review, Outside counsel conducting privilege review, Large-scale document review projects ### Custodian URL: https://rbacmap.com/roles/custodian-role/ Privilege: Standard Description: Identify and manage custodians (data owners) for eDiscovery cases and track their data sources. Permissions: Custodian Management - Add and remove custodians from cases, Data Sources - Identify custodian data sources (mailboxes, OneDrive, SharePoint), Custodian Holds - Place custodian communications on hold, Acknowledgments - Track custodian acknowledgment of holds, Indexing - Manage custodian index and reprocessing Use Cases: Tracking employees involved in litigation, Managing data preservation for departing executives, Organizing multi-custodian investigations, Ensuring all relevant data sources are identified and preserved ### Hold URL: https://rbacmap.com/roles/hold-role/ Privilege: Standard Description: Place and manage legal holds on content to preserve it during investigations and litigation. Permissions: Case Holds - Create and manage case holds, Location Holds - Place holds on mailboxes, SharePoint sites, and Teams, Query-Based Holds - Configure query-based holds for specific content, Hold Status - Monitor hold status and errors, Release Holds - Release holds when litigation concludes Use Cases: Preserving evidence for ongoing litigation, Implementing litigation hold notices, Preventing deletion of potentially relevant data, Responding to legal preservation requirements ## Category: Audit ### Audit Manager URL: https://rbacmap.com/roles/audit-manager/ Privilege: Standard Description: Search, manage, and configure audit log settings and retention policies for compliance monitoring. Permissions: Audit Search - Search and export unified audit logs, Retention Policies - Configure audit log retention policies, Custom Retention - Create custom audit log retention policies for specific users or activities, Premium Features - Access audit (Premium) features including long-term retention, Mailbox Auditing - Configure mailbox auditing settings, Search Jobs - Manage audit log search jobs Use Cases: Investigating security incidents and breaches, Compliance monitoring and reporting, Forensic analysis of user activities, Meeting regulatory audit requirements (SOX, HIPAA, GDPR), Tracking administrative changes to tenant ### Audit Reader URL: https://rbacmap.com/roles/audit-reader/ Privilege: Standard Description: Search and export audit logs with read-only access, without ability to configure settings. Permissions: Audit Search - Search unified audit logs, Export - Export audit log search results, Event Details - View audit log details and events, Reports - Run predefined audit reports Use Cases: Compliance analysts reviewing user activities, Help desk investigating user-reported issues, External auditors conducting compliance reviews, Management reviewing access and activity reports ## Category: Records Management ### Records Management URL: https://rbacmap.com/roles/records-mgmt-1/ Privilege: Standard Description: Configure retention labels for records, file plans, and disposition reviews for formal records management programs with regulatory-grade immutability. Permissions: Retention Labels - Create and configure retention labels that mark content as records or regulatory records, File Plan - Build and manage file plan with retention schedules and regulatory metadata (21 CFR Part 11, DoD 5015.2, ISO 15489), File Plan Descriptors - Configure file plan descriptors: function, category, subcategory, authority, provision/citation, Disposition Review - Configure disposition review workflows with single or multi-stage approval, Regulatory Records - Manage regulatory records with immutable protection (cannot edit, delete, or remove label), Record Versioning - Apply record versioning and declaration settings (locked vs unlocked records), Proof of Disposal - Configure proof of disposal settings for audit trail of permanent deletion, Event-Based Retention - Set up event-based retention for contracts, employee lifecycle, product lifetime triggers, Auto-Apply Labels - Configure auto-apply retention labels based on sensitive info, keywords, trainable classifiers, Bulk Import/Export - Import and export file plan in bulk for retention schedule migration, Record Unlocking - Manage record unlocking permissions (container admin only for locked records), Tenant Settings - Configure tenant-level record settings: property editing, label removal, version control, Regulatory Declaration - Enable or disable regulatory record declaration option organization-wide Use Cases: Implementing formal records management programs compliant with DoD 5015.2, ISO 15489, MoReq2, Meeting FDA 21 CFR Part 11 requirements for life sciences electronic records and signatures, Managing retention schedules for SEC, FINRA, HIPAA, GDPR, FERPA regulatory compliance, Coordinating multi-stage disposition review and approval processes for critical records, Ensuring records are properly declared with immutable protection against tampering, Meeting government or industry-specific records requirements with proof of disposal, Implementing event-based retention for employee separations, contract expirations, product EOL, Using record versioning to allow controlled updates to locked records in SharePoint/OneDrive, Creating file plan structure with metadata for classification and retrieval, Migrating legacy retention schedules from external systems via bulk import ### Disposition Management URL: https://rbacmap.com/roles/records-mgmt-2/ Privilege: Standard Description: Review and approve content disposition at end of retention period to ensure proper record destruction with proof of disposal and audit trail. Permissions: Disposition Queue - Access disposition review queue and pending disposition dashboard, Pending Review - Review items pending disposition across all Microsoft 365 locations, Retention Decisions - Approve or extend retention for items with justification required, Justification - Provide business justification for disposition decisions and retention extensions, Proof of Disposal - Export proof of disposal evidence and comprehensive disposition reports, Reviewer Management - Configure disposition reviewer permissions and assign reviewers to labels, Disposition History - View disposition history and audit trail of all disposition actions, Search and Filter - Filter and search disposition items by location, label, status, date range, Multi-Stage Review - Configure multi-stage disposition review workflows for critical records, Permanent Deletion - Permanently delete items after disposition approval (cannot be undone), Failed Dispositions - View items that failed disposition due to legal holds or preservation locks, Completion Monitoring - Monitor disposition completion status and generate compliance reports Use Cases: Reviewing records before permanent deletion to ensure retention requirements are met, Ensuring no litigation hold, eDiscovery hold, or preservation lock applies before disposition, Making final determination on extending retention for high-value or business-critical content, Providing approval for compliance with retention schedules and regulatory obligations, Creating audit trail of disposition decisions for SEC, FINRA, FDA compliance reporting, Coordinating with business units on whether to retain or dispose of valuable content, Generating proof of disposal reports for regulatory audits and compliance documentation, Managing multi-stage disposition review for records requiring legal or management approval, Handling event-based retention disposition when triggered by employee departure or contract expiration, Resolving disposition failures due to holds or locks by coordinating with legal teams ### View-Only Records Management URL: https://rbacmap.com/roles/records-mgmt-3/ Privilege: Standard Description: Read-only access to records management features for auditing, compliance reporting, and oversight without modification permissions. Permissions: File Plan - View file plan with all retention labels, schedules, and regulatory metadata, Reports - Access comprehensive records management reports and analytics dashboards, Disposition Queue - View disposition review queue, status, and history without approval permissions, Configuration - Review records management configuration including event types and auto-apply policies, Export - Export reports and analytics for compliance documentation and audit purposes, Label Analytics - View retention label analytics: application counts, locations, user vs auto-applied, Disposition History - Access disposition history and proof of disposal records for audit trail review, Record Versioning - View record versioning settings and locked vs unlocked record status, Event-Based Retention - Review event-based retention configuration and triggered events, File Plan Descriptors - Monitor file plan descriptor usage (function, category, authority, citation), Regulatory Records - View regulatory record vs standard record configuration and restrictions, Tenant Settings - Access tenant-level records management settings (read-only) Use Cases: External auditors reviewing records management program for regulatory compliance assessments, Compliance reporting and analytics for management, board, or regulatory submissions, Management oversight of records management practices and governance maturity, Training new records management staff on current configuration before granting full permissions, Legal team review of retention schedules and disposition workflows during litigation prep, Third-party consultants assessing records management program effectiveness, Internal audit teams verifying adherence to records retention policies and schedules, Compliance officers generating evidence for SEC, FINRA, FDA, or other regulatory audits, Business unit leaders monitoring records management coverage and label application rates, IT teams reviewing technical configuration without risk of accidental changes ## Category: Data Lifecycle Management ### Retention Management URL: https://rbacmap.com/roles/data-gov-1/ Privilege: Standard Description: Create and manage retention policies and labels across Microsoft 365 to ensure compliance with data retention requirements. Permissions: Retention Policies - Create and configure retention policies and retention labels, Workload Settings - Apply retention settings to Exchange, SharePoint, OneDrive, Teams, Copilot interactions, Auto-Labeling - Manage automatic labeling and user-published labels for manual application, Event-Based Retention - Configure event-based retention for contract or project lifecycle triggers, Adaptive Scopes - Configure adaptive scopes for dynamic policy targeting based on user attributes, Label Analytics - Review retention label analytics and label application reports, Exceptions - Manage exceptions, label overrides, and policy conflicts, Copilot Retention - Configure retention for Microsoft 365 Copilot interactions and AI-generated content, Disposition Review - Set up disposition review workflows for end-of-retention decisions, Administrative Units - Manage administrative units for scoped retention policies, Preservation Lock - Configure Preservation Lock for immutable regulatory retention, Policy Monitoring - Monitor retention policy effectiveness and coverage Use Cases: Implementing regulatory retention requirements (SEC, FINRA, HIPAA, GDPR, CCPA), Managing corporate records retention schedules with automated enforcement, Ensuring legal compliance for data retention and evidence preservation, Automating lifecycle management for business documents and communications, Retaining Microsoft 365 Copilot interactions per compliance requirements, Managing retention for different regions using administrative units, Implementing adaptive retention policies based on user department or location, Configuring disposition review for end-of-retention decision workflows ### View-Only Retention Management URL: https://rbacmap.com/roles/data-gov-4/ Privilege: Standard Description: Read-only access to retention policies, labels, and analytics for auditing, compliance reporting, and oversight without modification permissions. Permissions: Retention Policies - View all retention policies and labels across Exchange, SharePoint, OneDrive, Teams, Microsoft 365 Groups, Reports - Access comprehensive retention reports and analytics dashboards, Label Analytics - Review retention label applications: user-applied vs auto-applied, location-specific analytics, Disposition Status - View disposition status, pending reviews, and disposition history, Export - Export retention configuration reports for audit documentation and compliance submissions, Label Statistics - View retention label analytics: top labels, application counts, location breakdowns, Policy Lookup - Access policy lookup tool to determine which retention settings apply to specific locations, Adaptive Scopes - View adaptive scope configuration and membership queries (dynamic user groups), Event-Based Retention - Review event-based retention configuration and triggered events, Administrative Units - View administrative unit scoped policies and their target populations, Copilot Retention - Access retention settings for Microsoft 365 Copilot interactions, Preservation Lock - View preservation lock status on immutable retention policies Use Cases: External auditors reviewing retention compliance programs for SEC, FINRA, FDA, or other regulatory audits, Management oversight of retention program effectiveness and coverage gaps, Compliance reporting and analytics for board presentations or regulatory submissions, Training new retention management staff before granting full administrative permissions, Legal team review of retention schedules during litigation preparation or discovery, Third-party consultants assessing data governance and information lifecycle maturity, Internal audit teams verifying adherence to retention policies and regulatory requirements, Executive dashboards showing retention label adoption rates and compliance metrics, IT teams understanding retention configuration without risk of accidental changes, Business unit leaders monitoring retention coverage for their departments ## Category: Communication Compliance ### Communication Compliance URL: https://rbacmap.com/roles/comm-comp-1/ Privilege: Standard Description: Full access to configure policies, investigate alerts, remediate violations, and manage all aspects of communication monitoring. Permissions: Policy Configuration - Create and configure communication compliance policies with ML classifiers, Alert Investigation - Investigate all alerts and view full message content (Teams, Exchange, Copilot, third-party), Remediation - Take remediation actions (notify, escalate, remove messages, apply retention), Case Files - Access all case files and investigation history with audit trails, Policy Settings - Configure policy settings, conditions, and pseudonymization for privacy, User Permissions - Manage user permissions and role assignments for communication compliance, Export - Export case data, reports, and evidence for legal or regulatory proceedings, Trainable Classifiers - Configure trainable classifiers and customize detection logic, Policy Templates - Manage policy templates (harassment, threat, regulatory violations), Copilot Monitoring - Monitor Microsoft 365 Copilot interactions for sensitive content, Administrative Units - Configure administrative units for scoped policy management, Policy Exceptions - Manage policy exceptions and user exclusions Use Cases: HR investigations into harassment, discrimination, or hostile workplace violations, Compliance monitoring for regulated communications (FINRA, SEC, FCA, GDPR), Detecting insider trading, front-running, or market manipulation communications, Identifying potential data leakage or IP theft through communications channels, Monitoring for offensive, threatening, or inappropriate language and images, Regulatory compliance for financial services message supervision, Monitoring Microsoft 365 Copilot interactions for sensitive or prohibited content, Third-party communication platform monitoring (Zoom, Slack) integration ### Communication Compliance Admins URL: https://rbacmap.com/roles/comm-comp-2/ Privilege: Standard Description: Configure policies and settings but cannot investigate alerts or view message content - separated administration. Permissions: Policy Creation - Create and configure communication compliance policies with condition logic, Policy Conditions - Manage policy conditions, exceptions, supervised users, and scoped groups, Classifiers - Configure ML classifiers, trainable classifiers, and sensitive info types for detection, Policy Settings - Manage policy settings, notifications, and simulation mode, Statistics - View policy statistics, trends, and aggregate metrics (not individual messages), Policy Templates - Configure policy templates for common violations (harassment, regulatory, threats), Administrative Units - Manage administrative units for scoped policy deployment, Pseudonymization - Configure pseudonymization settings for privacy-preserving investigations, Copilot Monitoring - Set up monitoring for Microsoft 365 Copilot interactions, Third-Party Integration - Integrate third-party communication platforms (Zoom, Slack, etc.), Retention - Configure retention and deletion policies for communication compliance data Use Cases: Compliance team configuring monitoring policies per regulatory requirements, IT staff implementing technical policy requirements without HR involvement, Organizations requiring strict separation of duties between policy and investigation, Policy tuning specialists who optimize detection logic based on Analyst feedback, Regulatory compliance engineers deploying financial services supervision policies, Privacy officers configuring pseudonymization and data retention settings, Regional compliance teams managing policies scoped to their administrative units ### Communication Compliance Analysts URL: https://rbacmap.com/roles/comm-comp-3/ Privilege: Standard Description: Access and investigate alerts, view message metadata, but cannot view full message content - limited investigation access. Permissions: Alert View - View communication compliance alerts across all monitored channels, Message Metadata - See message metadata (sender, recipient, subject, timestamp, platform), Match Context - View match context, highlighted violations, and confidence scores, Alert Classification - Classify alerts (false positive, needs review, confirmed violation, escalate), Alert Routing - Route alerts to Communication Compliance Investigators for full message review, Reports - Access aggregate reporting, trends, and policy effectiveness dashboards, Investigation Notes - Add investigation notes and tags for case management, Pseudonymized Data - View pseudonymized investigator identities if configured, Alert Filtering - Filter alerts by policy, severity, user, or administrative unit, Metadata Export - Export alert metadata and statistics (not message content) Use Cases: Initial triage of communication compliance alerts to filter noise, Filtering false positives before escalation to senior investigators, Entry-level compliance monitoring and alert categorization, High-volume alert management and prioritization for investigation team, First-line compliance support for financial services message supervision, Regional compliance teams managing alerts scoped to their administrative units, SOC analysts monitoring for threat or harassment communications ### Communication Compliance Investigators URL: https://rbacmap.com/roles/comm-comp-4/ Privilege: Standard Description: Investigate alerts, view full messages, and take remediation actions without policy configuration access. Permissions: Message Content - View full message content and complete conversation threads (Teams, Exchange, Copilot), Conversation History - Access conversation history, context, and related communications, Remediation Actions - Take remediation actions (notify user, escalate to management, tag for review), Message Removal - Remove messages that violate policies (if configured and approved), Investigation Notes - Document investigation findings with notes, tags, and case files, Evidence Export - Export messages and evidence for legal review or regulatory reporting, Case Files - Access all investigation case files and audit trails, Attachments - View attachments, images, and embedded content in messages, Pseudonymization - Access pseudonymized data with ability to de-anonymize for investigations, Copilot Content - Review Microsoft 365 Copilot interaction content when flagged, Administrative Units - Filter investigations by administrative unit scope, Alert Resolution - Mark alerts as resolved, false positive, or escalated with justification Use Cases: HR investigators conducting formal harassment or discrimination inquiries, Legal team reviewing potential employment law violations or regulatory breaches, Senior compliance officers investigating serious incidents (insider trading, threats), Remediation and resolution of confirmed policy violations, Financial services compliance reviewing regulated communications for FINRA/SEC violations, Employee relations specialists handling workplace conduct investigations, Corporate security investigating threats or violent communications, Privacy officers reviewing potential data leakage through communications ### Communication Compliance Viewers URL: https://rbacmap.com/roles/comm-comp-5/ Privilege: Standard Description: View-only access to reports and analytics dashboards without alert or message access. Permissions: Dashboards - View communication compliance dashboards and program overview, Reports - Access aggregate reports, trends, and analytics, Policy Statistics - See policy statistics, metrics, and effectiveness data, Export - Export reports and analytics data for governance reporting, Policy Configuration - View policy configuration details (read-only, no editing), Alert Trends - Access alert volume trends and resolution metrics, Program Health - View compliance program health indicators, Coverage Statistics - Review policy coverage and supervised user statistics Use Cases: Executive oversight of communication compliance monitoring program, Board or audit committee reporting on compliance program effectiveness, Compliance program metrics and maturity assessment, External auditors reviewing program implementation and controls, Risk committee reporting on communication risk posture, Program health monitoring by leadership, Regulatory reporting and documentation of monitoring controls ### Supervisory Review URL: https://rbacmap.com/roles/purview-supervisory-review/ Privilege: Standard Description: Members can create and manage the policies that define which communications are subject to review in an organization. Used for regulatory supervisory review requirements (e.g., FINRA, SEC) where designated reviewers must sample employee communications. Permissions: Supervisory Review Administrator - Create and manage supervisory review policies, Define communication sampling rules and reviewer assignments, Configure conditions for communications subject to review, Manage reviewer groups and escalation paths, View and report on supervisory review activity Use Cases: FINRA Rule 3110 supervisory review for broker-dealers, SEC Rule 17a-4 communication retention and review, Healthcare regulatory communication oversight, Legal industry communication supervision, Government and defense contractor communication review programs ## Category: Purview Agents (Preview) ### Purview Agent Management URL: https://rbacmap.com/roles/purview-agent-mgmt/ Privilege: Standard Description: Dedicated role group for deploying and enabling all Purview agents. Contains the "Purview Content Analyst" role required to activate the DLP Triage Agent, IRM Triage Agent, and DSPM Posture Agent. Permissions: Enable Agent Deployment - Activate the DLP Triage Agent, IRM Triage Agent, and DSPM Posture Agent, Purview Content Analyst - Core role contained in this role group for agent enablement, Agent Identity Setup - When combined with Role Management role, configure dedicated agent identity (recommended), Does NOT grant access to configure agent settings or view triaged results, Does NOT grant access to underlying DLP, IRM, or DSPM data Use Cases: Initial deployment of Purview agents across the organization, Enabling new agent types as they become available, Setting up agent identity (with Role Management role from Purview Administrators), Granting agent enablement without configuration or data access ### Data Security DLP Triage Agent URL: https://rbacmap.com/roles/purview-dlp-triage-agent/ Privilege: Standard Description: Combined role requirements for setting up, configuring, and viewing results from the DLP Triage Agent. This agent automatically triages DLP alerts from Exchange, Teams, OneDrive, SharePoint, and Devices, categorizing them as "Needs attention", "Less urgent", or "Not categorized". Permissions: Enable DLP Triage Agent - Set up agent using user identity (requires Information Protection Analyst/Investigator + Purview Content Analyst), Configure Agent - Customize triage rules and agent behavior (requires Purview Agent Analysis role), View Triaged Alerts - Access agent-categorized DLP alerts and justifications (requires Purview Agent Analysis), Data Classification Content Download - Required for agent to access content for triage analysis, Security Copilot Contributor - Required for agent interaction and customization Use Cases: Automating initial DLP alert triage to reduce analyst workload, Prioritizing high-severity DLP incidents for immediate investigation, Reducing false positive fatigue for DLP alert reviewers, Accelerating DLP incident response times, Providing consistent alert categorization across DLP workloads ### Data Security IRM Triage Agent URL: https://rbacmap.com/roles/purview-irm-triage-agent/ Privilege: Standard Description: Combined role requirements for setting up, configuring, and viewing results from the Insider Risk Management Triage Agent. This agent automatically triages IRM alerts, helping analysts focus on high-priority insider threats. Permissions: Enable IRM Triage Agent - Set up agent using user identity (requires Insider Risk Management Analysis/Investigation + Purview Content Analyst), Configure Agent - Customize triage rules and agent behavior (requires Purview Agent Analysis role), View Triaged Alerts - Access agent-categorized IRM alerts and justifications (requires Purview Agent Analysis), Security Copilot Contributor - Required for agent interaction and customization Use Cases: Automating initial insider risk alert triage to reduce analyst workload, Prioritizing high-severity insider threats for immediate investigation, Reducing false positive fatigue for insider risk reviewers, Providing consistent risk categorization across IRM policies, Accelerating insider risk incident response and case creation ### Data Security DSPM Posture Agent URL: https://rbacmap.com/roles/purview-dspm-posture-agent/ Privilege: Standard Description: Combined role requirements for deploying, running, and viewing results from the DSPM Posture Agent (Preview). This agent uses natural language processing to find sensitive data across Microsoft 365, helping security teams understand their data landscape. Permissions: Deploy Posture Agent - Requires Purview Content Analyst + Compliance Admin/Security Reader/Data Security Viewer + Data Classification Viewer + Security Copilot Contributor/Owner, Run Posture Queries - Execute natural language searches for sensitive data across Microsoft 365, View Results - Access Posture Agent findings including data locations and sensitivity classifications, Data Classification Content Viewer - View classified content identified by the agent, Data Classification List Viewer - Browse list of classified items Use Cases: Discovering sensitive data locations across Microsoft 365 using natural language, Assessing data security posture before AI deployments (e.g., Copilot), Identifying oversharing of sensitive content across SharePoint, OneDrive, Exchange, Supporting compliance audits with comprehensive data discovery, Proactively finding unprotected sensitive data for remediation ## Category: Compliance Manager ### Compliance Manager Administrators URL: https://rbacmap.com/roles/comp-mgr-admin/ Privilege: Standard Description: Manage template creation and modification in Microsoft Purview Compliance Manager. Can create assessments, implement improvement actions, and manage all Compliance Manager content. Permissions: Compliance Manager Administration - Manage template creation and modification, Compliance Manager Assessment - Create assessments and implement improvement actions, Compliance Manager Contribution - Create assessments and perform work to implement improvement actions, Compliance Manager Reader - View all Compliance Manager content, Data Connector Admin - Configure data connectors Use Cases: Creating and customizing compliance assessment templates, Managing organizational compliance posture, Configuring Compliance Manager settings and automation, Overseeing improvement action implementation across teams ### Compliance Manager Assessors URL: https://rbacmap.com/roles/comp-mgr-assessor/ Privilege: Standard Description: Create assessments, implement improvement actions, and update test status for improvement actions in Microsoft Purview Compliance Manager. Permissions: Compliance Manager Assessment - Create assessments and implement improvement actions, Compliance Manager Contribution - Create assessments and perform work to implement improvement actions, Compliance Manager Reader - View all Compliance Manager content, Data Connector Admin - Configure data connectors Use Cases: Creating compliance assessments for specific regulations, Implementing and testing improvement actions, Updating test status and uploading evidence, Managing assessment lifecycle from creation to completion ### Compliance Manager Contributors URL: https://rbacmap.com/roles/comp-mgr-contributor/ Privilege: Standard Description: Create assessments and perform work to implement improvement actions in Microsoft Purview Compliance Manager. Cannot manage templates or update test status. Permissions: Compliance Manager Contribution - Create assessments and perform work to implement improvement actions, Compliance Manager Reader - View all Compliance Manager content, Data Connector Admin - Configure data connectors Use Cases: Implementing technical improvement actions (e.g., configuring MFA, DLP policies), Documenting compliance evidence and implementation notes, Contributing to assessment completion across IT and security teams, Performing remediation work assigned by Assessors ### Compliance Manager Readers URL: https://rbacmap.com/roles/comp-mgr-reader/ Privilege: Standard Description: View all Microsoft Purview Compliance Manager content except for administrator functions. Read-only access to assessments, improvement actions, and compliance score. Permissions: Compliance Manager Reader - View all Compliance Manager content Use Cases: Executive visibility into organizational compliance posture, Audit and oversight of compliance program progress, Board reporting on compliance score and assessment status, External auditor access for compliance reviews ## Category: Insider Risk Management ### Insider Risk Management URL: https://rbacmap.com/roles/insider-risk-1/ Privilege: Standard Description: Full access to all IRM features including policy creation, alert investigation, forensic evidence review, and Adaptive Protection. Permissions: Policy Management - Create, edit, and delete insider risk policies, Alert Investigation - View and investigate all alerts and cases, Forensic Evidence - Access and view forensic evidence captures, Content Explorer - Access and view Content Explorer for file content, Global Settings - Configure global settings and integrations, Adaptive Protection - Configure Adaptive Protection and risk levels, Notice Templates - Configure notice templates, Evidence Requests - Create forensic evidence capturing requests, Evidence Approval - Approve forensic evidence capturing requests, Indicators - Manage policy indicators and thresholds, Analytics - Access analytics insights and reports, Audit Logs - View and export audit logs, Users Tab - View Adaptive Protection users tab, Reports - View alert and case reports, Risk Graphs - View data risk graphs for alerts, Export - Export case data and generate comprehensive reports Use Cases: Chief Security Officer or Chief Compliance Officer oversight, Dedicated insider threat program managers, Senior security analysts handling sensitive investigations, Privacy officers overseeing data exfiltration risks ### Insider Risk Management Admins URL: https://rbacmap.com/roles/insider-risk-2/ Privilege: Standard Description: Configure IRM policies, settings, integrations, and Adaptive Protection without access to investigate individual cases. Permissions: Policy Creation - Create and configure insider risk policies, Indicators - Manage policy indicators and scoring thresholds, Global Settings - Configure global settings and integrations, Adaptive Protection - Configure Adaptive Protection and insider risk levels, Evidence Requests - Create forensic evidence capturing requests, Analytics - Access analytics insights and reports, Reports - View alert and case reports, Priority Users - Manage priority user groups and exclusions, Reporting Settings - Configure analytics and reporting settings, Integration - Set up integration with DLP and Conditional Access, Alert Customization - Configure inline alert customization settings Use Cases: Security engineers implementing insider risk policies, Compliance administrators configuring detection settings, IT administrators managing integrations and connectors, Policy owners who define but do not investigate violations, Configuring Adaptive Protection for DLP and Conditional Access, Setting up policy templates for data theft and security violations ### Insider Risk Management Analysts URL: https://rbacmap.com/roles/insider-risk-3/ Privilege: Standard Description: Review and investigate alerts, access analytics and case data, configure notice templates without policy configuration or forensic evidence access. Permissions: Alert Access - Access and investigate alerts, Case Access - Access and investigate cases, Risk Scores - View risk score details and activity timeline, Analytics - Access analytics insights, Notice Templates - Configure notice templates, Users Tab - View Adaptive Protection users tab, Reports - View alert and case reports, Risk Graphs - View data risk graphs for alerts, Case Management - Create and manage cases from alerts, Report Generation - Generate investigation reports, Alert Classification - Tag and classify alerts, Escalation - Escalate cases to Investigators, Threshold Editing - Optionally edit policy thresholds (if inline alert customization enabled) Use Cases: Security analysts performing initial alert triage, Compliance team members reviewing risk indicators, HR partners assessing employee risk patterns, Entry-level insider threat analysts, Reviewing Adaptive Protection user risk levels, Analyzing data risk graphs for alert prioritization ### Insider Risk Management Investigators URL: https://rbacmap.com/roles/insider-risk-4/ Privilege: Standard Description: Full investigation access including forensic evidence, Content Explorer, and detailed user activity review without policy configuration. Permissions: Analyst Permissions - All Analyst permissions (access and investigate alerts and cases), Forensic Evidence - Access and view forensic evidence captures, Content Explorer - Access and view Content Explorer to view file content, Notice Templates - Configure notice templates, Users Tab - View Adaptive Protection users tab, Reports - View alert and case reports, Risk Graphs - View data risk graphs for alerts, Activity Logs - View detailed user activity logs, Content Access - Access file and email content related to cases, Export - Export comprehensive investigation packages, Collaboration - Add contributors to cases for collaboration, Threshold Editing - Optionally edit policy thresholds (if inline alert customization enabled) Use Cases: Senior security analysts conducting thorough investigations, Legal team reviewing evidence for potential litigation, HR conducting serious misconduct investigations, Forensic analysts examining suspected data theft, Incident response team analyzing complex insider threats, Reviewing forensic evidence captures of user device activity ### Insider Risk Management Auditors URL: https://rbacmap.com/roles/insider-risk-5/ Privilege: Standard Description: View and export audit logs for IRM activities to ensure proper program governance, compliance, and ethical oversight. Permissions: Audit Logs - View and export insider risk management audit logs, Audit Export - Export audit records for compliance reporting, Access Tracking - Review who accessed which cases and when, Change Monitoring - Monitor policy changes and configuration updates, Evidence Tracking - Track evidence viewing and export activities, Governance Reports - Generate governance and compliance reports, Access Patterns - Audit alert and case access patterns, Approval Monitoring - Monitor forensic evidence capture approvals and denials Use Cases: Internal audit teams reviewing IRM program, Privacy officers ensuring proper data handling, Compliance reporting for regulatory requirements, Executive oversight of insider threat program, External auditors assessing program controls ### Insider Risk Management Approvers URL: https://rbacmap.com/roles/insider-risk-6/ Privilege: Standard Description: Approve forensic evidence capturing requests to ensure legal and privacy compliance before evidence collection. Permissions: Request Review - Review forensic evidence capture requests, Approval Authority - Approve or deny evidence collection, Justification View - View justification for evidence requests, Scope Setting - Set parameters for evidence capture scope, Collection Monitoring - Monitor active evidence collection, History Audit - Audit forensic evidence capture history Use Cases: Legal counsel approving evidence collection, Privacy officers ensuring compliance with laws, Chief Compliance Officer authorizing sensitive captures, HR leadership approving employee monitoring ### Insider Risk Management Session Approvers URL: https://rbacmap.com/roles/insider-risk-7/ Privilege: Standard Description: Provides controlled approval and oversight of user session-based activities within Microsoft Purview Insider Risk Management, without granting access to investigations, alerts, cases, or sensitive content. Permissions: Insider Risk Management Sessions - Approve or deny session-based activity requests, Review session activity details for approval decisions, View session request metadata and justifications, CANNOT access alerts, cases, or investigation data, CANNOT view sensitive content or forensic evidence, CANNOT modify policies or settings Use Cases: Approving user session monitoring requests, Providing management oversight for session-based activities, Authorizing session captures for specific investigations, Maintaining separation of duties for session approval workflows ### IRM Contributors URL: https://rbacmap.com/roles/purview-irm-contributors/ Privilege: Standard Description: System role group. Visible in the Purview portal but used by background services only — do not assign users directly. Provides permissions that allow Insider Risk Management automation to function (permanent and temporary contributions to insider risk signals). Permissions: Insider Risk Management Permanent Contribution - Persistent IRM signal contributions, Insider Risk Management Temporary Contribution - Time-bound IRM signal contributions Use Cases: Internal Microsoft 365 service authentication for IRM features, Background processing of IRM signals from connected services, Automated risk score contributions ## Category: Data Loss Prevention ### DLP Compliance Management URL: https://rbacmap.com/roles/dlp-1/ Privilege: Standard Description: Create, configure, and manage Data Loss Prevention policies to prevent unauthorized sharing of sensitive information across Microsoft 365 and endpoints. Permissions: DLP Policies - Create and manage DLP policies across Exchange, SharePoint, OneDrive, Teams, Devices, Copilot DLP - Configure DLP policies for Microsoft 365 Copilot location, Policy Conditions - Configure policy conditions, actions, and user notifications, Sensitive Info Types - Manage sensitive information types and custom classifiers, Endpoint DLP - Configure Endpoint DLP settings and device onboarding, Fabric DLP - Configure DLP for Fabric and Power BI, Policy Matches - Review and manage DLP policy matches, Alert Dashboard - Access DLP alerts dashboard and management, Alert Configuration - Configure aggregate and single-event alerts, Reports - Access DLP reports and analytics, Policy Tips - Manage policy tips and user overrides, Administrative Units - Configure administrative units for scoped DLP management Use Cases: Preventing accidental sharing of credit card or SSN data, Blocking upload of confidential documents to unauthorized cloud services, Restricting Microsoft 365 Copilot from processing highly confidential files, Preventing paste of sensitive content into third-party AI sites (ChatGPT, etc.), Protecting intellectual property and trade secrets on corporate devices, Ensuring GDPR, HIPAA, or PCI-DSS compliance, Monitoring and controlling sensitive data on corporate devices, Preventing data loss via Teams, email, or removable devices, Protecting data in Fabric and Power BI workspaces ### Information Protection Admins URL: https://rbacmap.com/roles/dlp-3/ Privilege: Standard Description: Create and edit DLP policies, sensitivity labels, and auto-labeling rules without investigation access. Permissions: Create and configure DLP policies (Exchange, SharePoint, OneDrive, Teams, Copilot, Devices), Design and deploy sensitivity labels with encryption, marking, and protection settings, Configure auto-labeling policies with conditions and machine learning classifiers, Manage sensitive information types (built-in and custom), Configure trainable classifiers and exact data match (EDM) schemas, Configure label policy settings and scoped policies (users, groups, admin units), Manage Microsoft Purview Information Protection scanner configuration, Configure DLP policy tips, user notifications, and incident reports, Access configuration reports and Activity Explorer (view-only on events), Configure Endpoint DLP settings and device onboarding, Manage Copilot location policies to control AI access to sensitive files, Create DLP policies for Microsoft Fabric and Power BI Use Cases: Information protection specialists configuring policies and labels, Data governance team implementing classification taxonomy, Compliance engineers deploying protection controls across workloads, Separation between policy creation and alert investigation for governance, DLP administrators managing protection without viewing file content, Multinational teams using administrative units for regional policy scoping, Endpoint DLP specialists onboarding devices and configuring device policies, AI governance teams managing Copilot location restrictions for sensitive data ### Information Protection Analysts URL: https://rbacmap.com/roles/dlp-4/ Privilege: Standard Description: Access DLP alerts, activity explorer, and investigate incidents without policy modification rights. Permissions: View and triage DLP alerts (Exchange, SharePoint, OneDrive, Teams, Copilot, Devices), Access Activity Explorer to track file labeling and DLP policy match activities, Investigate DLP policy matches and aggregate alerts, Review user activities and data movement patterns, Generate investigation reports and export alert data, Classify and dismiss false positive alerts with justification, Access DLP reports and analytics dashboards, View sensitivity label application events and trends, Track Endpoint DLP device events and user justifications, Monitor Copilot location policy violations and AI access attempts, View policy match details without modifying policies, Access administrative units scoped alert data Use Cases: Security analysts monitoring data loss prevention events, Compliance team investigating potential policy violations, Data protection officers reviewing data movement patterns and trends, Incident response team triaging DLP alerts and escalating serious violations, SOC analysts tracking sensitive data exfiltration attempts, Risk management teams analyzing aggregate alert patterns, Endpoint DLP monitors reviewing device policy violations, AI governance teams tracking Copilot location policy enforcement ### Information Protection Investigators URL: https://rbacmap.com/roles/dlp-5/ Privilege: Standard Description: Access Content Explorer to view in-place rendering of DLP-matched files for deep investigation. Permissions: All Information Protection Analyst permissions (DLP alerts, Activity Explorer), Access Content Explorer to view actual file content in rendered format, View in-place rendering of documents (Word, Excel, PowerPoint, PDF), See classified and labeled file content across SharePoint, OneDrive, Exchange, Export evidence files and metadata for formal investigations, Review sensitive data in context of DLP policy matches, Search Content Explorer by sensitivity label or sensitive info type, View file properties, labels, and protection settings, Access content from administrative units if scoped, Filter content by location, label, sensitive info type, or user Use Cases: Investigating serious data exfiltration incidents and IP theft, Legal review of potential trade secret or confidential information leakage, Forensic analysis of suspected data breach or insider threat attempts, Confirming true versus false positive DLP policy matches before enforcement action, Regulatory compliance investigations requiring file content review, Insider Risk Management case investigations with file evidence, eDiscovery preview of classified documents before full legal hold, Sensitive data inventory and classification validation projects ## Category: Information Protection ### Information Protection URL: https://rbacmap.com/roles/dlp-2/ Privilege: Standard Description: Full control over all information protection features including DLP, sensitivity labels, and classification. Permissions: DLP Policies - All DLP policy creation and management (Exchange, SharePoint, OneDrive, Teams, Copilot, Devices), Sensitivity Labels - Create and configure sensitivity labels with encryption and marking, Auto-Labeling - Configure auto-labeling policies with machine learning classifiers, Trainable Classifiers - Manage trainable classifiers (custom and pre-built), Content Explorer - Access Content Explorer (view labeled file content), Activity Explorer - Access Activity Explorer (view labeling and DLP events), On-Premises Scanner - Configure Microsoft Purview Information Protection scanner for on-premises, Encryption - Manage encryption and Azure Rights Management templates, Label Policies - Configure label policy scoped to specific users, groups, or admin units, EDM Schemas - Create exact data match (EDM) and document fingerprinting schemas, Reports - Full access to information protection reports and analytics, Records Integration - Manage records management and retention labels integration Use Cases: Chief Information Security Officer with comprehensive oversight responsibility, Data Protection Officer managing full information protection compliance program, Information governance lead implementing enterprise-wide protection strategy, Senior compliance architect designing multi-layered protection framework, Security operations lead coordinating DLP, encryption, and classification, Privacy officer managing data protection and GDPR compliance, Enterprise architect integrating on-premises and cloud protection, Full-time information protection specialist role in large organizations ### Sensitivity Label Administrator URL: https://rbacmap.com/roles/info-prot-1/ Privilege: Standard Description: Create and manage sensitivity labels and their policies for document classification and protection. Permissions: Create and configure sensitivity labels, Manage label policies and scoping, Configure label encryption and marking settings, Set up auto-labeling conditions, Publish labels to users and groups, Monitor label adoption and usage Use Cases: Implementing data classification framework, Deploying labels for regulatory compliance (ITAR, CUI, PII), Enabling user-driven document protection, Supporting information governance programs ### Sensitivity Label Reader URL: https://rbacmap.com/roles/info-prot-2/ Privilege: Standard Description: View sensitivity labels and configurations with read-only access for auditing and compliance. Permissions: View sensitivity label configuration, Access label policies and scoping settings, Review label usage reports, View auto-labeling rules, Export label configuration for documentation Use Cases: External auditors reviewing classification program, Compliance reporting on label deployment, Management oversight of information protection, Consultants assessing label effectiveness ### Information Protection Readers URL: https://rbacmap.com/roles/info-prot-3/ Privilege: Standard Description: View-only access to information protection reports and analytics dashboards. Permissions: View information protection dashboards and analytics, Access DLP and sensitivity label reports, Review classification and protection trends and metrics, Export reports, charts, and aggregate data for leadership, View Activity Explorer data (read-only, no file content), Access information protection summary reports, Monitor DLP policy effectiveness and alert volumes, Review label application coverage and trends, View aggregate sensitive information type statistics Use Cases: Executive dashboards for information protection program oversight, Board reporting on data protection effectiveness and compliance metrics, Compliance metrics and trend analysis for audit and regulatory reporting, Program health monitoring and maturity assessment, Risk committee reporting on data protection posture, External audit support with read-only access to metrics, Business unit leaders monitoring their department's classification compliance ### Content Explorer List Viewer URL: https://rbacmap.com/roles/info-prot-4/ Privilege: Standard Description: View file metadata and classifications in list format without viewing actual file content. Permissions: View Content Explorer file listings, See file metadata (name, location, owner, size), View applied sensitivity labels, See sensitive information type matches, Filter and search classified content, Export file lists for reporting Use Cases: Auditing label application coverage, Identifying unlabeled sensitive files, Generating classification reports, Validating auto-labeling effectiveness ### Content Explorer Content Viewer URL: https://rbacmap.com/roles/info-prot-5/ Privilege: Standard Description: View actual contents of classified and labeled files for detailed classification verification. Permissions: All Content Explorer List Viewer permissions, View in-place rendering of file content, Read documents, emails, and files, Verify classification accuracy, Review sensitive content matches, Export evidence for compliance verification Use Cases: Verifying auto-labeling accuracy, Investigating classification errors, Confirming sensitive content matches, Auditing protection effectiveness, Training and tuning classification models ### Exact Data Match Upload Admins URL: https://rbacmap.com/roles/purview-edm-upload-admins/ Privilege: Standard Description: Upload data for Exact Data Match (EDM) classifiers. EDM classifiers detect sensitive information by matching against an uploaded data set (e.g., customer database, employee records) rather than pattern matching alone. Permissions: Exact Data Match Upload Admin - Upload sensitive data tables for EDM, Refresh EDM data sets, Configure EDM schema and rule packages, Run EDM upload diagnostic tools Use Cases: Initial EDM data set upload (e.g., customer records, employee data), Scheduled refresh of EDM data sets (e.g., daily customer database sync), Operating the EDM upload agent on Windows machines, Validating EDM uploads against expected row counts ## Category: DSPM (Classic) ### Data Security Management URL: https://rbacmap.com/roles/dspm-1/ Privilege: Standard Description: Comprehensive DSPM role with full access to insights, Security Copilot integration, and ability to manage DLP, Information Protection, and Insider Risk Management solutions. Permissions: View all Data Security Posture Management (DSPM) insights and analytics dashboards, Use Microsoft Security Copilot for Security in DSPM for AI-powered investigations, Access DSPM recommendations to create DLP and Insider Risk Management policies, Monitor unprotected sensitive data across Exchange, SharePoint, OneDrive, Teams, Track data security posture trends and analytics reports over time, Investigate data security risks using Copilot promptbooks and custom prompts, Create and manage DLP policies from DSPM recommendations, Create and manage Insider Risk Management policies from DSPM recommendations, Create Adaptive Protection policies to dynamically apply DLP based on user risk, Manage Information Protection labels and auto-labeling policies, Access Content Explorer to view classified and labeled file content, Review sensitivity label usage, DLP policy coverage, and risky user behavior trends, Configure analytics in Insider Risk Management and DLP for DSPM scanning, Full Information Protection Admin permissions (DLP, sensitivity labels, classifiers), Full Information Protection Analyst permissions (alerts, Activity Explorer), Full Information Protection Investigator permissions (Content Explorer), Full Insider Risk Management Admin permissions (policies, Adaptive Protection), Full Insider Risk Management Analysis permissions (alerts, cases, analytics), Full Insider Risk Management Approval permissions (forensic evidence approval), Full Insider Risk Management Audit permissions (audit log access), Full Insider Risk Management Investigation permissions (Content Explorer, forensic evidence), Includes all roles: Case Management, Custodian, Data Connector Admin, and more Use Cases: Chief Information Security Officer (CISO) with comprehensive data security oversight, Data Protection Officer (DPO) managing holistic data protection compliance program, Chief Compliance Officer orchestrating integrated data security strategy, Security Operations Center (SOC) lead coordinating data loss prevention and insider threat, Enterprise security architect implementing end-to-end data protection framework, Senior security analyst with Security Copilot access for AI-powered threat investigation, Regulatory compliance manager overseeing GDPR, HIPAA, PCI-DSS, SOX compliance, Insider threat program director managing behavioral analytics and Adaptive Protection, Information governance leader coordinating classification, DLP, and retention, Security consultant implementing comprehensive Microsoft Purview data security solutions ### Data Security Viewer URL: https://rbacmap.com/roles/dspm-2/ Privilege: Standard Description: Read-only access to DSPM dashboard insights, analytics, and Security Copilot for viewing data security posture without policy modification or investigation. Permissions: View Data Security Posture Management (DSPM) dashboard insights and reports, Use Microsoft Security Copilot for Security to view detailed DSPM information and AI-powered analysis, Access DSPM analytics trends showing sensitivity label usage and DLP policy coverage, View data security recommendations (cannot create policies), Review unprotected sensitive assets reports and risk visualization, Monitor risky user behavior trends and data movement patterns, Access DSPM reports on data security posture over time, View top data security risks and vulnerabilities across organization, Use Security Copilot promptbooks for read-only investigation and risk identification, Review sensitivity label application coverage and classification effectiveness, View DLP policy effectiveness metrics and gap analysis, Monitor Insider Risk Management alert volumes and trends, Access aggregate analytics without individual user investigation access Use Cases: Executive leadership monitoring overall data security posture for board reporting, Security managers generating compliance metrics and trend reports for leadership, Audit committee members reviewing data protection program effectiveness, External auditors assessing DSPM implementation and coverage during compliance reviews, Risk management teams monitoring organizational data security risk exposure, Compliance reporting specialists creating regulatory compliance documentation, Business unit leaders tracking data security metrics for their departments, Security consultants reviewing DSPM configuration and recommendations, Privacy officers monitoring data protection trends and unprotected asset reduction, Program managers tracking data security initiative progress and ROI, SOC analysts using Security Copilot for read-only threat intelligence without investigation, Internal auditors verifying data security controls and policy coverage, Management dashboards displaying real-time data security posture to stakeholders ### Data Security AI Viewer URL: https://rbacmap.com/roles/dspm-ai-1/ Privilege: Standard Description: Read-only access to DSPM for AI to monitor AI app usage, view insights into Copilot interactions, and track AI-related data security risks without viewing prompts/responses. Permissions: View Data Security Posture Management for AI dashboard and reports, Access Apps and agents page showing AI app usage across organization, View AI interaction reports: Copilot experiences, enterprise AI apps, third-party AI sites, Monitor sensitive interactions per generative AI app (ChatGPT, Gemini, etc.), View insider risk severity trends for AI usage, Access Activity Explorer for AI events (cannot view prompts/responses), View AI website visit events and sensitive info type detections, See data risk assessment results for SharePoint sites and Fabric workspaces, View completion status of AI recommendation cards (most cards), View policy list for DLP and Information Protection (excludes IRM and Comm Compliance), Access reports showing total AI interactions, visits, and sensitive data exposure, Monitor weekly data risk assessments for top 100 SharePoint sites, View AI app categories: Copilot experiences, enterprise AI apps, other AI apps, See supported third-party AI sites usage (ChatGPT, Gemini, Claude, etc.), Cannot view prompts/responses in AI interactions (requires AI Content Viewer), Cannot view user risk level or IRM details (requires IRM Analyst/Investigator) Use Cases: AI governance teams monitoring organizational AI adoption and usage patterns, Security managers tracking AI-related data security risks and sensitive data exposure, Compliance officers monitoring AI app usage for regulatory compliance (GDPR, HIPAA), Executive leadership viewing AI usage dashboards for board reporting, Risk management teams assessing AI-related data oversharing and security posture, External auditors reviewing AI governance program implementation, Privacy officers monitoring AI interactions with sensitive data, IT leadership tracking which AI apps (Copilot, ChatGPT, Gemini) are being used, Data protection officers monitoring data risk assessments for AI readiness, Business unit leaders understanding AI usage trends in their departments, Security consultants assessing AI security posture and policy coverage, Audit committee members reviewing AI data protection effectiveness ### Data Security AI Content Viewer URL: https://rbacmap.com/roles/dspm-ai-2/ Privilege: Standard Description: View AI interaction prompts and responses for investigation of data security incidents in Copilot, agents, and third-party AI apps. Permissions: All Data Security AI Viewer permissions (AI dashboard, reports, Activity Explorer), View prompts and responses within AI Interaction events in Activity Explorer, See actual user prompts sent to Microsoft 365 Copilot, agents, and third-party AI sites, View AI-generated responses containing potentially sensitive information, Investigate AI interactions for data leakage, sensitive data exposure, or policy violations, Access AI interaction details: user, timestamp, AI app, sensitive info types detected, View web queries and search terms used in AI interactions, See files referenced in AI prompts and responses, Monitor sensitive file references in Copilot and agent interactions, Investigate potential data exfiltration through AI prompts, View AI interactions across Copilot experiences, enterprise AI apps, other AI apps, Access Content Explorer Content Viewer permissions for AI interactions, View file details for data risk assessments (SharePoint, OneDrive, Fabric), Requires Content Explorer Content Viewer or List Viewer role for file context Use Cases: Security incident investigators examining potential data leakage through AI prompts, Data protection officers investigating suspected sensitive data exposure in Copilot, Insider threat investigators reviewing AI usage for potential intellectual property theft, Compliance investigators reviewing AI interactions for regulatory violations (GDPR, HIPAA), Legal team examining AI prompts/responses for litigation or employment investigations, Security Operations Center (SOC) analysts investigating AI-related security alerts, Privacy officers investigating potential PII exposure through AI interactions, Forensic analysts examining suspicious AI usage patterns and content, eDiscovery team collecting AI interaction evidence for legal matters, Data loss prevention investigators confirming true vs false positive AI alerts, Corporate security investigating trade secret or confidential data sharing via AI, Regulatory compliance investigators responding to data breach notifications ## Category: DSPM (Preview) ### DSPM Full Access (Preview) URL: https://rbacmap.com/roles/dspm-preview-admin/ Privilege: HIGH Description: [Preview] Full administrative access to the unified Data Security Posture Management. Complete setup tasks, create one-click policies, manage data security objectives, create data risk assessments, and configure AI observability. Requires Compliance Administrator or Purview Compliance Administrator role group — NOT the classic Data Security Management role group. Permissions: Setup Tasks - Complete one-click get started steps for DSPM enablement, Posture Dashboard - View key posture metrics, data snapshot, and posture trends chart, Objectives - View and interact with all data security objectives and remediation plans, Objective Actions - Complete actions on data security objective cards (remediation, policy creation), Recommendations - View all recommendations and complete actions on recommendation cards, One-Click Policies - Create DLP, sensitivity label, and Insider Risk policies from objectives, Data Risk Assessments - Create and view data risk assessments for oversharing prevention, AI Observability - View Apps and agents page showing AI app usage including Agent 365, Activity Explorer - View all events in Activity Explorer (AI activities and all activity types), Reports - View all graphs, policies, and reports from the Reports page, Risk Patterns - View risk patterns and data security posture trends, Policy List - View all policies (DLP, Information Protection, IRM, Communication Compliance), Remediation Actions - Identify and create automatic policies from remediation actions Use Cases: Chief Information Security Officer (CISO) managing holistic data security posture, Data Protection Officer configuring unified data security objectives, Chief Compliance Officer orchestrating one-click policy deployment across DSPM, Security architect implementing proactive risk management workflows, Compliance manager creating data risk assessments before Copilot deployment, Security operations lead configuring AI observability and agent governance, Regulatory compliance manager tracking data security posture for GDPR, HIPAA, PCI-DSS, Information governance leader implementing data security objectives across the estate ### DSPM Viewer (Preview) URL: https://rbacmap.com/roles/dspm-preview-viewer/ Privilege: Standard Description: [Preview] View-only access to the unified Data Security Posture Management dashboards, reports, objectives, and data risk assessments. Uses Security Reader role group — does NOT require classic Data Security Viewer role. Permissions: Posture Dashboard - View key posture metrics, data snapshot, and posture trends chart, Objectives - View all data security objectives and their current status, Remediation Plans - View remediation plan details and completion status for objectives, Recommendations - View all recommendation cards (cannot complete actions), Reports - View all graphs from the Reports page, Policy List - View DLP and Information Protection policies (excludes IRM and Comm Compliance policies), Activity Explorer - View events in Activity Explorer (AI activities and all activity types, excludes IRM events), Data Risk Assessments - View existing data risk assessments (cannot create), AI Observability - View Apps and agents page showing AI app usage, Risk Patterns - View risk patterns and posture trends, Setup Steps - View all getting started steps and their completion status (excludes Audit and Extend Insights status) Use Cases: Executive leadership monitoring organizational data security posture for reporting, Security managers generating compliance metrics and trend reports, Audit committee members reviewing data protection program effectiveness, External auditors assessing DSPM implementation during compliance reviews, Risk management teams monitoring data security risk exposure, Business unit leaders tracking data security metrics for their departments, Security consultants reviewing DSPM configuration and posture, Privacy officers monitoring data protection trends and policy coverage, SOC analysts monitoring DSPM dashboards without configuration access ### AI Administrator (DSPM) URL: https://rbacmap.com/roles/dspm-preview-ai-admin/ Privilege: Standard Description: [Preview] Entra ID role providing view-only access to AI-related data in DSPM (Preview) including AI observability, AI activities, AI objectives, and AI-related risk patterns. New role introduced with the unified DSPM experience. Permissions: AI Observability - View Apps and agents page showing AI app usage including Agent 365, AI Activities - View events in Activity Explorer AI activities tab, AI Objectives - View AI-related data security objectives (e.g., prevent exfiltration to AI apps), AI Reports - View AI-related graphs and metrics from the Reports page, AI Risk Patterns - View AI-related risk patterns and posture trends, Recommendations - View all recommendation cards including AI recommendations, Recommendation Status - View completion status of recommendation cards (excludes Unethical Behavior card), Data Risk Assessments - View existing data risk assessments, Setup Steps - View getting started step completion status (excludes Audit and Extend Insights), Policy List - Cannot view Information Protection policies (unlike Security Reader) Use Cases: AI governance teams monitoring organizational AI adoption and risk, AI Administrator designated by organization to oversee Copilot and third-party AI usage, Executive leadership tracking AI-related data security for board reporting, Privacy officers monitoring AI interactions with sensitive data at scale, IT leadership understanding which AI apps (Copilot, ChatGPT, Gemini) are being used, Risk management teams assessing AI-specific data oversharing risk, Security consultants evaluating AI security posture and policy coverage, Compliance officers monitoring AI app usage for regulatory requirements (GDPR, HIPAA) ### Data Security AI Admin (Preview) URL: https://rbacmap.com/roles/dspm-preview-ai-dlp/ Privilege: Standard Description: [Preview] Edit DLP policies related to Copilot and view AI content in the unified DSPM (Preview). Cannot read prompts and responses of AI interactions. Role group: Data Security AI Admins. Permissions: Copilot DLP - Edit Data Loss Prevention policies related to Copilot location, AI Content Viewing - View AI content in Data Security Posture Management (preview), AI Activity Explorer - View AI-related events in Activity Explorer, AI Observability - View Apps and agents page for AI app usage monitoring, AI Reports - View AI-related reports and metrics, AI Recommendations - View and act on AI-related recommendation cards, Data Risk Assessments - View data risk assessments for AI readiness, DLP Configuration - Manage DLP policies specifically for Copilot and AI workloads, Cannot Read Prompts - Does NOT have access to read prompts/responses of AI interactions Use Cases: Security engineers creating DLP policies specifically for Copilot interactions, Compliance team members managing AI-specific data loss prevention controls, AI governance teams needing to create DLP protections for AI apps without broader DLP access, Security administrators configuring Copilot DLP to prevent sensitive data in AI prompts, IT security staff implementing AI-specific data protection policies, Organizations wanting targeted DLP administration for AI workloads only ## Category: Privacy Management (Priva) ### Privacy Management Administrators URL: https://rbacmap.com/roles/priva-1/ Privilege: Standard Description: Full administrative access to Microsoft Priva features including Privacy Risk Management and Subject Rights Requests. Can configure policies, manage settings, and oversee all privacy management operations. Permissions: Create, read, update, and delete Privacy Risk Management policies, Configure privacy risk detection settings and thresholds, Manage subject rights request workflows and settings, Assign roles and permissions to other Priva users, Access all privacy risk insights, reports, and analytics, Configure data retention and deletion policies for SRRs, Manage case management for privacy incidents, View case details and investigation results (View-Only Case role), Configure notification templates and remediation actions, Access Privacy Management Admin permissions for full control, Manage Priva integrations with other Microsoft 365 services, Configure privacy assessment templates and workflows, Set up and manage privacy policies across the organization, Access audit logs for all Priva activities, Manage Teams collaboration channels for subject rights requests Use Cases: Setting up and configuring Microsoft Priva for the first time, Creating and managing privacy risk management policies (data transfers, data minimization, overexposure), Defining organizational privacy standards and compliance requirements, Managing subject rights request workflows and approval processes, Responding to GDPR, CCPA, and other privacy regulation requirements, Configuring automated privacy risk detection and remediation, Overseeing privacy incident response and case management, Establishing privacy governance frameworks, Managing privacy team roles and permissions, Coordinating cross-functional privacy compliance initiatives, Integrating Priva with Microsoft Purview Compliance Manager, Setting up privacy assessments for new data processing activities ### Privacy Management Analysts URL: https://rbacmap.com/roles/priva-2/ Privilege: Standard Description: Investigate privacy policy matches and view file metadata without accessing file content. Can take remediation actions and manage privacy risk cases. Ideal for privacy analysts who need to triage privacy risks without viewing sensitive content. Permissions: Investigate Privacy Risk Management policy matches, View file metadata (name, location, owner, sensitivity label, last modified), View Data Classification List (metadata only - no content access), Take remediation actions on privacy policy matches, View privacy risk insights and analytics, Access case management for privacy incidents (Case Management role), View-Only Case access to review investigation results, Apply tags and classifications to privacy policy matches, Create and manage privacy incident cases, Export metadata reports for privacy compliance, View policy match statistics and trends, Access Privacy Risk Management dashboards and reports, Notify users about privacy policy violations, Recommend policy adjustments based on investigation findings, CANNOT view or access file content (no Data Classification Content Viewer) Use Cases: Triaging privacy policy matches for potential risks, Investigating data transfer violations (cross-border, departmental), Analyzing data minimization policy matches, Reviewing data overexposure incidents, Creating privacy incident cases for escalation, Generating privacy compliance reports with file metadata, Monitoring privacy risk trends and patterns, Taking initial remediation actions (notifications, policy tuning), Coordinating with data owners on privacy risk mitigation, Escalating high-risk privacy issues to Investigators or Admins, Reviewing sensitivity label compliance without content access, Conducting first-level privacy risk assessments, Managing privacy incident workflow and case tracking ### Privacy Management Investigators URL: https://rbacmap.com/roles/priva-3/ Privilege: Standard Description: Full investigative access to privacy policy matches including file content review. Can investigate privacy incidents, view associated file content, and take comprehensive remediation actions. Reserved for senior privacy investigators. Permissions: Investigate Privacy Risk Management policy matches with full context, View file content for privacy policy matches (Data Classification Content Viewer), View file metadata including name, location, owner, sensitivity label, View Data Classification List for metadata analysis, Access case management for privacy incidents (Case Management role), View-Only Case access to review investigation results, Take comprehensive remediation actions on privacy violations, Review actual file content to determine privacy risk severity, Export file content for privacy compliance documentation, Apply tags and classifications to investigated content, Create detailed privacy incident reports with content evidence, Access Privacy Risk Management insights and analytics, Notify users and data owners about privacy violations, Coordinate with legal on privacy incident response, Recommend policy changes based on content-level investigations, Preserve evidence for privacy breach investigations Use Cases: Investigating high-severity privacy policy violations requiring content review, Reviewing actual file content for GDPR Article 30 compliance, Conducting privacy breach investigations with content evidence, Analyzing data transfer violations with full document context, Investigating data minimization failures by reviewing content, Responding to data subject complaints about privacy violations, Documenting privacy incidents with content-level evidence, Conducting forensic privacy investigations for regulatory inquiries, Reviewing sensitive data overexposure with content access, Coordinating with legal counsel on privacy breach response, Preparing privacy incident reports for regulatory authorities, Investigating cross-border data transfer compliance, Validating privacy policy accuracy through content sampling, Conducting privacy impact assessments with content review ### Privacy Management Viewer URL: https://rbacmap.com/roles/priva-4/ Privilege: Standard Description: Read-only access to privacy analytics, reports, insights, and policy trends. Can view privacy risk dashboards and compliance metrics without investigative or administrative capabilities. Ideal for privacy stakeholders who need visibility into privacy posture. Permissions: View Privacy Risk Management reports and dashboards, Access privacy risk insights and analytics, View privacy policy trend analysis, Review privacy risk scores and compliance metrics, Access Subject Rights Request summary statistics, View privacy incident case summaries (no investigation access), Review privacy policy configuration (read-only), View privacy risk detection thresholds and settings, Access privacy compliance reports for executive review, View privacy risk management historical trends, Review privacy policy match statistics, Access privacy program maturity metrics, View subject rights request processing times and volumes, CANNOT investigate policy matches or access files, CANNOT modify privacy policies or settings, CANNOT take remediation actions or create cases Use Cases: Executive leadership monitoring organizational privacy posture, Board members reviewing privacy compliance metrics, Regional compliance officers viewing privacy trends, Auditors reviewing privacy program effectiveness, Privacy steering committee members accessing privacy dashboards, Legal counsel monitoring privacy risk exposure, Chief Information Security Officer (CISO) reviewing privacy metrics, Chief Privacy Officer (CPO) presenting privacy reports to stakeholders, Compliance team members tracking privacy program maturity, Risk management teams assessing privacy-related risks, Data protection officers in observer roles, Third-party privacy assessors conducting compliance reviews ### Subject Rights Request Administrators URL: https://rbacmap.com/roles/priva-5/ Privilege: Standard Description: Full administrative rights to create and manage subject rights requests (SRRs). Can handle GDPR, CCPA, and other privacy regulation requests including access, export, tagged list, and delete requests. Can add approvers and manage entire SRR lifecycle. Permissions: Create new subject rights requests (access, export, tagged list, delete), Manage all subject rights requests across the organization, Add approvers for subject rights requests, Configure SRR search settings and data source scopes, Review and approve data collected by subject rights requests, Mark files as included/excluded for export or deletion, Generate data packages for data subjects, Export file content for subject rights request responses, Manage delete requests and approve deletion workflows, Add collaborators to subject rights requests, Create and manage Teams collaboration channels for SRRs, Configure subject rights request templates, Set data retention limits for SRR data, Generate audit logs and compliance reports for SRRs, Close and archive completed subject rights requests, Tag files during data review for follow-up actions, Annotate and redact files for data subject responses, Manage SRR workflows from creation to completion Use Cases: Responding to GDPR Article 15 data subject access requests (DSARs), Processing CCPA consumer rights requests, Handling "right to be forgotten" deletion requests under GDPR Article 17, Fulfilling "right to data portability" export requests, Managing subject rights requests for PIPEDA (Canada) compliance, Coordinating cross-functional SRR response with legal, IT, HR, Creating subject rights request workflows and templates, Reviewing and approving data collected for SRR responses, Generating data packages for data subject delivery, Managing delete request approvals and execution, Collaborating with legal counsel on complex SRRs, Tracking SRR processing times for regulatory compliance, Preparing SRR documentation for regulatory audits, Handling escalated or high-risk subject rights requests ### Subject Rights Request Approvers URL: https://rbacmap.com/roles/priva-6/ Privilege: Standard Description: Can approve subject rights requests to which they are added as an approver. Typically used for approving delete requests or other high-risk SRRs requiring secondary authorization. Provides approval gate for sensitive SRR operations. Permissions: Approve or reject subject rights requests assigned to them, Review subject rights request details before approval, View data collection scope and search criteria for SRRs, Review files marked for deletion in delete requests, Provide approval for export package generation, Add approval comments and justifications, View SRR workflow status and timeline, Receive notifications when added as approver to SRR, Review data subject information for identity verification, Access SRR audit trail and activity history, CANNOT create new subject rights requests, CANNOT modify SRR settings or configurations, CANNOT add/remove other approvers, CANNOT execute deletions (only approve) Use Cases: Approving GDPR Article 17 "right to be forgotten" delete requests, Authorizing deletion of employee data after termination, Reviewing high-risk subject rights requests before fulfillment, Approving export requests containing sensitive business data, Providing legal counsel approval for complex SRRs, Authorizing cross-border data transfer requests, Approving SRRs that may impact ongoing litigation, Reviewing delete requests for regulatory compliance, Providing HR approval for employee data deletion, Authorizing SRRs involving executive or board member data, Approving SRRs requiring multiple stakeholder coordination, Reviewing tagged list requests for follow-up actions ### Privacy Management Contributors URL: https://rbacmap.com/roles/priva-7/ Privilege: Standard Description: Manage contributor access for privacy management cases in Microsoft Priva. Can perform compliance searches, work with custodian data, export data, and manage review set tags. Cannot configure policies or view content details. Permissions: Compliance Manager Contribution - Perform work to implement improvement actions, Compliance Manager Reader - View all Compliance Manager content, Compliance Search - Perform compliance content searches, Custodian - Manage custodian data for privacy cases, Data Map Reader - Read data map objects, Export - Export search and review set data, Manage Review Set Tags - Create, edit, delete review set tags, Preview - View list of items from content searches, Privacy Management Permanent contribution - Permanent contributor access, Privacy Management Temporary contribution - Temporary contributor access, Review - Access review sets and case data Use Cases: Contributing to subject rights request fulfillment workflows, Performing compliance searches for privacy cases, Exporting data packages for privacy request responses, Managing review set tags for case organization, Supporting privacy investigations with custodian data management ### Privacy Management URL: https://rbacmap.com/roles/purview-privacy-mgmt/ Privilege: HIGH Description: Top-level role group for the Privacy Management (Priva) solution in Microsoft Purview. Manages access control for the entire Privacy Management portal experience — distinct from the more scoped Privacy Management Administrators role group. Permissions: Case Management - Privacy case lifecycle management, Compliance Manager Contribution / Reader - Privacy assessments in Compliance Manager, Compliance Search - Search content for privacy investigations, Custodian - Manage data custodians for privacy investigations, Data Classification Content Viewer - View classified privacy-sensitive content, DLP Compliance Management - Manage privacy-related DLP policies, Information Protection Admin - Manage sensitivity labels with privacy implications, Manage Alerts - Privacy alert triage, Subject Rights Request (DSR) management, Privacy Risk Management policy administration Use Cases: GDPR, CCPA, LGPD privacy program administration, Subject Rights Request (DSR/DSAR) fulfillment program, Privacy risk identification and remediation, Privacy by design program ownership, Coordinating privacy work across compliance, legal, and IT teams ## Category: Data Security Investigations ### Data Security Investigations Administrators URL: https://rbacmap.com/roles/dsi-1/ Privilege: Standard Description: [Preview] Full administrative access to Data Security Investigations. Create and manage all investigations, configure settings, run searches, and coordinate data security incident response. Permissions: Create and manage all investigations (organization-wide), Create searches and add items to investigations, Estimate and preview search results across data sources, Manage investigation scope and parameters, Add, delete, and manage items for mitigation plans, Run categorization activities on investigated data, Run examination activities for detailed data analysis, Run vector searches for AI-powered investigation, View and interact with data risk graphs, Configure Data Security Investigations settings and workflows, Assign investigations to other investigators and reviewers, Export investigation results and evidence, Access case management capabilities, Use compliance search across Exchange, SharePoint, OneDrive, Teams, Preview file content and communications in search results Use Cases: Chief Information Security Officer (CISO) overseeing data security incident investigations, Security Operations Center (SOC) manager coordinating investigation workflows, Data security team lead managing multiple concurrent investigations, Incident response coordinator triaging and assigning data security incidents, Senior security analyst conducting complex multi-source data investigations, Compliance officer investigating potential data breaches or exfiltration, Privacy officer investigating unauthorized data access incidents, Forensic analyst conducting detailed examination of data security events, Security architect designing investigation processes and mitigation strategies, Data protection officer coordinating response to regulatory inquiries ### Data Security Investigations Investigators URL: https://rbacmap.com/roles/dsi-2/ Privilege: Standard Description: [Preview] Conduct assigned data security investigations. Create searches, analyze results, manage investigation scope, and develop mitigation plans for assigned cases. Permissions: Create and manage assigned investigations only (not all investigations), Create searches and add items to assigned investigations, Estimate and preview search results for assigned investigations, Manage investigation scope for assigned cases, Add, delete, and manage items for mitigation plans, Run categorization activities on investigated data, Run examination activities for detailed data analysis, Run vector searches for AI-powered investigation, View and interact with data risk graphs, Export investigation results and evidence for assigned cases, Access case management capabilities for assigned investigations, Use compliance search within assigned investigation scope, Preview file content and communications in search results, Collaborate with administrators and reviewers on investigations Use Cases: Security analyst investigating assigned data security incidents, Incident response specialist conducting detailed forensic analysis, Compliance analyst investigating potential data breach or exfiltration, Data protection analyst examining unauthorized access events, SOC analyst responding to data security alerts and creating investigations, Security operations engineer performing root cause analysis, Threat intelligence analyst investigating data-related threats, Privacy analyst investigating privacy incident reports, Regional security coordinator managing investigations for business unit, Information security specialist conducting targeted data investigations ### Data Security Investigations Reviewers URL: https://rbacmap.com/roles/dsi-3/ Privilege: Standard Description: [Preview] Review and analyze assigned data security investigations. Manage investigation scope, run analysis activities, view data risk graphs, and contribute to mitigation plans without search/preview capabilities. Permissions: View and manage investigation scope for assigned investigations, Add, delete, and manage items for mitigation plans, Run categorization activities on investigated data, Run examination activities for data analysis, Run vector searches for pattern identification, View and interact with data risk graphs, Export investigation results for assigned cases, Access case details and investigation metadata, Collaborate on mitigation plan development, Review investigation findings and analysis, No ability to create searches or preview file content, No ability to create new investigations Use Cases: Security manager reviewing investigation findings and progress, Compliance officer assessing investigation outcomes for regulatory reporting, Privacy officer reviewing data access investigations for privacy implications, Risk management analyst evaluating data security incident impact, Executive stakeholder monitoring high-priority investigation status, Legal counsel reviewing investigation scope and methodology, Audit committee member assessing investigation processes, Business unit leader reviewing investigations affecting their department, External auditor validating data security investigation controls, Consultant providing specialized analysis without search permissions ## Category: Tenant-Level Governance ### Purview Administrators URL: https://rbacmap.com/roles/gov-purview-admin/ Privilege: Standard Description: Tenant-level role group to create, edit, and delete domains and perform role assignments across the Microsoft Purview account. Permissions: Create, edit, and delete domains in Microsoft Purview Data Map, Perform role assignments at the tenant/organizational level, Manage Microsoft Purview account-level settings and configurations, Delegate access and permissions across the entire Purview instance, Configure tenant-wide data governance policies and standards, Manage integration with Azure services and other Microsoft 365 solutions, Oversee collection and domain hierarchy structure organization-wide Use Cases: Initial Microsoft Purview account setup and configuration, Creating organizational domain structure for data governance, Assigning Collection Administrators and Domain Admins to business units, Managing tenant-wide governance policies and compliance standards, Coordinating data governance strategy across multiple departments, Emergency access when Collection Administrators are unavailable, Merging multiple Microsoft Purview accounts into unified structure, Implementing organization-wide data cataloging and discovery strategy ### Data Governance (role group) URL: https://rbacmap.com/roles/gov-data-governance/ Privilege: Standard Description: Tenant-level role group that grants access to data governance roles and delegates permissions for Governance Domain Creators in Unified Catalog. Permissions: Grants access to assign data governance roles within Microsoft Purview, Enables delegation of Governance Domain Creator role in Unified Catalog, Provides foundation for catalog-level permission management, Required prerequisite for assigning catalog-level roles, Access to Unified Catalog role and permission management, Ability to configure governance domain structures and hierarchies Use Cases: Enabling data governance administrators to assign Unified Catalog roles, Delegating Governance Domain Creator permissions to business units, Setting up federated data governance model across organization, Managing Unified Catalog role assignments for data stewards, Implementing data governance hierarchy and domain structure, Coordinating between IT governance and business domain ownership ### Data Source Administrators (role group) URL: https://rbacmap.com/roles/gov-data-source-admin-tenant/ Privilege: Standard Description: Tenant-level role group to manage data sources and scans across Microsoft Purview Data Map, including registration, scanning, and integration runtime management. Permissions: Register and manage data sources across all collections in Data Map, Create and manage scans for Azure, on-premises, and multi-cloud data sources, Configure and manage self-hosted integration runtimes (SHIR), Manage scan rule sets and classification rules, Configure managed private endpoints for secure data access, Set up Azure Integration Runtime and Managed Virtual Network Integration Runtime, Manage data source credentials and authentication methods in Azure Key Vault, Monitor scan status and troubleshoot scanning issues organization-wide Use Cases: Registering Azure SQL, Storage, Synapse, Fabric, and other Azure data sources, Scanning on-premises SQL Server, Oracle, Teradata via self-hosted integration runtime, Configuring multi-cloud data sources (AWS S3, Google BigQuery), Setting up automated scanning schedules for data discovery, Implementing classification and sensitivity labeling through scans, Managing integration runtimes for secure data source connectivity, Troubleshooting scan failures and connectivity issues, Implementing metadata extraction across hybrid data estates ### Data Catalog Curators URL: https://rbacmap.com/roles/gov-data-catalog-curators/ Privilege: Standard Description: Tenant-level role group to perform create, read, modify, and delete actions on catalog data objects and establish relationships between objects in the classic Data Catalog. Permissions: Create, read, modify, and delete catalog data objects across all collections, Establish relationships between objects in the classic Data Catalog, Manage business glossary terms and definitions organization-wide, Apply and manage classifications on assets across the entire catalog, Configure custom classifications and classification rules, Curate metadata and annotations across all data sources, Access Data Map Reader and Writer capabilities, Manage asset lineage and data relationships Use Cases: Enterprise-wide data stewardship and metadata management, Building organization-wide business glossaries and taxonomies, Cross-domain data classification and governance standardization, Centralized metadata curation for large data estates, Implementing consistent data governance practices across business units, Managing enterprise data catalog for self-service analytics ### Data Estate Insights Readers URL: https://rbacmap.com/roles/gov-data-estate-insights-readers/ Privilege: Standard Description: Tenant-level role group providing read-only access to all insights reports across platforms and providers in the classic Data Catalog. Permissions: View all Data Estate Insights reports organization-wide, Access insights across all platforms and data providers, View asset distribution and classification analytics, Access sensitivity labeling reports and coverage metrics, View scan history and metadata ingestion statistics, Access glossary term usage and adoption insights, Read Data Map objects and metadata, Export insights reports for governance reporting Use Cases: Executive dashboards for data governance program health, Board and audit committee reporting on data estate posture, Compliance reporting on classification and labeling coverage, Management visibility into catalog adoption and usage, External auditors reviewing data governance maturity, Data governance program metrics and KPI tracking ### Data Estate Insights Admins URL: https://rbacmap.com/roles/gov-data-estate-insights-admins/ Privilege: Standard Description: Tenant-level role group providing admin access to all insights reports across platforms and providers in the classic Data Catalog. Permissions: Full administrative access to Data Estate Insights, Configure insights reports and dashboard settings, Manage insights across all platforms and data providers, Create custom insights reports and analytics, Configure insights data retention and refresh schedules, Manage insights access and sharing settings, All Data Estate Insights Readers permissions, Read Data Map objects and metadata Use Cases: Configuring enterprise-wide data governance dashboards, Setting up automated insights reporting for stakeholders, Customizing insights views for different audiences, Managing insights infrastructure and performance, Building custom analytics on data estate health, Integrating insights with external reporting tools ## Category: Data Map Collections ### Domain Admin URL: https://rbacmap.com/roles/gov-domain-admin/ Privilege: Standard Description: Domain-level role to assign permissions within a domain and manage its resources, collections, and role assignments. Permissions: Assign permissions within a specific domain, Manage domain resources including collections and data sources, Create and manage collections within the domain, Assign Collection Admins, Data Curators, Data Readers within domain, Register and manage data sources within domain scope, Configure domain-level access controls and permission inheritance, Manage domain metadata and organizational structure Use Cases: Managing data governance for specific business unit or department domain, Delegating collection administration to regional or functional teams, Implementing domain-specific data classification and tagging standards, Coordinating data source registration for business unit data estate, Managing access control for division-specific data assets, Aligning data governance with organizational structure (Finance, HR, Sales domains) ### Collection Administrator URL: https://rbacmap.com/roles/gov-collection-admin/ Privilege: Standard Description: Manage collections, assign roles, and organize data sources and assets within collection hierarchy. Permissions: Create, edit, and delete collections and subcollections, Assign users to roles within managed collections (Collection Admin, Data Curator, Data Reader, Data Source Admin), Manage collection details, descriptions, and organizational structure, Configure permission inheritance for subcollections, Organize data sources and assets into collection hierarchy, Manage collection-level access controls and restrictions Use Cases: Organizing data assets by business function, geography, or project, Delegating data governance responsibilities to regional or functional teams, Implementing least-privilege access control through collection structure, Managing access to data assets for specific departments or initiatives, Creating project-specific collections for temporary data governance needs, Aligning data catalog structure with organizational hierarchy ### Data Curator URL: https://rbacmap.com/roles/gov-data-curator/ Privilege: Standard Description: Manage assets, create classifications, build glossary terms, and curate data catalog metadata for improved discoverability and understanding. Permissions: Create, read, modify, move, and delete data assets in collections, Configure custom classifications and classification rules, Create and manage business glossary terms and relationships, Apply annotations, descriptions, and metadata to assets, Curate and certify data assets for quality assurance, View Data Estate Insights and analytics, Manage asset lineage and relationships, Apply sensitivity labels and classifications to assets, Create and edit asset schemas and column-level metadata, Manage asset ownership and expert contacts Use Cases: Building business glossary with standardized terminology and definitions, Classifying data assets with PII, financial, or confidential tags, Enriching asset metadata with business context and descriptions, Certifying trusted data assets for analytical use, Creating data lineage documentation for impact analysis, Managing data quality annotations and trusted data sources, Coordinating with data owners to capture institutional knowledge, Implementing data governance policies through metadata enrichment ### Data Reader URL: https://rbacmap.com/roles/gov-data-reader/ Privilege: Standard Description: Read-only access to data assets, classifications, glossary terms, and collections for data discovery and search. Permissions: Search and browse data assets in assigned collections, View asset metadata, descriptions, and business context, Read classifications and sensitivity labels on assets, Access business glossary terms and definitions, View data lineage and asset relationships, Read collection metadata and organizational structure, View asset ownership and expert contact information, Search for assets using filters, tags, and classifications Use Cases: Data analysts discovering datasets for analytical projects, Business users finding data assets relevant to their work, Compliance teams auditing data classification and governance, Data scientists exploring available data for machine learning, Developers identifying data sources for application integration, Business intelligence teams discovering trusted data assets, External auditors reviewing data governance implementation ### Data Source Administrator URL: https://rbacmap.com/roles/gov-data-source-admin/ Privilege: Standard Description: Manage data sources and scans within assigned collections, including registration, scanning, and credential management. Permissions: Register data sources in assigned collections, Create and manage scans for registered data sources, Run scans using existing scan rules, Configure scan schedules and triggers, Manage scan credentials and authentication methods, Monitor scan status and history, Create new scan rules (requires Data Reader or Data Curator role), Manage self-hosted integration runtime connections, Publish data access policies (when combined with Policy Author role) Use Cases: Registering departmental data sources for metadata discovery, Configuring automated scan schedules for data freshness, Managing credentials for data source connectivity, Troubleshooting scan failures and connectivity issues, Implementing scanning for new data sources as they are deployed, Coordinating with IT on network access and firewall rules, Managing service principal or managed identity authentication ### Insights Reader URL: https://rbacmap.com/roles/gov-insights-reader/ Privilege: Standard Description: Read-only access to Data Estate Insights reports and analytics for collections where also assigned Data Reader role. Permissions: View Data Estate Insights reports for assigned collections, Access asset distribution and classification analytics, View scan history and metadata ingestion statistics, Read sensitivity labeling reports and coverage metrics, Access glossary term usage and adoption insights, View data source and scan performance metrics Use Cases: Data governance teams monitoring catalog health and coverage, Management reviewing data classification and labeling progress, Compliance teams assessing sensitivity label application rates, Data stewards tracking glossary term adoption, IT teams monitoring scan performance and success rates, Executives reviewing data governance program maturity ### Policy Author URL: https://rbacmap.com/roles/gov-policy-author/ Privilege: Standard Description: Create, view, update, and delete data access policies through Microsoft Purview Data Policy feature for Azure data sources. Permissions: Create data owner policies for Azure SQL, Storage, and other supported sources, View and update existing data access policies, Delete policies that are no longer needed, Configure policy subjects (users, groups, service principals), Define policy access permissions (Read, Modify), Manage policy scope (resource group, subscription, specific assets), Publish policies (requires Data Source Administrator role) Use Cases: Implementing centralized access management for Azure data sources, Creating self-service data access policies for governed data products, Managing permissions for Azure SQL, ADLS Gen2, Azure Storage accounts, Delegating access provisioning from resource owners to data governance team, Implementing data mesh access patterns with federated policy authoring, Temporarily granting access for projects without changing Azure RBAC ### Workflow Administrator URL: https://rbacmap.com/roles/gov-workflow-admin/ Privilege: Standard Description: Access workflow authoring page in Microsoft Purview governance portal and publish workflows on collections where they have access permissions. Permissions: Access the workflow authoring page in Microsoft Purview governance portal, Create and configure approval workflows for data governance processes, Publish workflows on collections where they have access permissions, Design workflow logic and approval chains, Configure workflow triggers and conditions, Manage workflow templates and reusable components, Monitor workflow execution and status Use Cases: Creating approval workflows for data access requests, Building workflows for glossary term approval processes, Configuring classification change approval workflows, Setting up data product publication approval chains, Automating data stewardship tasks and approvals, Implementing governance checkpoints for sensitive data changes, Creating self-service data request workflows ## Category: Unified Catalog Governance ### Data Governance Administrator URL: https://rbacmap.com/roles/gov-data-governance-admin/ Privilege: Standard Description: Catalog-level role that delegates first level of access for Governance Domain Creators and other catalog permissions. Permissions: Delegate Governance Domain Creator role to users, Assign other catalog-level permissions (Data Health Owner, Global Catalog Reader), Manage Unified Catalog solution settings, Configure roles and permissions for Unified Catalog, Oversee catalog-level governance across all domains Use Cases: Chief Data Officer or Data Governance Director managing catalog strategy, Assigning Governance Domain Creator role to business unit leaders, Managing catalog-level permissions and role assignments, Overseeing federated governance implementation, Configuring catalog settings and solution integrations ### Governance Domain Creator URL: https://rbacmap.com/roles/gov-governance-domain-creator/ Privilege: Standard Description: Create governance domains and delegate governance domain owner role (or remain owner by default). Permissions: Create new governance domains in Unified Catalog, Delegate Governance Domain Owner role to domain experts, Remain as Governance Domain Owner by default if not delegated, Define domain scope and boundaries, Set up initial domain structure and hierarchy Use Cases: Business unit leaders creating domains for their areas (Sales, Marketing, Finance), Data platform teams establishing technical domains (Customer Data, Product Data), Setting up federated governance structure aligned to organizational structure, Creating domains for regulatory or compliance boundaries (GDPR, HIPAA data), Establishing data mesh architecture with domain-oriented governance ### Global Catalog Reader URL: https://rbacmap.com/roles/gov-global-catalog-reader/ Privilege: Standard Description: Read published artifacts across all governance domains that don't have Local Catalog Reader restrictions. Permissions: Search and browse published data products across all domains, View published glossary terms and business concepts, Search Unified Catalog for data assets with proper Data Map permissions, Request access to data products, View data product metadata and descriptions, Discover business-curated data across organization Use Cases: Business analysts discovering data products for analytics, Data scientists finding training datasets across organization, Business users searching for data to meet reporting needs, Executives browsing available data assets for decision-making, Cross-functional teams discovering data products from other departments, New employees understanding organizational data landscape ### Data Health Owner URL: https://rbacmap.com/roles/gov-data-health-owner/ Privilege: Standard Description: Create, update, and read artifacts in Data Estate Health management area of Unified Catalog. Permissions: Create custom data health reports and dashboards, Configure data quality monitoring and alerts, Update data health management settings, Access full Data Estate Health explorer view, Create data observability configurations, Manage data health insights and recommendations Use Cases: Data governance teams building custom health dashboards, Creating executive reports on data quality and catalog health, Setting up automated data quality monitoring and alerts, Configuring data observability across data estate, Building reports to track catalog adoption and maturity, Developing custom metrics for data governance KPIs ### Data Health Reader URL: https://rbacmap.com/roles/gov-data-health-reader/ Privilege: Standard Description: Read artifacts in Data Estate Health management area of Unified Catalog. Permissions: View data health reports and dashboards, Access Data Estate Health explorer view (read-only), View data quality insights and metrics, Review data observability findings, Access catalog health and maturity reports, View data health trends and analytics Use Cases: Executives reviewing data governance program health, Management dashboards and reporting, Stakeholders monitoring catalog quality trends, External auditors reviewing data governance maturity, Business unit leaders tracking their domain health, Compliance officers assessing data quality compliance ### Governance Domain Owner URL: https://rbacmap.com/roles/gov-governance-domain-owner/ Privilege: Standard Description: Delegate all governance domain permissions, configure data quality alerts, set schedules, and manage access policies. Permissions: Delegate all governance domain roles (Data Product Owner, Data Steward, etc.), Configure domain-level data quality scan alerts, Set up domain-level schedule for data quality scanning jobs, Set domain-level access policies, Manage domain settings and configuration, Oversee all data products and assets within domain, Full administrative control within assigned domain Use Cases: VP of Sales owning Sales data governance domain, Finance Director managing Finance domain, Chief Marketing Officer overseeing Marketing domain, Product leadership governing Product domain, Domain architects managing data mesh domains, Establishing federated governance with clear ownership ### Data Product Owner URL: https://rbacmap.com/roles/gov-data-product-owner/ Privilege: Standard Description: Create, update, and read data products within governance domain. Build relationships with concepts across domains. Permissions: Create data products within assigned governance domain, Add data assets to data products (requires Data Map permissions), Update data product metadata, descriptions, and documentation, Build relationships between data products and glossary terms, Configure data product access policies, Publish data products for catalog users, Read and reference concepts from other governance domains Use Cases: Product manager curating Customer 360 data product, Analytics lead creating Sales Performance data product, Data engineer building Customer Churn Prediction dataset product, Business analyst assembling Marketing Campaign Analytics product, Data scientist creating ML Training Data product, Domain team packaging business-ready data for consumers ### Data Steward URL: https://rbacmap.com/roles/gov-data-steward/ Privilege: Standard Description: Create, update, and read artifacts and policies within governance domain. Read artifacts from other domains. Permissions: Create and manage glossary terms within domain, Create and update critical data elements (CDEs), Define business objectives and key results (OKRs), Manage data products and their metadata, Configure access policies within domain, Read and reference artifacts from other governance domains, Curate business metadata and documentation Use Cases: Business glossary curator maintaining terminology standards, Data governance analyst defining critical data elements, Domain SME documenting business concepts and definitions, Metadata specialist enriching data product documentation, Business analyst creating domain-specific glossaries, Data steward coordinating definitions across business units ### Governance Domain Reader URL: https://rbacmap.com/roles/gov-governance-domain-reader/ Privilege: Standard Description: Read governance domain metadata for published domains they are added to. Permissions: View published and draft metadata within assigned domain, Access unpublished data products and concepts, View domain configuration and settings (read-only), See all domain content including work-in-progress, Required base role for data quality and profile sub-roles Use Cases: Domain team members who need visibility into work-in-progress, Quality assurance reviewers validating domain content, Base role for data profile and quality reader roles, Contributors who need domain visibility without edit permissions, External consultants reviewing domain structure, Auditors assessing domain governance implementation ### Local Catalog Reader URL: https://rbacmap.com/roles/gov-local-catalog-reader/ Privilege: Standard Description: Read published concepts only in assigned governance domain. Limits federated access for regulatory requirements. Permissions: View published data products in assigned domain only, Access published glossary terms within domain, Search and discover data within domain boundaries, Request access to data products in assigned domain, Blocked from viewing other domains unless explicitly granted access Use Cases: Regulatory isolation for HIPAA, GDPR, or other compliance domains, Highly confidential domains requiring access restrictions, Geographic data residency requirements, Third-party contractors with limited scope access, Vendor access to specific domain only, Legal or compliance domains with confidentiality requirements ### Data Quality Steward URL: https://rbacmap.com/roles/gov-data-quality-steward/ Privilege: Standard Description: Manage data quality rules, scanning, insights, scheduling, monitoring, and alerts. Sub-role requiring Governance Domain Reader and Data Product Owner. Permissions: Create and manage data quality rules, Run data quality scanning jobs, Browse all data quality insights and error records, Configure data quality scheduling and automation, Monitor data quality job execution, Configure data quality thresholds and alerts, Remediate data quality issues, Export data quality reports Use Cases: Data quality engineers implementing quality rules for domain, Domain teams ensuring data products meet quality standards, Setting up automated data quality monitoring and alerts, Responding to data quality degradation and incidents, Implementing data quality SLAs and metrics, Root cause analysis of data quality issues ### Data Quality Reader URL: https://rbacmap.com/roles/gov-data-quality-reader/ Privilege: Standard Description: Browse all data quality insights and rules. Sub-role requiring Governance Domain Reader and catalog reader role. Permissions: Browse all data quality insights (except column-level profiling), View data quality rule definitions, Access data quality scores and trends, View quality issue summaries, Cannot run scanning jobs or create rules, Cannot access detailed error records Use Cases: Business users monitoring data quality for their use cases, Data consumers checking quality before using data products, Management reviewing domain data quality trends, Auditors assessing quality control implementation, Stakeholders tracking quality improvement progress ### Data Profile Steward URL: https://rbacmap.com/roles/gov-data-profile-steward/ Privilege: Standard Description: Run data profiling jobs and access profiling insights. Sub-role requiring Governance Domain Reader and Data Product Owner. Permissions: Run data profiling jobs on data products, Access profiling insight details including column statistics, Browse all data quality insights, Monitor profiling job execution, Cannot create data quality rules, Cannot run data quality scanning (separate from profiling) Use Cases: Data analysts profiling datasets before creating data products, Understanding data distribution and patterns, Identifying data quality issues through profiling, Documenting data characteristics for consumers, Discovering sensitive data through profiling, Supporting data classification and cataloging efforts ### Data Profile Reader URL: https://rbacmap.com/roles/gov-data-profile-reader/ Privilege: Standard Description: Browse data profile insights and drill down to column-level statistics. Sub-role requiring Governance Domain Reader and catalog reader. Permissions: Browse data profile insights, Drill down to column-level profiling statistics, View data distributions and patterns, Access min/max/avg and other statistical measures, Cannot run profiling jobs, Cannot modify profiling configurations Use Cases: Data consumers understanding data characteristics, Analysts evaluating data suitability for use cases, Business users checking data completeness and quality, Data scientists assessing training data distributions, Stakeholders verifying data product documentation accuracy ### Data Quality Metadata Reader URL: https://rbacmap.com/roles/gov-data-quality-metadata-reader/ Privilege: Standard Description: Browse data quality insights, rule definitions, and scores. Sub-role requiring Governance Domain Reader and catalog reader. Permissions: Browse data quality insights (except profiling column-level), View data quality rule definitions, Access rule-level quality scores, Cannot access error records, Cannot run profiling or quality scanning jobs, Read-only access to quality metadata Use Cases: Auditors reviewing quality control implementation, Compliance teams verifying quality rules exist, Management monitoring quality rule coverage, Documentation teams describing quality controls, External consultants assessing quality maturity =============================================================================== # 2. MICROSOFT ENTRA ID (140 roles, 19 categories) # URL: https://rbacmap.com/services/entra/ =============================================================================== ## Category: Developer & Technical ### Azure DevOps Administrator URL: https://rbacmap.com/roles/entra-azure-devops-admin/ Privilege: Standard Description: Can manage all enterprise Azure DevOps policies for organizations backed by Microsoft Entra ID. Permissions: Manage Azure DevOps organization policies, Configure security policies, Manage billing and licensing, Claim ownership of orphaned organizations, Configure guest access policies, Manage project collection settings Use Cases: Enterprise DevOps governance, Security policy enforcement, Organization standards management, Orphaned organization recovery, Cross-organization policy alignment ### Network Administrator URL: https://rbacmap.com/roles/entra-network-admin/ Privilege: Standard Description: Can manage network locations and review enterprise network design insights for Microsoft 365 SaaS applications. Permissions: Manage network locations, Review network performance insights, Configure discovered user locations, View network telemetry, Optimize M365 network connectivity, Review network design recommendations Use Cases: Office network location configuration, Network performance optimization, Connectivity troubleshooting, Network design review, User location configuration ### Desktop Analytics Administrator URL: https://rbacmap.com/roles/entra-desktop-analytics-admin/ Privilege: Standard Description: Can access and manage Desktop management tools and services for Windows device analytics. Permissions: Access Desktop Analytics service, Manage Desktop Analytics settings, View device compatibility data, Create deployment plans, View deployment readiness, Manage update insights Use Cases: Windows upgrade planning, Application compatibility assessment, Deployment readiness analysis, Update compliance monitoring, Device inventory insights ### Edge Administrator URL: https://rbacmap.com/roles/entra-edge-admin/ Privilege: Standard Description: Manage all aspects of Microsoft Edge including policies, settings, and enterprise configurations. Permissions: Manage Edge browser policies, Configure Edge for Business settings, Manage site lists, Configure IE mode settings, Manage extension policies, View Edge usage analytics Use Cases: Edge browser policy configuration, IE mode site list management, Extension approval and blocking, Browser security configuration, Enterprise browser management ### Organizational Data Source Administrator URL: https://rbacmap.com/roles/entra-org-data-source-admin/ Privilege: Standard Description: Manages organizational data ingestion for Microsoft 365 and Microsoft Viva applications. Permissions: Upload organizational data, Update ingested data, Delete organizational data, Configure ingestion settings, Read org data settings Use Cases: HR data integration, Org chart population, Viva Insights data setup, Custom attribute ingestion ### Agent ID Administrator URL: https://rbacmap.com/roles/entra-agent-id-admin/ Privilege: Standard Description: Manages all aspects of agents in a tenant including identity lifecycle operations for agent blueprints, agent service principals, agent identities, and agentic users. Permissions: Create and manage agent identities (Microsoft Entra Agent ID), Manage agent blueprints, Update agent role assignments, Enable/disable agents, Manage agent credentials, Create agentic users, Manage agents surfaced in the Microsoft Agent 365 inventory that have an Entra agent identity Use Cases: Managing AI agent authentication, Configuring agent service principals, Setting up agentic user accounts, Controlling agent permissions ### Agent ID Developer URL: https://rbacmap.com/roles/entra-agent-id-developer/ Privilege: Standard Description: Creates agent blueprints and their service principals. The user is added as owner of the agent blueprint and its service principal. Permissions: Create agent blueprints, Create agent service principals, Read service principal properties, Become owner of created blueprints Use Cases: Building AI agent applications, Setting up agent authentication, Developing copilot integrations ### Agent Registry Administrator URL: https://rbacmap.com/roles/entra-agent-registry-admin/ Privilege: Standard Description: Manages all aspects of the Agent Registry service in Microsoft Entra ID including metadata, collections, and visibility of AI agents. Permissions: Manage agent metadata, Manage agent collections, Control agent visibility, Assign registry roles to users/agents Use Cases: Organizing AI agents in registry, Managing agent discoverability, Controlling agent access ### Authentication Extensibility Administrator URL: https://rbacmap.com/roles/entra-auth-extensibility-admin/ Privilege: Standard Description: Creates and manages custom authentication extensions to customize sign-in and sign-up experiences for users. Permissions: Create custom authentication extensions, Manage authentication extension settings, Configure sign-in customizations, Manage sign-up extensions Use Cases: Custom claim providers, Token enrichment, External attribute lookup, Custom authentication workflows ### Dragon Administrator URL: https://rbacmap.com/roles/entra-dragon-admin/ Privilege: Standard Description: Manages all aspects of the Microsoft Dragon admin center for healthcare voice recognition. Permissions: Manage Dragon settings, Configure voice profiles, Administer Dragon center, Manage templates, View usage data Use Cases: Healthcare documentation, Clinical voice recognition, Provider management, Template configuration ### Authentication Extensibility Password Administrator URL: https://rbacmap.com/roles/entra-auth-extensibility-password-admin/ Privilege: HIGH Description: Triggers password submit events for custom authentication extensions. Works alongside Authentication Extensibility Administrator to enable password-based custom authentication flows. Permissions: Trigger password submit events for custom authentication extensions, Invoke custom authentication extension password flows, Read basic directory information, Read basic properties on policies Use Cases: Custom password validation during sign-in, External password store integration, Legacy system password migration flows, Custom password policy enforcement during authentication ## Category: B2C & External Identity ### External Identity Provider Administrator URL: https://rbacmap.com/roles/entra-external-id-admin/ Privilege: Standard Description: Can configure identity providers for direct federation with external organizations for B2B collaboration. Permissions: Manage identity providers, Create identity providers, Delete identity providers, Read identity provider properties, Update identity provider settings, Configure SAML/WS-Fed identity providers, Configure social identity providers (Google, Facebook, etc.), Manage domain federation settings, Configure direct federation for B2B Use Cases: B2B direct federation setup, Partner identity provider integration, Social login configuration for B2C, SAML federation with external organizations, Workforce identity provider configuration, Multi-tenant collaboration setup ### B2C IEF Keyset Administrator URL: https://rbacmap.com/roles/entra-b2c-keyset-admin/ Privilege: HIGH Description: Manages policy keys and secrets used for token encryption, token signing, and claim encryption/decryption in Azure AD B2C. Permissions: Create and manage policy keys, Manage encryption secrets, Add keys to key containers, View complete secret details, Manage token signing keys Use Cases: Token signing key rotation, Encryption key management, Secret rollover operations, Policy key configuration, SAML certificate management ### B2C IEF Policy Administrator URL: https://rbacmap.com/roles/entra-b2c-policy-admin/ Privilege: HIGH Description: Creates and manages custom policies in Azure AD B2C Identity Experience Framework including user flows and federation. Permissions: Create and manage custom policies, Configure identity providers, Manage user flows, Edit directory schema, Create new users, Send data to external systems Use Cases: Custom user journey development, External IdP federation setup, Claims transformation configuration, Multi-step authentication flows, Progressive profiling implementation ### Tenant Creator URL: https://rbacmap.com/roles/entra-tenant-creator/ Privilege: Standard Description: Can create new Microsoft Entra and Azure AD B2C tenants even when tenant creation is disabled for regular users. Permissions: Create new Entra ID tenants, Create new Azure AD B2C tenants, Bypass tenant creation restrictions Use Cases: Setting up new B2C environments, Creating development/test tenants, Multi-tenant application setup, Subsidiary tenant provisioning ### External ID User Flow Administrator URL: https://rbacmap.com/roles/entra-external-id-user-flow-admin/ Privilege: Standard Description: Creates and manages all aspects of user flows for external identity scenarios. Permissions: Create user flows, Update user flows, Delete user flows, Manage user flow configuration Use Cases: Configuring sign-up/sign-in flows, Customizing user journeys, Managing self-service registration ### External ID User Flow Attribute Administrator URL: https://rbacmap.com/roles/entra-external-id-user-flow-attr-admin/ Privilege: Standard Description: Creates and manages the attribute schema available to all user flows for external identities. Permissions: Create custom attributes, Update attribute schema, Delete attributes, Manage attribute configuration Use Cases: Adding custom profile attributes, Configuring required fields, Managing attribute display ## Category: Hardware & Devices ### Microsoft Hardware Warranty Administrator URL: https://rbacmap.com/roles/entra-hardware-warranty-admin/ Privilege: Standard Description: Creates and manages warranty claims and entitlements for Microsoft manufactured hardware like Surface and HoloLens. Permissions: Create warranty claims, Manage device replacements, View all service requests, Manage shipping addresses, Read warranty claim status Use Cases: Processing warranty repairs, Managing device replacements, Tracking service requests, Coordinating shipping logistics ### Microsoft Hardware Warranty Specialist URL: https://rbacmap.com/roles/entra-hardware-warranty-specialist/ Privilege: Standard Description: Creates warranty claims for Microsoft hardware and reads existing claims they created, with limited access to shipping addresses. Permissions: Create warranty claims, Read own warranty claims, Read shipping addresses, View shipping status Use Cases: Submitting warranty repairs, Tracking own service requests, Viewing repair status ### IoT Device Administrator URL: https://rbacmap.com/roles/entra-iot-device-admin/ Privilege: Standard Description: Provisions new IoT devices, manages their lifecycle, configures certificates, and manages device templates. Permissions: Provision IoT devices, Manage device lifecycle, Configure device certificates, Create device templates, Manage template owners Use Cases: IoT device onboarding, Device template management, Certificate configuration, Device lifecycle management, Smart building deployments ### Kaizala Administrator URL: https://rbacmap.com/roles/entra-kaizala-admin/ Privilege: Standard Description: Manages Microsoft Kaizala settings, usage reports, and business reports generated using Kaizala actions. Permissions: Manage Kaizala settings, View adoption reports, Access business reports, Manage support tickets, Monitor service health Use Cases: Frontline worker communication, Field workforce management, Adoption monitoring, Report analysis ### Microsoft Entra Joined Device Local Administrator URL: https://rbacmap.com/roles/entra-device-local-admin/ Privilege: HIGH Description: Users assigned to this role are added to the local administrators group on Microsoft Entra joined devices. Permissions: Local administrator on Entra joined devices, Read group settings, Read group setting templates Use Cases: Device troubleshooting, Software installation, Local device management, IT support scenarios ## Category: Universal Print ### Printer Administrator URL: https://rbacmap.com/roles/entra-printer-admin/ Privilege: Standard Description: Manages all aspects of printers and printer connectors in Microsoft Universal Print including configuration and connector settings. Permissions: Manage all printers, Configure printer connectors, Create and manage print policies, Consent to print permissions, Access print reports Use Cases: Enterprise print management, Printer deployment, Connector configuration, Print policy management, Cost control initiatives ### Printer Technician URL: https://rbacmap.com/roles/entra-printer-technician/ Privilege: Standard Description: Registers and unregisters printers, updates printer status, and reads connector information but cannot set permissions. Permissions: Register printers, Unregister printers, Update printer status, Read connector information, Update basic printer properties Use Cases: Printer deployment, Status updates, Troubleshooting support, Printer registration ## Category: Privileged Identity Management ### PIM Administrator URL: https://rbacmap.com/roles/entra-pim-admin/ Privilege: Standard Description: Can manage all aspects of Privileged Identity Management including settings, eligible assignments, and approval workflows. This role is equivalent to Privileged Role Administrator for PIM purposes. Permissions: PIM - Full PIM management, PIM Settings - Configure PIM settings for all Entra roles, Approvals - Approve or deny role activation requests, Workflows - Configure approval workflows and approvers, Activation - Set activation requirements (MFA, justification, ticket), Duration - Configure activation duration limits, Audit - Review PIM audit logs and history, Role Assignments - Manage eligible and active role assignments, Notifications - Configure notifications for role activations, Alerts - Set up PIM alerts and thresholds, PIM for Groups - Manage PIM for Groups settings Use Cases: Just-in-time access implementation, Role activation workflow management, Privileged access governance, Approval process configuration, PIM policy standardization, Activation alerting configuration, Emergency access procedure setup, Compliance audit support ### PIM Approver URL: https://rbacmap.com/roles/entra-pim-approver/ Privilege: Standard Description: Designated as approver for PIM role activation requests. Can approve or deny activation requests but cannot modify PIM settings. Permissions: Approvals - Approve or deny role activation requests, Requests - View pending activation requests, Justification - Provide approval justification, Request Details - View activation request details and context, Notifications - Receive notification of pending approvals, Limitation - Cannot modify PIM settings or configurations, Limitation - Cannot grant or revoke role eligibility Use Cases: Manager approval for subordinate access elevation, Security team approval for sensitive roles, Compliance-required approval workflows, Separation of duties enforcement, Change management approval integration, Emergency access approval authority ## Category: Identity Protection ### Identity Protection Administrator URL: https://rbacmap.com/roles/entra-idp-admin/ Privilege: Standard Description: Can manage Identity Protection policies, investigate and remediate risky users and sign-ins, and configure risk-based policies. Requires Microsoft Entra ID P2 license. Permissions: IDP Data - Read all Identity Protection data, IDP Settings - Update Identity Protection settings, Risk Policies - Configure user risk and sign-in risk policies, Risky Users - Review and remediate risky users, User Compromise - Confirm user compromise, Risk Dismissal - Dismiss user risk, Risk Investigation - Investigate risk detections, CA Integration - Configure risk-based Conditional Access policies, Reports - View Identity Protection reports and dashboards, Workload Identity - Access risky workload identities, Sign-in Risk - Review sign-in risk detections, Data Export - Export risk data for analysis Use Cases: Configuring user and sign-in risk policies, Investigating potentially compromised accounts, Managing risky user remediation workflows, Risk detection analysis and triage, Automated risk response configuration, Risk-based Conditional Access policy tuning, Workload identity risk management, Risk trend analysis and reporting, Compliance reporting for identity risks ### Identity Protection Reader URL: https://rbacmap.com/roles/entra-idp-reader/ Privilege: Standard Description: Can read Identity Protection reports, risk detections, and configurations but cannot remediate risks or modify policies. Requires Microsoft Entra ID P2 license. Permissions: IDP Data - Read all Identity Protection data, Risk Reports - View Identity Protection risk reports, Risk Detections - Read risk detection details and algorithms, Risky Users - View risky users and sign-ins list, IDP Policies - Read Identity Protection policies configuration, Risk Trends - Access risk trend reports, Workload Identity - View workload identity risks, Limitation - Cannot modify policies or dismiss risks, Limitation - Cannot confirm user compromise Use Cases: Security monitoring and oversight, Compliance auditing and reporting, Risk assessment visibility for leadership, Executive security dashboards, Third-party security assessment support, Risk trend analysis for planning, Security posture reporting ## Category: Identity Governance ### Identity Governance Administrator URL: https://rbacmap.com/roles/entra-elm-admin/ Privilege: Standard Description: Can manage access using Microsoft Entra ID for identity governance scenarios including access packages, access reviews, catalogs, and entitlement management. Permissions: App Access Reviews - Manage app access reviews, Entitlement Reviews - Manage entitlement access reviews, Group Access Reviews - Manage group access reviews, All Reviews - Manage all access reviews, Entitlement Management - Full entitlement management, Group Membership - Update group members for access packages, App Roles - Update app role assignments, Access Packages - Create and manage access packages with resources, Catalogs - Create and manage catalogs for access governance, Connected Orgs - Configure connected organizations for B2B governance, Package Policies - Manage access package policies and approval workflows, Terms of Use - Configure terms of use requirements, Lifecycle Workflows - Set up lifecycle workflows for access automation, Review Schedules - Configure access review schedules and settings, Custom Extensions - Manage custom extension callouts for workflows Use Cases: Designing access package architecture for the organization, Creating catalogs aligned with business units, Configuring connected organizations for partner access, Setting up self-service access request workflows, Implementing access lifecycle policies (time-bound access), Creating access reviews for periodic recertification, Configuring automatic removal for non-response in reviews, Implementing separation of duties through incompatible packages, Setting up terms of use for compliance, Configuring lifecycle workflows for joiner/mover/leaver, Managing guest access governance, Implementing project-based access with expiration ### Lifecycle Workflows Administrator URL: https://rbacmap.com/roles/entra-lifecycle-workflows-admin/ Privilege: Standard Description: Create and manage all aspects of workflows and tasks associated with Lifecycle Workflows for joiner, mover, and leaver scenarios. Permissions: Create and manage lifecycle workflows, Create and manage workflow tasks, Check execution of scheduled workflows, Launch on-demand workflow runs, Inspect workflow execution logs, Configure workflow triggers and conditions Use Cases: Employee onboarding automation, Department transfer workflows, Employee offboarding automation, Contractor lifecycle management, Pre-hire provisioning, Post-termination cleanup ### Attribute Definition Administrator URL: https://rbacmap.com/roles/entra-attribute-definition-admin/ Privilege: Standard Description: Define and manage the definition of custom security attributes that can be assigned to supported Microsoft Entra objects. Permissions: Create attribute sets, Define custom security attributes, Activate/deactivate attributes, Manage attribute definitions, Configure attribute properties Use Cases: Custom attribute schema design, Security classification attributes, Project-based access control attributes, Regulatory compliance tagging, Data residency classification ### Attribute Assignment Administrator URL: https://rbacmap.com/roles/entra-attribute-assignment-admin/ Privilege: Standard Description: Assign custom security attribute keys and values to supported Microsoft Entra objects like users, service principals, and devices. Permissions: Assign custom security attributes to users, Assign attributes to service principals, Assign attributes to devices, Update attribute values, Remove attribute assignments Use Cases: Tagging users with security classifications, Assigning project attributes, Setting compliance attributes, Device classification tagging, Application sensitivity labeling ### Attribute Log Administrator URL: https://rbacmap.com/roles/entra-attribute-log-admin/ Privilege: Standard Description: Read audit logs and configure diagnostic settings for events related to custom security attributes. Permissions: Read custom security attribute audit logs, Read attribute definition change logs, Read attribute assignment change logs, Configure diagnostic settings for attributes, Export attribute audit logs Use Cases: Attribute change auditing, Compliance monitoring for attributes, Attribute assignment tracking, Security investigation support, Diagnostic log configuration ### Attribute Log Reader URL: https://rbacmap.com/roles/entra-attribute-log-reader/ Privilege: Standard Description: Read audit logs for custom security attribute value changes, definition changes, and assignments. Cannot configure diagnostic settings or read other audit log types. Permissions: Read custom security attribute audit logs, Read attribute value change logs, Read attribute definition change logs, Read attribute assignment change logs Use Cases: Attribute change monitoring, Compliance auditing for attribute assignments, Security investigation support, Reviewing attribute definition changes, Attribute governance oversight ### Attribute Assignment Reader URL: https://rbacmap.com/roles/entra-attribute-reader/ Privilege: Standard Description: Read custom security attribute keys and values for supported Microsoft Entra objects. Permissions: Read attribute sets, Read custom security attribute definitions, Read attribute values on users, Read attribute values on service principals, Read attribute values on devices Use Cases: Attribute value verification, Reporting on attribute assignments, Application attribute lookup, Compliance reporting, Access decision support ### Attribute Definition Reader URL: https://rbacmap.com/roles/entra-attribute-definition-reader/ Privilege: Standard Description: Reads the definition of custom security attributes but cannot assign values. Permissions: Read attribute set properties, Read custom security attribute definitions Use Cases: Auditing attribute definitions, Understanding attribute structure, Compliance reporting ### Attribute Provisioning Administrator URL: https://rbacmap.com/roles/entra-attribute-provisioning-admin/ Privilege: HIGH Description: Reads and edits provisioning configuration of custom security attributes for applications. Permissions: Read custom security attributes in sync schema, Update attribute mappings in sync schema, Read provisioning logs for attributes Use Cases: Setting up attribute provisioning, Mapping attributes to target systems, Troubleshooting attribute sync ### Attribute Provisioning Reader URL: https://rbacmap.com/roles/entra-attribute-provisioning-reader/ Privilege: Standard Description: Reads the provisioning configuration of custom security attributes for applications. Permissions: Read custom security attributes in sync schema, Read provisioning logs for attributes Use Cases: Reviewing attribute provisioning setup, Auditing attribute flows, Troubleshooting (read-only) ### Permissions Management Administrator URL: https://rbacmap.com/roles/entra-permissions-mgmt-admin/ Privilege: HIGH Description: Manage all aspects of Microsoft Entra Permissions Management including discovery, remediation, and monitoring of permissions across multi-cloud environments. Permissions: Full administration of Permissions Management, Configure Permissions Management settings, Manage data collectors for AWS, Azure, and GCP, View and act on permissions analytics, Create and manage Permissions Creep Index alerts, Generate multi-cloud permissions reports, Configure just-in-time permissions requests, Manage Permissions Management roles and policies Use Cases: Multi-cloud permissions discovery and right-sizing, Permissions Creep Index monitoring, Just-in-time access workflows for cloud resources, Cross-cloud permissions analytics, Detecting over-provisioned identities in AWS, Azure, and GCP, Remediation of excessive permissions ### Tenant Governance Administrator URL: https://rbacmap.com/roles/entra-tenant-gov-admin/ Privilege: Standard Description: Manages all capabilities in the Microsoft Entra Tenant Governance service for multi-tenant organization management. Permissions: Manage all tenant governance capabilities, Configure governance policies across tenants, Manage tenant governance settings and configurations, Create and manage governance relationships, View and manage all tenant governance data Use Cases: Multi-tenant organization governance setup, Cross-tenant policy management and enforcement, Subsidiary and partner tenant governance, Centralized compliance governance across tenant boundaries, Multi-tenant identity lifecycle coordination ### Tenant Governance Reader URL: https://rbacmap.com/roles/entra-tenant-gov-reader/ Privilege: Standard Description: Read-only access to all tenant governance data in the Microsoft Entra Tenant Governance service. Permissions: Read all tenant governance data, View governance policies and configurations, View governance relationship details, Access governance reports and status Use Cases: Auditing multi-tenant governance compliance, Monitoring governance relationship health, Executive reporting on cross-tenant governance, Compliance reviews of multi-tenant configurations ### Tenant Governance Relationship Administrator URL: https://rbacmap.com/roles/entra-tenant-gov-relationship-admin/ Privilege: Standard Description: Can initiate governance relationships with other tenants and terminate existing governance relationships in Microsoft Entra Tenant Governance. Permissions: Initiate new governance relationships with other tenants, Terminate existing governance relationships, Manage governance relationship lifecycle, Configure relationship settings and parameters Use Cases: Establishing governance relationships with subsidiaries, Onboarding new tenants into governance framework, Offboarding tenants from governance relationships, Managing partner tenant governance connections ### Tenant Governance Relationship Reader URL: https://rbacmap.com/roles/entra-tenant-gov-relationship-reader/ Privilege: Standard Description: Can read tenant governance relationships and relevant objects in Microsoft Entra Tenant Governance. Permissions: Read tenant governance relationships, View governance relationship configurations, Access relationship status and details, View related governance objects Use Cases: Auditing governance relationships across tenants, Monitoring relationship health and status, Compliance reporting on cross-tenant connections ### Customer Delegated Admin Relationship Administrator URL: https://rbacmap.com/roles/entra-cdar-admin/ Privilege: HIGH Description: Manage all aspects of Granular Delegated Admin Privileges (GDAP) relationships in a customer tenant. Used by Microsoft Cloud Solution Provider (CSP) partners and their delegated administrators to manage the lifecycle of customer access relationships. Permissions: Create and manage GDAP customer relationships, Approve or terminate delegated admin relationships, Configure granular permission scopes within GDAP, Manage relationship requests from partners, Read directory and policy information needed for GDAP administration, Audit GDAP relationship changes Use Cases: Onboarding a new Microsoft Cloud Solution Provider (CSP) partner, Granting time-bound, role-scoped access to partner administrators, Reviewing and renewing existing GDAP relationships, Terminating a partner relationship at end of contract, Migrating from legacy DAP (delegated admin privileges) to GDAP ### Directory Synchronization Accounts URL: https://rbacmap.com/roles/entra-dir-sync-accounts/ Privilege: Standard Description: System role used exclusively by the Microsoft Entra Connect service to synchronize on-premises Active Directory with Microsoft Entra ID. Not intended for human assignment — Microsoft manages membership automatically when Entra Connect is configured. Permissions: Read and write all directory data needed for directory sync, Create, update, and delete users, groups, and contacts, Manage hybrid identity attributes, Synchronize password hashes (if PHS is enabled), Read and update on-premises identity attributes Use Cases: Microsoft Entra Connect service authentication, Microsoft Entra Connect cloud sync agent authentication, Hybrid identity password hash synchronization, Pass-through authentication agent authentication ## Category: Security & Compliance ### Security Operator URL: https://rbacmap.com/roles/entra-security-operator/ Privilege: Standard Description: Can manage security events, view reports, dismiss alerts, and take limited remediation actions. Cannot modify security policies. Permissions: Audit - Read audit logs, Authorization - Read authorization policy, Cloud App Security - Manage Cloud App Security, Identity Protection - Read Identity Protection, Identity Protection - Update Identity Protection settings, PIM - Read PIM, Provisioning - Read provisioning logs, Sign-in Reports - Read sign-in reports, Azure ATP - Manage Azure ATP, Service Health - Manage Azure service health, Support Tickets - Create Azure support tickets, Attack Simulation - Read attack simulation events, Security Center - Manage Security & Compliance Center, M365 Health - Manage M365 service health, M365 Support - Create M365 support tickets, Alerts - Dismiss or remediate security alerts, Limitation - Cannot modify security policies Use Cases: SOC analyst daily operations, Security incident triage and response, Alert investigation and dismissal, Security monitoring and reporting, Identity Protection alert handling, Cloud App Security management, Threat detection investigation, Risky user investigation ### Attack Simulation Administrator URL: https://rbacmap.com/roles/entra-attack-simulation-admin/ Privilege: Standard Description: Can create and manage all aspects of attack simulation campaigns including phishing simulations, payload creation, and campaign reporting. Permissions: Admin Center - Read admin center properties, Payloads - Manage attack payloads, Reports - Read attack simulation reports, Simulations - Manage attack simulations, Campaigns - Create and launch phishing simulation campaigns, Payloads - Create custom simulation payloads and templates, Results - View simulation results and user performance, Training - Manage training assignments from simulations, Schedules - Configure simulation schedules and automation, Content - Access attack simulation training content Use Cases: Phishing simulation campaigns, Security awareness training programs, User risk assessment and baselining, Compliance training requirements, Social engineering awareness testing, Credential harvesting simulations, Business email compromise testing, Targeted attack simulations, Training content assignment, Security culture measurement ### Compliance Administrator URL: https://rbacmap.com/roles/entra-compliance-admin/ Privilege: Standard Description: Can read and manage compliance configuration and reports across Microsoft Entra ID and Microsoft 365 including DLP, retention, sensitivity labels, and eDiscovery. Permissions: Azure Information Protection management, Manage Azure service health, Create Azure support tickets, Read entitlement management, Compliance Manager administration, Manage M365 service health, Create M365 support tickets, Read admin center properties, Manage Microsoft Purview compliance features, Configure DLP, retention, and sensitivity labels, Manage eDiscovery and content search, View compliance reports and dashboards, Configure Information Protection policies, Manage communication compliance, Configure insider risk management Use Cases: Compliance program management, DLP policy configuration and management, Information Protection and sensitivity labels, eDiscovery case management, Retention and records management, Communication compliance policies, Insider risk management configuration, Compliance Manager assessments, Regulatory compliance reporting, Data classification and labeling ### Compliance Data Administrator URL: https://rbacmap.com/roles/entra-compliance-data-admin/ Privilege: Standard Description: Creates and manages compliance content, tracks data in Microsoft Purview, and can perform eDiscovery operations. Permissions: Create and manage compliance content, Monitor compliance policies across M365, Manage compliance alerts, Track data in Purview compliance portal, Perform data governance operations, Manage data classification, Create and manage file policies in Defender for Cloud Apps Use Cases: eDiscovery case management, Data classification configuration, Compliance policy monitoring, Data loss prevention oversight, Information governance, Audit log analysis for compliance ### Azure Information Protection Administrator URL: https://rbacmap.com/roles/entra-aip-admin/ Privilege: Standard Description: Can manage all aspects of the Azure Information Protection product including labels, policies, and protection templates. Permissions: Configure labels for AIP policy, Manage protection templates, Activate protection, Configure AIP scanner, Manage AIP policies and settings, View AIP analytics and reports Use Cases: Sensitivity label configuration, Protection template management, AIP scanner deployment, Data classification policies, Rights management configuration ### Customer LockBox Access Approver URL: https://rbacmap.com/roles/entra-customer-lockbox-approver/ Privilege: HIGH Description: Can approve Microsoft support requests to access customer organizational data. Critical for controlling Microsoft engineer access. Permissions: Approve Customer Lockbox requests, Deny Customer Lockbox requests, View pending Lockbox requests, Turn Customer Lockbox feature on/off, Receive Lockbox request notifications Use Cases: Approving Microsoft support access, Reviewing support request justifications, Maintaining audit trail of access approvals, Controlling data sovereignty, Compliance with data access policies ### Microsoft 365 Backup Administrator URL: https://rbacmap.com/roles/entra-m365-backup-admin/ Privilege: Standard Description: Manages all aspects of Microsoft 365 Backup including policies, restore operations, and backup configurations. Permissions: Create and manage backup policies, Perform restore operations, Configure backup for SharePoint, OneDrive, Exchange, View backup status and reports, Manage backup storage and retention Use Cases: Backup policy configuration, Disaster recovery operations, Granular restore for users, Compliance-driven backup retention, Business continuity planning ### Message Center Privacy Reader URL: https://rbacmap.com/roles/entra-message-center-privacy-reader/ Privilege: Standard Description: Can read all notifications in Message Center including data privacy messages. Important for privacy compliance awareness. Permissions: Read Message Center notifications, Read data privacy messages, View groups, domains, subscriptions, Receive email notifications for privacy messages, Unsubscribe using Message Center preferences Use Cases: Privacy impact awareness, Data privacy change monitoring, Compliance change tracking, Proactive privacy planning, Regulatory notification monitoring ### Attack Payload Author URL: https://rbacmap.com/roles/entra-attack-payload-author/ Privilege: Standard Description: Creates attack payloads for security awareness training but cannot launch simulations. Payloads are available to all tenant admins. Permissions: Create attack payloads, Manage attack payloads, Read simulation reports (own simulations only), Read associated training reports Use Cases: Creating phishing templates, Designing security awareness content, Building training scenarios ### Cloud App Security Administrator URL: https://rbacmap.com/roles/entra-cloud-app-security-admin/ Privilege: HIGH Description: Full permissions in Microsoft Defender for Cloud Apps including adding administrators, policies, and governance actions. Permissions: Add Defender for Cloud Apps administrators, Create and modify policies, Upload logs for analysis, Perform governance actions, Full admin access to MCAS Use Cases: Cloud app discovery, Shadow IT detection, Data loss prevention, Threat detection for cloud apps ## Category: Reporting & Knowledge ### Reports Reader URL: https://rbacmap.com/roles/entra-reports-reader/ Privilege: Standard Description: Can read sign-in and audit reports, and view the Microsoft Agent 365 overview and agent registry for the tenant including agent metadata. Ideal for compliance and security monitoring without broader administrative permissions. Permissions: Read sign-in reports, Read audit logs, Read usage reports, Read M365 usage analytics, View Microsoft Agent 365 overview and agent registry with full agent metadata, Access reporting dashboards, Export report data Use Cases: Security monitoring and alerting, Compliance reporting, Usage analytics review, Audit log analysis, Sign-in pattern investigation, License utilization reporting ### Knowledge Administrator URL: https://rbacmap.com/roles/entra-knowledge-admin/ Privilege: Standard Description: Can configure knowledge, learning, and intelligent features including Microsoft Viva Topics, Learning, and search customizations. Permissions: Configure Microsoft Viva Topics, Manage Viva Learning sources, Configure knowledge network settings, Manage topic centers, Configure search customizations, Manage organizational insights Use Cases: Viva Topics configuration, Learning content source management, Knowledge network governance, Search experience customization, Organizational insights configuration ### Search Editor URL: https://rbacmap.com/roles/entra-search-editor/ Privilege: Standard Description: Can create and manage editorial content for Microsoft Search such as bookmarks, Q&A, and locations. Permissions: Create bookmarks, Manage Q&A content, Edit locations, Manage floor plans content, Read Message Center, Cannot change search settings Use Cases: Creating helpful bookmarks, Curating Q&A content, Managing location information, Search content optimization, Decentralized content management ### Insights Analyst URL: https://rbacmap.com/roles/entra-insights-analyst/ Privilege: Standard Description: Access the analytical capabilities in Microsoft Viva Insights and run custom queries. Permissions: Run custom Viva Insights queries, Access advanced analytics, Create custom reports, View organizational patterns, Export insights data Use Cases: Custom workplace analytics queries, Meeting culture analysis, Collaboration pattern research, Manager effectiveness insights, Organizational network analysis ### Insights Business Leader URL: https://rbacmap.com/roles/entra-insights-business-leader/ Privilege: Standard Description: Can view and share dashboards and insights via the Microsoft Viva Insights app. Permissions: View Insights dashboards, Share insights with others, Access pre-built reports, View organizational insights, Deploy and manage programs Use Cases: Executive insights consumption, Team wellbeing monitoring, Meeting effectiveness review, Sharing insights with leadership, Program deployment ### User Experience Success Manager URL: https://rbacmap.com/roles/entra-ux-success-manager/ Privilege: Standard Description: Views product feedback, survey results, and reports to find training and communication opportunities for users. Permissions: Read usage reports (aggregated), View product feedback, View NPS survey results, View help article views, View Microsoft Agent 365 insights, organization data, and agent registry information (cannot manage agents), Read message center posts Use Cases: Identifying training needs, Planning communications, Measuring adoption, Understanding user sentiment ## Category: Global Secure Access ### Global Secure Access Administrator URL: https://rbacmap.com/roles/entra-global-secure-access-admin/ Privilege: HIGH Description: Can manage Microsoft Entra Private Access and Internet Access, configure traffic policies, and manage network security features. Permissions: Configure Private Access apps, Manage Internet Access policies, Configure traffic forwarding, Manage connector groups, View network traffic logs, Configure security profiles, Manage compliant network policies Use Cases: Zero Trust Network Access configuration, Private app access without VPN, Internet traffic security policies, Conditional Access integration, Network traffic monitoring, Secure access service edge (SASE) management ### Global Secure Access Log Reader URL: https://rbacmap.com/roles/entra-gsa-log-reader/ Privilege: Standard Description: Provides read-only access to network traffic logs in Microsoft Entra Internet Access and Private Access for security analysis. Permissions: Read Internet Access logs, Read Private Access logs, Read network traffic data, Access traffic analytics Use Cases: Security incident investigation, Network traffic analysis, Compliance auditing, Threat hunting ## Category: Conditional Access ### Conditional Access Administrator URL: https://rbacmap.com/roles/entra-ca-admin/ Privilege: HIGH Description: Can manage Conditional Access settings and policies. This is a privileged role that controls access to all cloud resources. Permissions: CA Properties - Update basic properties for CA policies, CA Policies - Create Conditional Access policies, CA Policies - Delete Conditional Access policies, CA Ownership - Read CA policy owners, CA Ownership - Update CA policy owners, Applied Policies - Read applied to property, CA Policies - Read CA policies, Tenant Default - Update tenant default CA, Named Locations - Update named locations, Named Locations - Create named locations, Named Locations - Delete named locations, Named Locations - Read named locations, Auth Context - Update authentication context for RBAC resource actions, Access Controls - Configure IP-based, location-based, and device-based access controls, Auth Strength - Implement authentication strength requirements, Session Controls - Configure session controls and sign-in frequency Use Cases: Implementing Zero Trust access policies, Configuring MFA requirements by application, user, or location, Managing device compliance requirements for access, Setting location-based access controls (block countries, allow office IPs), Configuring sign-in risk-based access policies, Implementing session controls (sign-in frequency, persistent browser), Creating authentication strength policies (phishing-resistant MFA), Managing Named Locations (trusted IPs, countries), Implementing block legacy authentication policies, Configuring app protection policies integration, Creating report-only policies for testing, Managing authentication context for sensitive resources ## Category: Access Reviews ### Access Reviews Administrator URL: https://rbacmap.com/roles/entra-ar-admin/ Privilege: Standard Description: Can create and manage access reviews for group memberships, application assignments, and role assignments. Requires Microsoft Entra ID P2 license. Permissions: Access Reviews - Full access review management, Review Creation - Create and configure access reviews, Review Settings - Manage access review settings and schedules, Review Results - View access review results and history, Scope Configuration - Configure review scope and reviewers, Auto-Apply - Set auto-apply and notification settings, Multi-Stage - Configure multi-stage reviews, Recurring Reviews - Set up recurring review schedules, Export - Export review results for compliance Use Cases: Periodic group membership certification, Application access recertification, Privileged role access reviews, Guest user access attestation, Regulatory compliance attestation, Joiner-mover-leaver process support, Quarterly access certification programs, Sensitive resource access governance ### Access Review Reviewer URL: https://rbacmap.com/roles/entra-ar-reviewer/ Privilege: Standard Description: Designated reviewer for access reviews who can approve or deny continued access. Cannot modify review settings. Permissions: Decisions - Review and make access decisions, Decisions - Approve or deny continued access, Review Scope - View review scope and members under review, History - View review history for assigned reviews, Notes - Add review notes and justifications, Recommendations - Accept recommendations from system, Limitation - Cannot modify review settings or scope, Limitation - Cannot create new access reviews Use Cases: Manager reviews for team member access, Application owner access reviews, Group owner membership attestation, Self-review for personal access, Resource owner access certification, Delegated access governance ## Category: Entitlement Management ### Catalog Owner URL: https://rbacmap.com/roles/entra-elm-catalog-owner/ Privilege: Standard Description: Can manage catalogs and access packages within their assigned catalogs. Permissions: Add resources to catalog, Create and manage access packages in catalog, Assign catalog roles to others, Configure package policies, Cannot create new catalogs Use Cases: Department-level access management, Business unit self-service configuration, Project-based access packages ### Access Package Manager URL: https://rbacmap.com/roles/entra-elm-package-manager/ Privilege: Standard Description: Can manage access packages within assigned catalogs. Permissions: Create and edit access packages, Configure package policies and approvals, Manage package assignments, Cannot add resources to catalog, Cannot manage catalog settings Use Cases: Day-to-day package administration, Request and approval management, Package policy updates ## Category: Teams Communication ### Teams Communications Administrator URL: https://rbacmap.com/roles/entra-teams-comms-admin/ Privilege: Standard Description: Can manage calling and meetings features within the Microsoft Teams service including policies, configurations, and analytics. Permissions: Manage Teams meeting policies, Configure calling policies, Manage live events settings, Configure audio conferencing, Manage dial plans and routing, View call quality analytics, Manage emergency calling Use Cases: Meeting policy configuration, Calling feature management, Audio conferencing setup, Live events administration, Call quality management, Emergency calling configuration ### Teams Telephony Administrator URL: https://rbacmap.com/roles/entra-teams-telephony-admin/ Privilege: Standard Description: Can manage voice and telephony features in Microsoft Teams including phone numbers, calling policies, and voice configurations. Permissions: Manage phone number assignments, Configure voice routing policies, Manage dial plans, Configure calling queues and auto attendants, Manage Direct Routing, Configure emergency addresses, View voice analytics Use Cases: Phone number management, Direct Routing configuration, Auto attendant and call queue setup, Voice policy management, PSTN connectivity administration, Emergency location management ### Teams Devices Administrator URL: https://rbacmap.com/roles/entra-teams-devices-admin/ Privilege: Standard Description: Can manage Teams certified devices including phones, meeting room devices, and collaboration bars. Permissions: Manage Teams device inventory, Configure device policies, Deploy device updates, View device health reports, Manage meeting room devices, Configure Teams Rooms settings, Remote device management Use Cases: Teams device fleet management, Meeting room system administration, Device firmware and updates, Device policy configuration, Health monitoring and troubleshooting, Collaboration device deployment ### Teams Reader URL: https://rbacmap.com/roles/entra-teams-reader/ Privilege: Standard Description: Read-only access to Teams admin center settings and Call Quality Dashboard without management capabilities. Permissions: Read Teams admin settings, View Call Quality Dashboard, Read all Teams properties, View basic resources Use Cases: Configuration auditing, Settings review, Quality monitoring, Reporting access ### Teams Communications Support Engineer URL: https://rbacmap.com/roles/entra-teams-comms-support-engineer/ Privilege: Standard Description: Troubleshoots communications issues in Teams with access to full call records for all participants. Permissions: View full call records, Access CQD data, Troubleshoot call issues, View all participant details, Access advanced tools Use Cases: Call quality investigation, Network issue diagnosis, User support escalation, Quality improvement initiatives ### Teams Communications Support Specialist URL: https://rbacmap.com/roles/entra-teams-comms-support-specialist/ Privilege: Standard Description: Troubleshoots communications issues in Teams with access to call details only for specific users looked up. Permissions: View user-specific call details, Access basic CQD data, Troubleshoot individual calls, Use basic troubleshooting tools Use Cases: First-line call support, User-reported issues, Basic quality checks, Initial triage ### Teams External Collaboration Administrator URL: https://rbacmap.com/roles/entra-teams-external-collab-admin/ Privilege: Standard Description: Manages external collaboration policies and settings for Teams, including configuring external domains and controlling which groups and users can interact with the organization. Permissions: Configure external access domains for Teams, Manage external collaboration policies, Control which groups can communicate externally, Configure guest access settings for Teams, Manage cross-organization communication settings, Set external sharing policies for Teams Use Cases: Configuring approved external domains for Teams federation, Managing B2B collaboration policies for Teams, Controlling external meeting and chat access, Setting up cross-organization collaboration securely, Restricting external communication to specific groups ## Category: Viva & Employee Experience ### AI Administrator URL: https://rbacmap.com/roles/entra-ai-admin/ Privilege: HIGH Description: Manage all aspects of Microsoft 365 Copilot, Microsoft Agent 365, and AI-related enterprise services including extensibility and copilot agents. Has tenant-wide visibility and full governance authority over agents in the Microsoft 365 admin center. Permissions: Manage Microsoft 365 Copilot settings, Manage AI-related enterprise services, Approve and publish copilot agents, Install, modify, approve, and manage agent configurations in Microsoft 365 admin center (Agent 365), View the complete agent inventory across Copilot Studio, SharePoint, Agent Builder, AI Foundry, and connected platforms, Approve pending agent requests and manage agents without owners, Configure extensibility settings, Manage integrated apps for AI, View usage reports and adoption insights, Create and manage support tickets Use Cases: Copilot deployment and configuration, AI agent governance via Microsoft Agent 365, Approving agent requests and assigning agent ownership, Reviewing publisher attestation and Microsoft 365 Certification on agents, Copilot extensibility management, AI usage monitoring, Plugin and connector approval, AI adoption tracking ### Viva Goals Administrator URL: https://rbacmap.com/roles/entra-viva-goals-admin/ Privilege: Standard Description: Manage and configure all aspects of Microsoft Viva Goals including OKR settings and integrations. Permissions: Configure Viva Goals settings, Manage OKR configurations, Configure integrations, Manage organization settings, View Viva Goals analytics, Manage user access to Viva Goals Use Cases: Viva Goals deployment, OKR framework configuration, Integration with other tools, Goal-setting best practices enforcement, Adoption monitoring ### Viva Pulse Administrator URL: https://rbacmap.com/roles/entra-viva-pulse-admin/ Privilege: Standard Description: Can manage all settings for Microsoft Viva Pulse app including survey configurations and privacy settings. Permissions: Configure Viva Pulse settings, Manage survey templates, Configure privacy settings, View pulse analytics, Manage notification settings, Configure response thresholds Use Cases: Employee pulse survey configuration, Survey template management, Privacy threshold configuration, Pulse analytics review, Manager enablement for pulses ### Viva Glint Tenant Administrator URL: https://rbacmap.com/roles/entra-viva-glint-admin/ Privilege: Standard Description: Manage and configure Microsoft Viva Glint settings in the Microsoft 365 admin center including admin assignments. Permissions: Configure Viva Glint settings, Assign Viva Glint service admins, Create feature access policies, Manage Viva Glint experiences, View Glint analytics, Configure survey programs Use Cases: Viva Glint deployment, Employee engagement survey management, Service admin delegation, Feature access configuration, Analytics and insights review ### Insights Administrator URL: https://rbacmap.com/roles/entra-insights-admin/ Privilege: Standard Description: Has administrative access in the Microsoft 365 Insights app for organizational analytics. Permissions: Configure Insights app settings, Manage data sources, Configure privacy settings, View organizational insights, Manage insights access, Configure dashboard settings Use Cases: Workplace analytics configuration, Meeting and collaboration insights, Privacy threshold management, Organizational network analysis, Productivity insights deployment ### AI Reader URL: https://rbacmap.com/roles/entra-ai-reader/ Privilege: HIGH Description: Read all aspects of Microsoft 365 Copilot and AI-related enterprise services in Microsoft 365. Recommended least-privilege role for viewing the complete agent inventory in Microsoft Agent 365 and the Microsoft Entra Agent Registry. Permissions: Read all Microsoft 365 Copilot settings, Read AI-related enterprise service configurations, View the complete agent inventory in Microsoft Agent 365, View agents with Microsoft Entra Agent IDs in the Agent Registry, Read Copilot usage reports and adoption insights, Read service health and message center entries for AI services Use Cases: Microsoft Agent 365 inventory monitoring without governance authority, Auditing AI agent sprawl across Copilot Studio, SharePoint, Agent Builder, AI Foundry, and connected platforms, Reporting on Copilot adoption and AI usage trends, Compliance reviewers validating agent metadata and ownership, Security analysts triaging agent-related signals before escalation ## Category: M365 & Platform Services ### Power Platform Administrator URL: https://rbacmap.com/roles/entra-power-platform-admin/ Privilege: Standard Description: Can create and manage all aspects of Microsoft Power Apps, Power Automate, and Power BI environments and policies. Permissions: Create and manage Power Platform environments, Configure Power Platform DLP policies, Manage Power Apps and connectors, Manage Power Automate flows organization-wide, Configure Power BI tenant settings, Manage capacity and resources, View Power Platform analytics Use Cases: Power Platform environment management, DLP policy configuration, Connector governance, Capacity planning for Power Apps, Power Automate governance, Power BI tenant administration ### Dynamics 365 Administrator URL: https://rbacmap.com/roles/entra-dynamics-admin/ Privilege: Standard Description: Has access to Dynamics 365 admin center, can manage Dynamics 365 environments, and perform administrative tasks across Dynamics 365 apps. Permissions: Manage Dynamics 365 environments, Configure Dynamics 365 settings, Manage Dynamics 365 user access, Monitor Dynamics 365 usage and analytics, Manage Dynamics 365 apps and solutions, Configure integrations and data connections Use Cases: Dynamics 365 environment provisioning, User and license management for D365, Integration configuration, Solution deployment and management, Performance monitoring ### Fabric Administrator URL: https://rbacmap.com/roles/entra-fabric-admin/ Privilege: Standard Description: Can manage all aspects of Microsoft Fabric including workspaces, capacities, and tenant-wide settings for analytics workloads. Permissions: Manage Microsoft Fabric tenant settings, Configure Fabric capacities, Manage Fabric workspaces, Configure data governance for Fabric, View Fabric usage metrics, Manage Fabric security settings Use Cases: Fabric capacity management, Workspace governance, Data lakehouse administration, Tenant-wide policy configuration, Usage and adoption monitoring ### Message Center Reader URL: https://rbacmap.com/roles/entra-message-center-reader/ Privilege: Standard Description: Can read messages and updates for their organization in Office 365 Message Center only. Permissions: Read Message Center posts, Receive weekly email digests, Share Message Center posts, View basic directory information, Access to groups and domains info Use Cases: Tracking M365 service updates, Change communication awareness, Proactive planning for updates, Sharing updates with stakeholders, Advisory monitoring ### Usage Summary Reports Reader URL: https://rbacmap.com/roles/entra-usage-summary-reader/ Privilege: Standard Description: Read Usage reports and Adoption Score but cannot access user-level details. Permissions: Read tenant-level usage reports, View Adoption Score, Read network performance data, View aggregated usage metrics, Cannot access user-level data Use Cases: Executive reporting on M365 adoption, Adoption Score monitoring, License utilization analysis, Productivity insights (aggregate), ROI reporting for M365 ### Dynamics 365 Business Central Administrator URL: https://rbacmap.com/roles/entra-d365-bc-admin/ Privilege: Standard Description: Accesses and performs all administrative tasks on Dynamics 365 Business Central environments. Permissions: Full Business Central admin access, Manage Business Central environments, Configure Business Central settings, Manage Business Central users Use Cases: Business Central environment management, ERP administration, Business Central configuration ## Category: M365 Workloads & Services ### Intune Administrator URL: https://rbacmap.com/roles/entra-intune-admin/ Privilege: Standard Description: Can manage all aspects of Microsoft Intune product including devices, apps, policies, and user management for endpoints. Permissions: Intune - Full Intune administration, Cloud PCs - Manage Windows 365 Cloud PCs, BitLocker - Read BitLocker recovery keys, Contacts - Update contact properties, Contacts - Create contacts, Contacts - Delete contacts, Devices - Update device properties, Devices - Create/enroll devices, Devices - Delete devices, Devices - Disable devices, Devices - Enable devices, Extension Attributes - Update extension attributes, Device Ownership - Update device owners, Device Users - Update device users, LAPS - Read local admin credentials, Security Groups - Create security groups, Security Groups - Delete security groups, Group Membership - Update security group members, Group Ownership - Update security group owners, User Properties - Update user properties, User Management - Update user managers, User Photos - Update user photos, Org Messages - Read organizational messages, Compliance - Create and manage device compliance policies, App Management - Deploy and manage applications, Updates - Configure Windows Update for Business Use Cases: Endpoint management team lead responsibilities, MDM and MAM policy administration, Device compliance and security policy management, Application deployment and lifecycle management, Windows Autopilot configuration and management, macOS, iOS, and Android device management, Windows Update ring configuration, BitLocker and encryption key management, Endpoint security baseline configuration, Windows 365 Cloud PC management, Corporate device enrollment configuration, BYOD policy and app protection ### Exchange Administrator URL: https://rbacmap.com/roles/entra-exchange-admin/ Privilege: Standard Description: Can manage all aspects of Exchange Online including mailboxes, groups, connectors, mail flow rules, and organization-wide settings. Permissions: Manage Azure service health, Create and manage support tickets, Create Microsoft 365 groups, Delete Microsoft 365 groups, Update M365 group members, Update M365 group owners, Restore deleted M365 groups, Update M365 group properties, Read hidden group members, Full Exchange Online management, Read network performance, Manage service health, Create support tickets, Read usage reports, Read admin center properties, Manage mailboxes, distribution groups, and mail contacts, Configure transport rules and connectors, Manage organization sharing and external collaboration, Configure anti-spam and anti-malware policies Use Cases: Exchange Online deployment and migration, Mailbox creation and management, Mail flow rule configuration, Connector setup for hybrid environments, Distribution group and shared mailbox management, Retention policy configuration, Email security policy management, Address book and global address list management, Public folder administration, Email signature and disclaimer policies, Journaling and compliance configuration, Mobile device mailbox policies ### SharePoint Administrator URL: https://rbacmap.com/roles/entra-sharepoint-admin/ Privilege: Standard Description: Can manage all aspects of SharePoint Online including site collections, sharing policies, term store, and OneDrive for Business settings. Permissions: Manage Azure service health, Create and manage support tickets, Create Microsoft 365 groups, Delete Microsoft 365 groups, Update M365 group members, Update M365 group owners, Restore deleted M365 groups, Update M365 group properties, Read hidden group members, Read network performance, Manage service health, Full SharePoint management, Create support tickets, Read usage reports, Read admin center properties, Manage site collections, hub sites, and site templates, Configure sharing and access policies, Manage OneDrive for Business settings, Configure term store and content types, Manage app catalog and SharePoint add-ins Use Cases: SharePoint Online deployment and migration, Site collection creation and management, External sharing policy configuration, Storage quota management, Hub site configuration and navigation, OneDrive for Business administration, Term store and managed metadata, Content type hub management, SharePoint app catalog administration, Site design and site script management, Information architecture planning, SharePoint search configuration ### Teams Administrator URL: https://rbacmap.com/roles/entra-teams-admin/ Privilege: Standard Description: Can manage the Microsoft Teams service including meetings, calling, messaging policies, and Teams-certified devices. Permissions: Full Teams administration, Create Microsoft 365 groups, Delete Microsoft 365 groups, Update M365 group members, Update M365 group owners, Restore deleted M365 groups, Update M365 group properties, Read hidden group members, Create cross-tenant access for Teams, Update cross-cloud meeting settings, Manage external user profiles for Teams, Manage pending external profiles, Read permission grant policies, Read network performance, Manage Skype for Business, Read usage reports, Manage all Teams policies (messaging, meeting, calling, app, etc.), Configure Teams phone system and calling plans, Manage Teams-certified devices Use Cases: Teams deployment and management, Meeting policy configuration for organization, Calling policy and phone system administration, Teams app governance and permissions, Teams device management (phones, displays, rooms), Cross-tenant meeting federation settings, Messaging policy and compliance configuration, Live events and webinar management, Teams channel and team governance, Guest access configuration for Teams, Teams analytics and reporting review, Shift management and frontline worker configuration ### Yammer Administrator URL: https://rbacmap.com/roles/entra-yammer-admin/ Privilege: Standard Description: Manage all aspects of the Yammer service including network settings, usage policies, and content moderation. Permissions: Manage Yammer network settings, Configure usage policies, Manage content and moderation, Create and manage M365 groups, View Yammer analytics, Configure external network access Use Cases: Yammer network configuration, Community management, Content moderation policies, External collaboration settings, Usage analytics and reporting ### Search Administrator URL: https://rbacmap.com/roles/entra-search-admin/ Privilege: Standard Description: Can create and manage all aspects of Microsoft Search settings including bookmarks, Q&A, and locations. Permissions: Manage Microsoft Search settings, Create and manage bookmarks, Manage Q&A content, Configure location settings, Manage floor plans, View search analytics Use Cases: Search experience optimization, Bookmark management for key resources, Q&A content curation, Floor plan configuration, Search analytics review ### Office Apps Administrator URL: https://rbacmap.com/roles/entra-office-apps-admin/ Privilege: Standard Description: Can manage Microsoft 365 apps cloud settings including policies, feature management, and whats new content. Permissions: Manage cloud policies for Office apps, Configure self-service download settings, Manage whats new feature visibility, View Office app usage reports, Configure Office app settings, Manage support tickets Use Cases: Office app policy configuration, Feature rollout management, Whats new content control, App usage analytics, Update channel management ### Service Support Administrator URL: https://rbacmap.com/roles/entra-service-support-admin/ Privilege: Standard Description: Can create and manage support requests with Microsoft for Azure and Microsoft 365 services. Permissions: Create Azure support tickets, Create M365 support tickets, View service dashboard, Read Message Center posts, Monitor service health, Manage support request lifecycle Use Cases: Opening support cases with Microsoft, Service health monitoring, Incident communication, Escalation management, Message Center monitoring ### Virtual Visits Administrator URL: https://rbacmap.com/roles/entra-virtual-visits-admin/ Privilege: Standard Description: Manage and share Virtual Visits information and metrics from admin centers or the Virtual Visits app. Permissions: Manage Virtual Visits settings, Configure booking policies, View visit analytics, Manage SMS notifications, Configure waiting room, Share usage metrics Use Cases: Healthcare virtual appointments, Customer consultation scheduling, Virtual meeting room configuration, Appointment analytics, SMS reminder configuration ### Knowledge Manager URL: https://rbacmap.com/roles/entra-knowledge-manager/ Privilege: Standard Description: Creates and manages content like topics, acronyms, and manages topic visibility and taxonomies. Permissions: Confirm topics, Approve topic edits, Delete topics, Manage taxonomies, Create content centers Use Cases: Topic curation, Knowledge quality assurance, Taxonomy management, Content organization, Expert identification ### Microsoft Graph Data Connect Administrator URL: https://rbacmap.com/roles/entra-graph-data-connect-admin/ Privilege: Standard Description: Manages Microsoft Graph Data Connect settings including dataset configuration and application authorization. Permissions: Enable/disable Data Connect, Configure dataset workloads, Manage cross-tenant data movement, Approve application requests, Manage app registrations Use Cases: Data pipeline configuration, Analytics enablement, Application authorization, Cross-tenant data governance, Bulk data access management ### Microsoft 365 Migration Administrator URL: https://rbacmap.com/roles/entra-m365-migration-admin/ Privilege: Standard Description: Performs all migration functionality to migrate content to Microsoft 365 using Migration Manager. Permissions: Select migration sources, Create migration inventories, Schedule and execute migrations, Download migration reports, Create SharePoint sites for migration, Manage migration project settings Use Cases: Google Drive migration, Dropbox migration, Box migration, Egnyte migration ### SharePoint Advanced Management Administrator URL: https://rbacmap.com/roles/entra-spo-advanced-mgmt-admin/ Privilege: HIGH Description: Performs all SharePoint Administrator actions plus advanced management capabilities like viewing file metadata and removing permissions. Permissions: All SharePoint Administrator permissions, View file/folder names, paths, URLs, Remove permissions from files/folders, View document metadata, Manage SharePoint advanced settings Use Cases: Content governance, Permission cleanup, Site restructuring, Compliance investigations ### SharePoint Backup Administrator URL: https://rbacmap.com/roles/entra-spo-backup-admin/ Privilege: Standard Description: Manages all aspects of Microsoft 365 Backup for SharePoint and OneDrive including backup policies and restore operations. Permissions: Create/manage backup policies, Perform restore operations, Manage SharePoint protection, Manage OneDrive protection, View restore points Use Cases: Disaster recovery, Content restoration, Backup policy management, Compliance retention ### SharePoint Embedded Administrator URL: https://rbacmap.com/roles/entra-spo-embedded-admin/ Privilege: Standard Description: Manages all aspects of SharePoint Embedded containers using PowerShell, Graph API, or SharePoint admin center. Permissions: Manage SharePoint Embedded containers, Configure container settings, Manage container permissions, Manage container storage, Apply compliance policies Use Cases: ISV application storage management, Container governance, Storage quota management, Compliance configuration ### Exchange Backup Administrator URL: https://rbacmap.com/roles/entra-exchange-backup-admin/ Privilege: Standard Description: Backs up and restores content including granular restore for Exchange Online in Microsoft 365 Backup. Permissions: Create Exchange backup policies, Perform mailbox restores, Manage Exchange protection, Granular item restore, View restore points Use Cases: Mailbox disaster recovery, Item-level restoration, Backup policy management, Compliance preservation ### Exchange Recipient Administrator URL: https://rbacmap.com/roles/entra-exchange-recipient-admin/ Privilege: Standard Description: Creates or updates Exchange Online recipients within the Exchange Online organization. Permissions: Create mailboxes, Update recipient properties, Manage distribution groups, Configure mail contacts, Manage resource mailboxes Use Cases: User mailbox provisioning, Distribution list management, Resource mailbox setup, Mail contact management ### Skype for Business Administrator URL: https://rbacmap.com/roles/entra-skype-admin/ Privilege: Standard Description: Can manage all aspects of the Skype for Business product. Legacy role retained for organizations still using Skype for Business features. Permissions: Manage all Skype for Business settings, Configure Skype policies and features, Manage Skype user settings, View Skype service health, Create and manage support tickets Use Cases: Managing legacy Skype for Business deployments, Skype to Teams migration planning, Maintaining Skype policies during transition, Hybrid Skype/Teams environment management ## Category: Organizational Management ### Organizational Branding Administrator URL: https://rbacmap.com/roles/entra-org-branding-admin/ Privilege: Standard Description: Manages all aspects of organizational branding including default and localized branding themes. Permissions: Create branding themes, Delete branding themes, Update branding properties, Manage localized branding, Configure sign-in page appearance Use Cases: Sign-in page customization, Brand consistency enforcement, Multi-language branding, Seasonal branding updates, Corporate identity management ### Organizational Messages Writer URL: https://rbacmap.com/roles/entra-org-messages-writer/ Privilege: Standard Description: Writes, publishes, and manages organizational messages delivered through Microsoft product surfaces. Permissions: Write organizational messages, Publish messages to users, Manage message delivery, Review message status, Delete messages Use Cases: Company announcements, Change management communications, Training reminders, Policy updates, Adoption campaigns ### Organizational Messages Approver URL: https://rbacmap.com/roles/entra-org-messages-approver/ Privilege: Standard Description: Reviews, approves, or rejects organizational messages before they are delivered to users. Permissions: Approve organizational messages, Reject organizational messages, Read all messages, Review pending messages Use Cases: Message quality control, Content approval workflow, Compliance review, Brand consistency enforcement ### People Administrator URL: https://rbacmap.com/roles/entra-people-admin/ Privilege: Standard Description: Manages profile photos for all users including administrators, and configures people settings like pronouns and name pronunciation. Permissions: Update profile photos for all users, Configure pronouns settings, Manage name pronunciation, Configure profile card settings, Manage people settings Use Cases: Corporate headshot management, Profile standardization, Pronouns enablement, Profile card configuration, Employee directory management ### Places Administrator URL: https://rbacmap.com/roles/entra-places-admin/ Privilege: Standard Description: Manages all aspects of Microsoft Places service including buildings, floors, rooms, desks, and booking policies. Permissions: Configure buildings and floors, Manage rooms and desks, Create booking policies, Oversee space management, Configure Places settings Use Cases: Hybrid workspace setup, Desk booking configuration, Room management, Building directory maintenance, Space optimization ### Extended Directory User Administrator URL: https://rbacmap.com/roles/entra-extended-directory-user-admin/ Privilege: Standard Description: Manages all aspects of external user profiles in the extended directory for Teams. Permissions: Manage external user profiles, Update extended directory entries, Configure Teams external profiles Use Cases: Teams external user management, Extended directory configuration, External profile maintenance ## Category: Remaining Built-in Roles ### Global Administrator URL: https://rbacmap.com/roles/entra-global-admin/ Privilege: HIGH Description: Can manage all aspects of Microsoft Entra ID and Microsoft services. This is the highest privilege role with the ability to reset any password, consent to any app, and elevate to Azure subscriptions. Permissions: Directory Resources - Full control over all directory resources, Password Reset - Reset passwords for any user including other Global Admins, App Consent - Consent to any application permissions on behalf of the organization, Azure Access - Elevate access to manage all Azure subscriptions, Security Policies - Configure all Conditional Access and Identity Protection policies, PIM Management - Manage PIM settings and role assignments, Emergency Accounts - Create and manage emergency access accounts, Federation - Configure federation and external identity providers, M365 Services - Manage all Microsoft 365 services (Exchange, SharePoint, Teams, etc.) Use Cases: Initial tenant setup and baseline configuration, Emergency break-glass administrative access, Assigning administrator roles when no other admin exists, Configuring cross-tenant trust relationships, Managing critical security incidents requiring full access, Setting up federation and external identity providers ### Global Reader URL: https://rbacmap.com/roles/entra-global-reader/ Privilege: HIGH Description: Can read everything that a Global Administrator can read, but cannot update anything. This is a PRIVILEGED role - the information visible can be used to plan attacks. Permissions: Directory Objects - Read all directory objects and properties, Service Health - Read Azure Service Health, Billing - Read billing information, Message Center - Read Message Center, Network - Read network performance, Security & Compliance - Read Security & Compliance, M365 Health - Read M365 Service Health, Usage Reports - Read usage reports, Conditional Access - Read all Conditional Access policies and settings, Identity Protection - Read all Identity Protection configurations, PIM - Read PIM settings and assignments, Audit Logs - Read all audit logs and sign-in reports, Applications - Read all application registrations and enterprise apps, Users & Groups - Read all user and group properties, Agents - View insights, organization data, and the agent registry in Microsoft Agent 365 (cannot install, modify, or approve agents), Limitation - Cannot make any modifications to any settings Use Cases: Security auditing and compliance reviews, IT managers needing visibility without edit rights, Consultants and contractors reviewing tenant configuration, Helpdesk supervisors monitoring settings, Executive dashboards and reporting access, Third-party security assessments, Configuration documentation and review, Monitoring for unauthorized changes, Compliance officer access for reviews, Vendor security questionnaire completion ### Privileged Role Administrator URL: https://rbacmap.com/roles/entra-priv-role-admin/ Privilege: HIGH Description: Can manage role assignments in Microsoft Entra ID and all aspects of Privileged Identity Management (PIM). This role can grant any role to any user including Global Administrator. Permissions: Access Reviews - Manage access reviews for role assignments, Admin Units - Create and manage administrative units, Authorization - Manage authorization policy, Directory Roles - Create and delete directory roles, Role Groups - Update role-assignable groups, Role Groups - Create role-assignable groups, Role Groups - Delete role-assignable groups, OAuth Grants - Manage OAuth 2.0 permission grants, PIM Management - Manage PIM, Role Assignments - Manage role assignments, Custom Roles - Create and manage custom role definitions, Scoped Roles - Manage scoped role memberships, App Roles - Update app role assignments, Service Principals - Update service principal permissions, App Consent - Grant consent for any permission, Role Assignment - Assign users to any Microsoft Entra role including Global Administrator, PIM Settings - Configure PIM settings including approval workflows, Role Groups - Create and manage role-assignable groups Use Cases: Managing PIM configurations and approval policies, Role assignment governance and delegation, Implementing least-privilege access model across the organization, Setting up approval workflows for sensitive role activations, Creating and managing custom role definitions, Configuring role-assignable groups for scalable administration, Managing access reviews for privileged role assignments, Implementing time-bound role assignments via PIM, Configuring Just-in-Time (JIT) access for all admin roles, Creating administrative units for delegated administration, Designing and implementing Entra ID RBAC strategy, Auditing and reviewing role assignment patterns ### Privileged Authentication Administrator URL: https://rbacmap.com/roles/entra-priv-auth-admin/ Privilege: HIGH Description: Can set or reset any authentication method (including passwords) for any user, including Global Administrators. This is one of the highest-privilege roles. Permissions: Auth Methods - Update auth methods for all users, Auth Methods - Create auth methods for all users, Auth Methods - Delete auth methods for all users, Auth Methods - Read auth method properties, Certificates - Update certificate user IDs property, User Properties - Update basic user properties, User Management - Delete any user including admins, User Management - Disable any user including admins, User Management - Enable any user, Session Management - Force sign-out for any user, User Management - Update manager for users, Password Reset - Reset passwords for ALL users including Global Admins, User Recovery - Restore deleted users, UPN Management - Update UPN for any user, User Recovery - Restore soft-deleted users, Support Tickets - Create and manage Azure support tickets, Support Tickets - Create and manage Microsoft 365 support tickets Use Cases: Emergency password resets for compromised Global Admin accounts, Resetting MFA for executives locked out of their accounts, Managing authentication for highly-privileged admin accounts, Incident response requiring credential reset for any user, Disabling compromised accounts across all privilege levels, Managing certificate-based authentication for admins, Forcing sign-out for suspected compromised admin sessions, Recovery scenarios when Global Admin is unavailable ### Security Administrator URL: https://rbacmap.com/roles/entra-security-admin/ Privilege: Standard Description: Can read security information and reports, and manage configuration in Microsoft Entra ID and Microsoft 365. This role has broad security configuration permissions across services. Permissions: Conditional Access - Update Conditional Access policies, Conditional Access - Create Conditional Access policies, Conditional Access - Delete Conditional Access policies, Identity Protection - Read all Identity Protection resources, Identity Protection - Update Identity Protection, Named Locations - Update named locations, Named Locations - Create named locations, Named Locations - Delete named locations, Policies - Update policies, Policies - Create policies, Policies - Delete policies, PIM - Read PIM settings, Audit - Read audit logs, Sign-in Reports - Read sign-in reports (including privileged), BitLocker - Read BitLocker keys, Cross-Tenant - Update cross-tenant access policy, Federation - Update federation settings, Multi-Tenant - Update multi-tenant organization, Global Secure Access - Manage Global Secure Access, Security Center - Update Security & Compliance Center, Attack Simulation - Manage attack simulation, Attack Simulation - Run attack simulations, M365 Security - Read and configure security-related features across Microsoft 365, Cloud App Security - Manage Microsoft Defender for Cloud Apps settings, Agents - Read visibility into agents and the Agent 365 registry in the Microsoft 365 admin center for investigation and risk assessment (cannot publish or manage agent lifecycle) Use Cases: Implementing and managing Conditional Access policies, Configuring Identity Protection risk policies, Managing security baselines and hardening, Responding to security incidents, Configuring attack simulation campaigns, Managing cross-tenant access policies for B2B, Implementing Zero Trust security model, Reviewing and analyzing security reports, Configuring named locations for risk assessment, Managing federation security settings, Configuring Global Secure Access (Entra Private/Internet Access), Implementing phishing-resistant authentication policies, Managing multi-tenant organization security ### Security Reader URL: https://rbacmap.com/roles/entra-security-reader/ Privilege: Standard Description: Can read security information and reports across Microsoft Entra ID, Identity Protection, Privileged Identity Management, and Microsoft 365 Defender. Permissions: Audit - Read audit logs, Authorization - Read authorization policy, BitLocker - Read BitLocker recovery keys, Conditional Access - Read Conditional Access policies, Cross-Tenant - Read cross-tenant policy, Device Credentials - Read device local credentials, Identity Protection - Read Identity Protection data, Named Locations - Read named locations, Policies - Read policies, PIM - Read PIM data, Provisioning - Read provisioning logs, Sign-in Reports - Read sign-in reports, Service Health - Manage Azure service health, Cloud PC - Read Cloud PC properties, Protection Center - Read protection center, Security Center - Read Security & Compliance Center, M365 Health - Manage M365 service health, Admin Center - Read admin center, Defender Portal - Access Microsoft Defender portal (read-only) Use Cases: Security analysts monitoring threats, Compliance officers reviewing security posture, Helpdesk staff investigating sign-in issues, SOC analysts reviewing security alerts, Auditors reviewing security configurations, Incident response team members, Security awareness program managers, Risk assessment analysts, Third-party security assessors (with caution) ### Billing Administrator URL: https://rbacmap.com/roles/entra-billing-admin/ Privilege: Standard Description: Can perform billing related tasks including purchases, subscription management, support tickets, and service health monitoring. Permissions: Service Health - Manage Azure service health, Support Tickets - Create Azure support tickets, Billing - Full billing management, Organization - Update organization properties, M365 Health - Manage M365 service health, Support Tickets - Create M365 support tickets, Admin Center - Read admin center properties, Purchases - Make purchases and manage subscriptions, Payment - Update payment methods and billing information, Invoices - View invoices and billing history, Cost Management - Manage cost management and budgets Use Cases: Finance team managing Microsoft subscriptions, Procurement staff handling license purchases, Managing payment methods and invoices, Subscription renewal management, Cost management and optimization, Budget tracking and forecasting, Billing dispute resolution, Invoice reconciliation ### License Administrator URL: https://rbacmap.com/roles/entra-license-admin/ Privilege: Standard Description: Can manage product licenses on users and groups. Can also manage usage location and read service plans but cannot purchase or manage subscriptions. Permissions: Group Licenses - Assign licenses to groups, Group Licenses - Reprocess license assignments, User Licenses - Assign licenses to users, User Licenses - Reprocess user license assignments, Usage Location - Update usage location for users, Service Health - Manage Azure service health, M365 Health - Manage M365 service health, Usage Reports - Read usage reports, Admin Center - Read admin center properties, License Inventory - View license usage and availability, User Properties - Read user properties for license assignment, Limitation - Cannot purchase new licenses or subscriptions Use Cases: IT helpdesk managing user licenses, HR onboarding/offboarding workflows, License optimization and reallocation, Group-based licensing administration, License audit and compliance, License usage reporting, Service plan assignment management, Usage location management for licensing ### User Administrator URL: https://rbacmap.com/roles/entra-user-admin/ Privilege: Standard Description: Can create users and groups, and manage all aspects of users and groups, including resetting passwords for limited admins. This is a privileged role with significant scope. Permissions: User Management - Add users, User Management - Delete users, User Management - Disable users, User Management - Enable users, User Properties - Update basic properties on users, User Management - Update manager for users, Password Reset - Reset passwords for all users (limited admin scope), User Properties - Update photo of users, UPN Management - Update User Principal Name, Licensing - Manage user licenses, Session Management - Force sign-out by invalidating refresh tokens, User Recovery - Restore deleted users, Guest Management - Invite guest users, Guest Management - Convert external to internal user, Group Management - Create Security and Microsoft 365 groups, Group Management - Delete groups (excluding role-assignable), Group Properties - Update group properties, Group Membership - Update group membership, Group Ownership - Update group owners, Group Recovery - Restore deleted groups, Group Settings - Update group settings, Contacts - Create contacts, Contacts - Delete contacts, Entitlement - Manage entitlement management, Access Reviews - Manage group access reviews, Service Principals - Update service principal role assignments, OAuth - Manage OAuth 2.0 permission grants Use Cases: HR-driven user lifecycle management (joiner/mover/leaver), IT helpdesk user support and password resets, Group administration and membership management, Password reset operations for end users and limited admins, User onboarding and provisioning workflows, License assignment and management, Guest user invitation and management, User property updates (job title, department, manager), Group creation for access management, User account recovery and restoration, Bulk user operations and imports, Self-service group management delegation, Entitlement management configuration ### Authentication Administrator URL: https://rbacmap.com/roles/entra-auth-admin/ Privilege: Standard Description: Can view, set, and reset authentication method information for any non-admin user. Cannot manage MFA settings or password protection policies. Permissions: Auth Methods - Create authentication methods for users, Auth Methods - Delete authentication methods for users, Auth Methods - Read standard authentication methods, Auth Methods - Update authentication methods for users, User Recovery - Restore recently deleted users, User Management - Delete users, User Management - Disable user accounts, User Management - Enable user accounts, Session Management - Invalidate user refresh tokens, Password Reset - Reset passwords for non-admin users, User Recovery - Restore deleted users, Service Health - Manage Azure service health, Support Tickets - Create and manage support tickets, MFA Management - Force re-registration of MFA for non-admin users, Auth Methods - Read user authentication method configuration, Limitation - Cannot manage admin user authentication Use Cases: Helpdesk password resets for end users, MFA enrollment and troubleshooting support, Authentication method registration assistance, Force MFA re-registration for non-admin users, Temporary Access Pass creation for onboarding, Windows Hello for Business enrollment support, FIDO2 security key registration assistance, Authenticator app setup support, Phone number verification for SMS/voice MFA, User account enable/disable operations, Refresh token invalidation for security incidents ### Authentication Policy Administrator URL: https://rbacmap.com/roles/entra-auth-policy-admin/ Privilege: Standard Description: Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials configuration. Permissions: Auth Policy - Full authentication policy management, MFA Settings - Manage MFA settings, Credential Policies - Create credential policies, Credential Policies - Delete credential policies, Credential Policies - Read credential policies, Credential Policies - Update credential policies, Credential Policies - Read credential policy owners, Credential Policies - Update credential policy owners, Verifiable Credentials - Read verifiable credentials config, Verifiable Credentials - Update verifiable credentials config, Verifiable Credentials - Read VC contracts, Verifiable Credentials - Update VC contracts, Verifiable Credentials - Read VC cards, Verifiable Credentials - Revoke VC cards, Verifiable Credentials - Create VC contracts, Auth Strength - Manage authentication strength requirements, Passwordless - Configure FIDO2, passwordless, and Windows Hello policies, Password Protection - Set password protection and banned password lists Use Cases: Implementing passwordless authentication strategy, Configuring MFA methods organization-wide, Setting password complexity requirements, Managing FIDO2 security key rollouts, Configuring Windows Hello for Business policies, Setting up verifiable credentials issuance, Defining authentication strengths for Conditional Access, Managing banned password lists, Configuring smart lockout settings, Certificate-based authentication configuration, Temporary Access Pass policy management, SMS and voice MFA policy configuration ### Helpdesk Administrator URL: https://rbacmap.com/roles/entra-helpdesk-admin/ Privilege: Standard Description: Can reset passwords for non-administrators and Helpdesk Administrators. Cannot manage service health, support tickets, or advanced user properties. Permissions: BitLocker - Read BitLocker recovery keys, Session Management - Invalidate user refresh tokens, Password Reset - Reset passwords for non-admin users, Service Health - Manage Azure service health, Support Tickets - Create and manage support tickets, M365 Health - Manage M365 service health, M365 Support - Create M365 support tickets, Admin Center - Read admin center properties, Password Reset - Reset passwords for other Helpdesk Admins, User Profiles - View user profiles and basic properties, Limitation - Cannot reset passwords for other admin roles Use Cases: First-line helpdesk password support, Self-service password reset backup, Basic user support operations, BitLocker recovery key retrieval, Session invalidation for compromised accounts, Service health monitoring and ticket creation, User lockout resolution, Temporary password provisioning ### Password Administrator URL: https://rbacmap.com/roles/entra-password-admin/ Privilege: Standard Description: Can reset passwords for non-administrators. Most limited password reset role without additional service health or support ticket access. Permissions: Password Reset - Reset passwords for non-admin users, Admin Center - Read admin center properties, Limitation - Cannot reset passwords for any admin roles, Limitation - Cannot invalidate refresh tokens, Limitation - Cannot manage authentication methods, Limitation - Cannot access BitLocker recovery keys, Limitation - Cannot create support tickets Use Cases: Limited helpdesk password operations, Minimal privilege password reset delegation, Self-service password reset backup, Delegated password reset in specific scenarios, Temporary staff with password reset needs ### Groups Administrator URL: https://rbacmap.com/roles/entra-groups-admin/ Privilege: Standard Description: Can create and manage all aspects of groups and group settings like naming and expiration policies, and manage group membership and ownership. Permissions: Group Licensing - Assign licenses to groups, Group Management - Create groups of all types, Group Management - Delete groups of all types, Group Membership - Read hidden group members, Group Membership - Update group membership, Group Ownership - Update group owners, Group Recovery - Restore deleted groups, Group Settings - Update group settings, Group Properties - Update basic group properties, Group Settings - Manage group settings, Group Templates - Read group setting templates, Service Health - Manage Azure service health, Support Tickets - Create and manage support tickets, M365 Health - Manage M365 service health, M365 Support - Create M365 support tickets, Naming Policy - Configure group naming policies, Expiration Policy - Set group expiration policies, Dynamic Groups - Configure dynamic group membership rules Use Cases: Group lifecycle management and governance, Dynamic group rule configuration, Group-based licensing administration, Microsoft 365 group governance, Group naming policy enforcement, Group expiration policy management, Security group administration, Distribution group management, Self-service group management oversight, Group-based access package configuration ### Guest Inviter URL: https://rbacmap.com/roles/entra-guest-inviter/ Privilege: Standard Description: Can invite guest users independent of the member invitation settings. This is the most limited guest invitation role. Permissions: Guest Invitation - Invite B2B guest users, User Properties - Read standard user properties, App Roles - Read user app role assignments, Device Access - Read device for resource account, Reports - Read direct reports, Licensing - Read license details, Management - Read user manager, Group Membership - Read group memberships, OAuth - Read OAuth2 grants, Guest Invitation - Bypass "members can invite guests" restrictions, Limitation - Cannot manage invited guest properties after invitation, Limitation - Cannot remove or disable guest users Use Cases: External collaboration coordinators, Partner relationship managers, Project teams needing external contractors, Vendor onboarding coordinators, Training program facilitators with external trainers, Cross-organizational project leads, External audit coordination ### Directory Readers URL: https://rbacmap.com/roles/entra-directory-readers/ Privilege: Standard Description: Can read basic directory information. Commonly used to grant directory read access to service principals and guest users. Permissions: Admin Units - Read administrative unit members, Admin Units - Read administrative unit properties, Applications - Read application owners, Applications - Read application policies, Applications - Read standard app properties, Contacts - Read contact group memberships, Contacts - Read contact properties, Contracts - Read contract properties, Devices - Read device group memberships, Devices - Read device owners, Devices - Read device users, Devices - Read device properties, Roles - Read eligible role members, Roles - Read role members, Groups - Read group memberships, Groups - Read group members, Groups - Read group properties, Organization - Read organization properties, Users - Read user properties Use Cases: Service accounts needing directory lookups, Applications integrating with Entra ID, Guest users needing directory visibility, Reporting applications reading directory data, HR systems synchronizing user data, Directory synchronization services, Address book population for email clients ### Directory Writers URL: https://rbacmap.com/roles/entra-directory-writers/ Privilege: Standard Description: Can read and write basic directory information. Primarily used for granting access to applications and services, not intended for end users. Permissions: Applications - Create applications as owner, Groups - Create security and M365 groups, Groups - Create groups as owner, Group Membership - Update group members, Group Ownership - Update group owners, Group Properties - Update basic group properties, OAuth - Create OAuth2 permission grants, OAuth - Update OAuth2 grants, Service Principals - Create service principals as owner, Licensing - Assign licenses to users, Users - Create new users, Users - Disable user accounts, Users - Enable user accounts, Session Management - Invalidate refresh tokens, User Management - Update user manager, User Properties - Update user photo, Directory Readers - All Directory Readers permissions Use Cases: Applications needing to provision users, Sync services updating directory attributes, Directory integration scenarios, Automated group management services, User provisioning applications, License assignment automation, Photo synchronization services ### Application Administrator URL: https://rbacmap.com/roles/entra-app-admin/ Privilege: HIGH Description: Can create and manage all aspects of app registrations and enterprise apps. This is a privileged role that can impersonate applications. Permissions: Applications - Create all types of applications, Applications - Delete all types of applications, App Roles - Update appRoles property, App Settings - Update audience property, Authentication - Update authentication settings, App Properties - Update basic properties, Credentials - Update application credentials, Extensions - Update extension properties, App Properties - Update notes, Ownership - Update owners, Permissions - Update permissions, Policies - Update policies, Verification - Update verification property, App Proxy - Read App Proxy properties, App Proxy - Update App Proxy settings, App Proxy - Update App Proxy auth, Certificates - Update SSL certs, URLs - Update URL settings, Provisioning - Read provisioning settings, Service Principals - Create service principals, Service Principals - Delete service principals, Service Principals - Disable service principals, Service Principals - Enable service principals, Role Assignments - Update role assignments, Credentials - Update credentials, Ownership - Update owners, Permissions - Update permissions, Policies - Update policies, Provisioning - Manage app provisioning, Consent - Grant consent except for Microsoft Graph/Azure AD Graph app permissions, OAuth - Manage OAuth 2.0 grants, App Policies - Create application policies, App Policies - Delete application policies, App Proxy - Manage App Proxy connector groups, App Proxy - Create App Proxy connectors, Custom Extensions - Manage custom auth extensions, Applications - Permanently delete applications, Applications - Restore deleted applications Use Cases: Managing SaaS application integrations (ServiceNow, Salesforce, etc.), Application development and registration for custom apps, Enterprise app consent and permissions management, Application Proxy deployment for on-premises apps, Configuring SSO for enterprise applications, Managing application credentials and certificates, Setting up user provisioning (SCIM) for applications, Configuring custom authentication extensions, Managing app roles and user/group assignments, Troubleshooting application authentication issues, Managing third-party gallery applications, Configuring claims mapping for SAML/OIDC apps ### Cloud Application Administrator URL: https://rbacmap.com/roles/entra-cloud-app-admin/ Privilege: Standard Description: Can create and manage all aspects of app registrations and enterprise apps except App Proxy. Ideal for cloud-only environments. Permissions: App Policies - Manage application policies, App Registrations - Full app registration management, App Registrations - Create application registrations, App Registrations - Delete application registrations, Credentials - Manage application credentials, Ownership - Manage application owners, Permissions - Update application permissions, Applications - Permanently delete apps, Applications - Restore deleted apps, OAuth - Manage OAuth grants, Service Principals - Manage service principals, Sync - Manage sync credentials, Sync - Manage sync jobs, Sync - Manage sync schema, Consent - Grant admin consent for applications, Limitation - Cannot manage Application Proxy applications or connectors Use Cases: Cloud-only application management, SaaS integration without on-premises needs, Application registration lifecycle management, Enterprise application configuration, API permission consent management, Service principal credential management, SCIM provisioning configuration, Application ownership delegation ### Application Developer URL: https://rbacmap.com/roles/entra-app-developer/ Privilege: Standard Description: Can create application registrations independent of the "Users can register applications" setting. Most limited application role. Permissions: App Registrations - Create app registrations as owner, OAuth - Create OAuth grants as owner, Service Principals - Create service principals as owner, Consent - Consent to applications on own behalf, Limitation - Cannot manage existing applications they don't own, Limitation - Cannot grant admin consent, Limitation - Cannot access other users' applications Use Cases: Developers needing to register apps for testing, Dev/test environment application creation, When "Users can register apps" is disabled organization-wide, Controlled developer access to app registration, Temporary access for specific development projects ### Cloud Device Administrator URL: https://rbacmap.com/roles/entra-cloud-device-admin/ Privilege: Standard Description: Can enable, disable, and delete devices in Microsoft Entra ID and read Windows BitLocker recovery keys in the Azure portal. Permissions: Audit - Read audit logs, BitLocker - Read BitLocker recovery keys, Devices - Delete devices from Entra ID, Devices - Disable devices in Entra ID, Devices - Enable devices in Entra ID, Device Credentials - Read device local credentials, Device Policies - Read device management policies, Registration - Read registration policies, Sign-in Reports - Read sign-in reports, Device Properties - View device properties and metadata, Limitation - Cannot enroll or configure devices via Intune, Limitation - Cannot manage Intune device policies Use Cases: Device lifecycle management in Entra ID, BitLocker key recovery for helpdesk support, Removing stale or compromised devices, Disabling lost or stolen devices, Device troubleshooting and diagnostics, LAPS password retrieval for local admin, Device cleanup and hygiene operations ### Windows Update Deployment Administrator URL: https://rbacmap.com/roles/entra-windows-update-admin/ Privilege: Standard Description: Can create and manage all aspects of Windows Update deployments through Windows Update for Business. Permissions: Deployments - Create and manage Windows Update deployment settings, Update Rings - Configure update rings and feature updates, Driver Updates - Manage driver updates and expedited updates, Reports - View Windows Update reports and compliance Use Cases: Windows patching and update management, Feature update deployment planning, Driver update administration ### Windows 365 Administrator URL: https://rbacmap.com/roles/entra-windows-365-admin/ Privilege: Standard Description: Can provision and manage all aspects of Cloud PCs. Permissions: Cloud PCs - Provision and deprovision Cloud PCs, Policies - Manage Cloud PC policies and settings, Provisioning - Configure provisioning policies, User Assignments - Manage Cloud PC user assignments, Health Monitoring - View Cloud PC health and performance Use Cases: Cloud PC deployment and management, Virtual desktop infrastructure administration, Cloud PC user provisioning ### Hybrid Identity Administrator URL: https://rbacmap.com/roles/entra-hybrid-id-admin/ Privilege: Standard Description: Can manage AD to Microsoft Entra cloud provisioning, Microsoft Entra Connect, pass-through authentication, and federation settings for hybrid environments. Permissions: Update application audience, Update app authentication, Create applications for cloud provisioning, Update application owners, Cloud provisioning management, Manage domain settings, Update domain federation, Hybrid auth policy, Update directory sync settings, Password hash sync, Manage Azure service health, Configure Microsoft Entra Connect settings, Manage cloud provisioning agents, Configure pass-through authentication, Manage AD FS and federation settings Use Cases: Microsoft Entra Connect deployment and management, Cloud provisioning agent configuration, Hybrid authentication configuration, Pass-through authentication setup, Password hash sync configuration, Federation and AD FS management, Directory synchronization troubleshooting, Hybrid migration planning and execution, Domain verification and configuration ### Domain Name Administrator URL: https://rbacmap.com/roles/entra-domain-name-admin/ Privilege: Standard Description: Can manage domain names in cloud and on-premises including adding, verifying, and removing custom domains. Permissions: Full domain management, Add new domains, Remove domains, Read domain properties, Update domain settings, Configure domain federation, Verify domain ownership, Add and verify custom domain names, Configure DNS records for domains, Remove domains from tenant Use Cases: Custom domain configuration for the tenant, Domain verification and DNS setup, Multi-domain tenant management, Domain federation configuration, UPN suffix management, Email domain configuration, Vanity domain setup ### Entra Backup Administrator URL: https://rbacmap.com/roles/entra-backup-admin/ Privilege: Standard Description: Manages all aspects of Microsoft Entra Backup including creating recovery jobs and managing backup snapshots for directory data. Permissions: Create and manage recovery jobs for Entra directory data, Manage backup snapshots and retention, View backup job status and history, Configure backup settings and schedules, Restore directory objects from backup Use Cases: Restoring accidentally deleted users or groups, Recovering from bulk directory changes, Disaster recovery for Entra ID directory data, Scheduled backup management for compliance, Point-in-time recovery of directory objects ### Entra Backup Reader URL: https://rbacmap.com/roles/entra-backup-reader/ Privilege: Standard Description: Read-only access to Microsoft Entra Backup including listing preview jobs, recovery jobs, and backup snapshots. Can create preview jobs to assess recovery scope. Permissions: List all preview jobs and their status, List all recovery jobs and their status, View backup snapshots and details, Create preview jobs to assess recovery scope, Read backup configuration and settings Use Cases: Auditing backup coverage and compliance, Assessing recovery scope before requesting a restore, Monitoring backup job health and status, Reporting on backup and recovery activities ### Partner Tier1 Support URL: https://rbacmap.com/roles/entra-partner-tier1-support/ Privilege: HIGH Description: Legacy Microsoft partner support role marked "Do not use". Per MC1409305, new assignments are being phased out as part of deprecated-role lifecycle management (rollout Aug 3–24, 2026). Replacements: User Administrator (primary), or GDAP / Customer Delegated Admin Relationship Administrator for partners. Permissions: Reset passwords for non-administrators, Invalidate refresh tokens for non-administrators, Create and manage support tickets in Azure and Microsoft 365 admin centers, Read service health information and messages Use Cases: NONE — Microsoft documents this role as "Do not use — not intended for general use", Internal scenarios: use User Administrator (primary), or Helpdesk / Groups / License / Domain Name Administrator (MC1409305 guidance), Partner-delegated access: migrate to GDAP via Customer Delegated Admin Relationship Administrator ### Partner Tier2 Support URL: https://rbacmap.com/roles/entra-partner-tier2-support/ Privilege: HIGH Description: Legacy Microsoft partner support role with elevated permissions (can reset admin passwords), marked "Do not use". Per MC1409305, new assignments are being phased out (rollout Aug 3–24, 2026). Replace with User Administrator, or License + Application Administrator; use GDAP for partners. Permissions: Reset passwords for any user including administrators (HIGH PRIVILEGE), Invalidate refresh tokens for any user, Delete and restore non-administrator users, Create and manage support tickets in Azure and Microsoft 365 admin centers, Read service health information and messages Use Cases: NONE — Microsoft documents this role as "Do not use — not intended for general use", Internal scenarios: use User Administrator, or a combination of License + Application Administrator (MC1409305 guidance), Partner-delegated access: migrate to GDAP via Customer Delegated Admin Relationship Administrator =============================================================================== # 3. EXCHANGE ONLINE (18 roles, 6 categories) # URL: https://rbacmap.com/services/exchange/ =============================================================================== ## Category: Organization Management ### Organization Management URL: https://rbacmap.com/roles/exo-org-admin/ Privilege: HIGH Description: Members have administrative access to the entire Exchange Online organization and can perform almost any task. This is the most powerful Exchange role group. Permissions: Audit Logs - Search and view audit logs, Compliance Admin - Configure compliance settings, Data Loss Prevention - Manage DLP policies, Distribution Groups - Full group management, E-Mail Address Policies - Manage email address policies, Federated Sharing - Configure cross-org sharing, Information Rights Management - IRM configuration, Journaling - Configure message journaling, Legal Hold - Place mailboxes on hold, Mail Recipients - Create/modify all recipients, Message Tracking - Track message delivery, Migration - Mailbox migration operations, Move Mailboxes - Move mailbox operations, Public Folders - Manage mail-enabled public folders, Remote and Accepted Domains - Domain management, Retention Management - Configure retention policies, Role Management - Manage role groups and assignments, Security Admin - Security configuration and reports, Transport Hygiene - Anti-spam/anti-malware settings, Transport Rules - Create/manage mail flow rules Use Cases: Primary Exchange Online administrators, Organizational-level administrative tasks, Managing organization-wide email policies, Configuring mail flow and security settings, Small organizations with few admins ### Exchange Administrator URL: https://rbacmap.com/roles/exo-exchange-admin/ Privilege: HIGH Description: Entra ID role that provides full administrative access to Exchange Online. Members are synchronized to the ExchangeServiceAdmins role group which inherits Organization Management permissions. Permissions: Inherits all Organization Management role group permissions, Manage all aspects of Exchange Online, Create and manage mailboxes and groups, Configure mail flow policies, Manage Exchange Online protection settings, View and manage Exchange reports, Configure compliance and retention settings Use Cases: Dedicated Exchange Online management, Hybrid Exchange environment administration, Email policy and compliance management, Preferred over Global Admin for Exchange-only tasks ### Help Desk URL: https://rbacmap.com/roles/exo-help-desk/ Privilege: Standard Description: Members can view and manage the configuration for individual recipients and view recipients in the Exchange organization. Limited to settings that users can manage on their own mailbox. Permissions: Reset Password - Reset room mailbox passwords, User Options - View and modify Outlook on the web options, View-Only Recipients - View recipient properties Use Cases: First-line email support, User mailbox troubleshooting, Viewing user mailbox configuration, Modifying settings users can manage themselves ## Category: Recipient Management ### Recipient Management URL: https://rbacmap.com/roles/exo-recipient-mgmt-role/ Privilege: Standard Description: Members have administrative access to create or modify Exchange Online recipients within the organization. Ideal for delegated administration of mailboxes and groups. Permissions: Distribution Groups - Create and manage distribution groups and mail-enabled security groups, Mail Recipient Creation - Create mail users and mail contacts, Mail Recipients - Modify existing mail users and mail contacts, Message Tracking - Track message delivery, Migration - Migrate mailboxes and content, Move Mailboxes - Move mailbox operations, Recipient Policies - Manage authentication, encryption, and OWA policies, Reset Password - Reset mailbox passwords Use Cases: User provisioning and deprovisioning, Group management for email distribution, Mailbox configuration and maintenance, Large organizations with dedicated recipient managers ### Mail Recipients URL: https://rbacmap.com/roles/exo-mail-recipients/ Privilege: Standard Description: Manage existing mailboxes and recipient settings without the ability to create new mailboxes. Permissions: Modify mailbox properties, Configure mailbox features, Manage mailbox permissions, Set out-of-office replies, Manage mail forwarding Use Cases: Day-to-day mailbox maintenance, Updating user mailbox settings, Managing mailbox forwarding and delegation ### Distribution Groups URL: https://rbacmap.com/roles/exo-distribution-groups/ Privilege: Standard Description: Create and manage distribution groups and mail-enabled security groups. Permissions: Create, modify, and delete distribution groups, Manage group membership, Configure group delivery settings, Set group moderation and restrictions, Manage mail-enabled security groups Use Cases: Group creation for departments or projects, Managing mailing lists, Email distribution management ### Shared Mailboxes URL: https://rbacmap.com/roles/exo-shared-mailboxes/ Privilege: Standard Description: Create and manage shared mailboxes, resource mailboxes, and room mailboxes. Permissions: Create shared, room, and equipment mailboxes, Manage shared mailbox access permissions, Configure resource booking settings, Set up room scheduling options, Manage shared mailbox delegates Use Cases: Creating departmental shared mailboxes, Setting up meeting room calendars, Managing equipment booking resources ## Category: Mail Flow ### Transport Rules URL: https://rbacmap.com/roles/exo-transport-rules/ Privilege: Standard Description: Create and manage mail flow rules (transport rules) that apply conditions and actions to messages passing through the organization. Permissions: Create, modify, and delete transport rules, Configure rule conditions, exceptions, and actions, Set rule priority and enable/disable rules, Export and import rule configurations, Test rules before enforcement Use Cases: Adding email disclaimers and signatures, Routing emails based on sender, recipient, or content, Enforcing email policies (encryption, moderation), Blocking or redirecting specific messages, Implementing DLP via transport rules (legacy) ### Connectors URL: https://rbacmap.com/roles/exo-connectors/ Privilege: Standard Description: Manage mail flow connectors that control how email flows between Exchange Online and external systems including on-premises Exchange, partner organizations, and third-party services. Permissions: Create inbound and outbound connectors, Configure partner organization connectors, Set up hybrid Exchange connectors, Configure TLS and certificate settings, Manage smart host routing, Configure Enhanced Filtering for Connectors Use Cases: Hybrid Exchange configuration with on-premises, Partner organization secure mail flow, Third-party email security gateway integration, Conditional mail routing scenarios, Smart host configuration ### Remote and Accepted Domains URL: https://rbacmap.com/roles/exo-accepted-domains/ Privilege: Standard Description: Manage remote domains, accepted domains, and connectors that define valid email domains and how external domains are treated. Permissions: Add and remove accepted domains, Configure domain types (Authoritative, Internal Relay, External Relay), Manage remote domain settings, Configure message format for external domains, Set default reply domain Use Cases: Adding new email domains to the organization, Configuring subsidiary or additional domains, Managing message format for partner domains, Setting up domain-based mail routing ## Category: Compliance & Security ### Compliance Management URL: https://rbacmap.com/roles/exo-compliance-mgmt/ Privilege: Standard Description: Members can configure and manage compliance settings within Exchange in accordance with organizational policies. Covers DLP, retention, journaling, and IRM. Permissions: Audit Logs - Search administrator audit log and view results, Compliance Admin - View and edit compliance feature settings, Data Loss Prevention - Manage DLP policies for mail flow rules, Information Rights Management - Configure IRM features, Journaling - Configure journaling rules, Message Tracking - Track messages in the organization, Retention Management - Manage retention policies, Transport Rules - Create and manage mail flow rules, View-Only Audit Logs - Search and view audit logs, View-Only Configuration - View organization settings, View-Only Recipients - View recipient properties Use Cases: Implementing email retention policies, Configuring DLP for Exchange mail flow, Setting up journaling for compliance, Managing Information Rights Management ### Discovery Management URL: https://rbacmap.com/roles/exo-discovery-mgmt/ Privilege: HIGH Description: Members can perform searches of mailboxes for data that meets specific criteria and can configure legal holds on mailboxes. By default, this role group has no members. Permissions: Legal Hold - Place mailboxes on Litigation Hold or In-Place Hold, Mailbox Search - Search mailbox content using In-Place eDiscovery Use Cases: Legal discovery requests and litigation, Internal investigations, Compliance audits, Placing mailboxes on legal hold ### Hygiene Management URL: https://rbacmap.com/roles/exo-hygiene-mgmt/ Privilege: Standard Description: Members can manage Exchange anti-spam features, grant permissions for antivirus products to integrate with Exchange, and manage mail flow rules for hygiene purposes. Permissions: Transport Hygiene - Manage anti-malware, anti-spam, and anti-spoofing features, View-Only Configuration - View organization and mail flow settings, View-Only Recipients - View recipient properties Use Cases: Managing email security policies, Configuring anti-spam and anti-malware settings, Reviewing and releasing quarantined messages, Third-party antivirus integration ### Records Management URL: https://rbacmap.com/roles/exo-records-mgmt/ Privilege: Standard Description: Members can configure compliance features such as retention policy tags, message classifications, and mail flow rules for records purposes. Permissions: Audit Logs - Search administrator audit log, Journaling - Configure journaling rules, Message Tracking - Track message delivery, Retention Management - Manage retention policies and tags, Transport Rules - Create and manage mail flow rules Use Cases: Implementing email lifecycle management, Configuring auto-archive policies, Managing retention for regulatory compliance, Setting up message journaling ## Category: Permissions & Delegation ### Role Management URL: https://rbacmap.com/roles/exo-role-mgmt/ Privilege: HIGH Description: Enables admins to manage management role groups, role assignment policies, management roles, role entries, assignments, and scopes. Core role for delegating Exchange administration. Permissions: Create, modify, and delete role groups, Add and remove role group members, Create and manage role assignment policies, Modify management role entries and scopes, Delegate role assignments to others Use Cases: Delegating Exchange administration to teams, Creating custom role groups with specific permissions, Managing role assignment policies for end users, Restricting role scope to specific organizational units ### Delegated Setup URL: https://rbacmap.com/roles/exo-delegation/ Privilege: Standard Description: Allows limited administrative access for initial Exchange setup and configuration tasks. Permissions: Perform initial Exchange configuration, Install and configure Exchange servers (hybrid), Add servers to existing Exchange organization, Limited post-installation configuration Use Cases: Hybrid Exchange deployment, Initial tenant configuration, Edge server setup ## Category: View-Only & Reporting ### View-Only Organization Management URL: https://rbacmap.com/roles/exo-view-only-org/ Privilege: Standard Description: Members can view the properties of any object in the Exchange Online organization. Read-only access for monitoring and auditing purposes. Permissions: View-Only Configuration - View all organization and mail flow settings, View-Only Recipients - View all recipient properties Use Cases: Auditing Exchange configuration, Monitoring without change access, Reporting and analysis, Compliance oversight ### View-Only Recipients URL: https://rbacmap.com/roles/exo-view-only-recipients/ Privilege: Standard Description: Read-only access to recipient and mailbox information. Permissions: View mailbox properties, View distribution group membership, View mail contact information, View recipient configurations, Cannot modify any settings Use Cases: Directory information access, Help desk lookup without modify, User directory viewing =============================================================================== # 4. MICROSOFT INTUNE (11 roles, 6 categories) # URL: https://rbacmap.com/services/intune/ =============================================================================== ## Category: Device & Endpoint Management ### Endpoint Security Manager URL: https://rbacmap.com/roles/intune-endpoint-security-mgr/ Privilege: HIGH Description: Manages security and compliance features including security baselines, device compliance, Conditional Access, and Microsoft Defender for Endpoint. Permissions: Device compliance policies - Full CRUD + Assign + View reports, Security baselines - Full CRUD + Assign, Endpoint Detection and Response - Full CRUD + View reports, Attack surface reduction - Full CRUD + View reports, App Control for Business - Full CRUD + View reports, Managed devices - Delete, Read, Set primary user, Update, View reports, Remote tasks - Reboot, Remote lock, Sync, Windows Defender, Rotate keys, Mobile Threat Defense - Modify + Read, Endpoint Privilege Management - Full policy authoring + elevation requests, Security tasks - Read + Update Use Cases: Security team managing device compliance, Configuring security baselines and policies, Managing Defender for Endpoint integration, Responding to security incidents on devices ### Policy and Profile Manager URL: https://rbacmap.com/roles/intune-policy-profile-mgr/ Privilege: Standard Description: Manages compliance policy, configuration profiles, Apple enrollment, corporate device identifiers, and security baselines. Permissions: Device configurations - Full CRUD + Assign + View reports, Device compliance policies - Full CRUD + Assign + View reports, Corporate device identifiers - Full CRUD, Enrollment programs - Full management (profiles, tokens, devices), Managed apps - Full CRUD + Assign, Policy Sets - Full CRUD + Assign, Quiet Time policies - Full CRUD + Assign + View reports, Filters - Full CRUD, Android Enterprise - Read, Update app sync, enrollment profiles, onboarding Use Cases: Creating and deploying configuration profiles, Managing device compliance policies, Setting up Apple DEP/ABM enrollment, Managing corporate device identifiers (IMEI, serial numbers) ### School Administrator URL: https://rbacmap.com/roles/intune-school-admin/ Privilege: Standard Description: Manages apps and settings for education groups. Can take remote actions on devices including lock, restart, and retire. Permissions: Device configurations - Full CRUD + Assign, Mobile apps - Full CRUD + Assign + Relate, Managed devices - Delete, Read, Set primary user, Update, Remote tasks - Wipe, Retire, Lock, Reboot, Reset passcode, Locate, and more, Enrollment programs - Full profile and token management, Customization - Full CRUD + Assign, Terms and conditions - Full CRUD + Assign, Remote Help - Elevation, Full control, View screen, Endpoint Analytics - Full CRUD Use Cases: K-12 and higher education IT administrators, Managing student and teacher devices, Deploying educational apps, Remote device support for classrooms ## Category: Application Management ### Application Manager URL: https://rbacmap.com/roles/intune-app-mgr/ Privilege: Standard Description: Manages mobile and managed applications, can read device information and view device configuration profiles. Permissions: Mobile apps - Full CRUD + Assign + Relate, Managed apps - Full CRUD + Assign + Wipe, Policy Sets - Full CRUD + Assign, Filters - Full CRUD, Cloud attached devices - View apps, Take app actions, View client details, Managed devices - Read only, Device configurations - Read only, Microsoft Store for Business - Read, Microsoft Defender ATP - Read Use Cases: Deploying line-of-business applications, Managing app protection policies (MAM), Configuring app configuration policies, Managing VPP/Apple Business Manager apps ## Category: Support & Operations ### Help Desk Operator URL: https://rbacmap.com/roles/intune-helpdesk/ Privilege: Standard Description: Performs remote tasks on users and devices, can assign applications or policies to users or devices. Permissions: Remote tasks - Wipe, Retire, Lock, Reboot, Reset passcode, Locate device, and 15+ more, Managed devices - Read, Set primary user, Update, View reports, Remote Help - Elevation, Full control, Unattended control, View screen, Mobile apps - Assign + Read, Managed apps - Assign, Read, Wipe, Device configurations - Read + View reports, Device compliance policies - Read + View reports, Enrollment programs - Read device, profile, token, ServiceNow - View Incidents Use Cases: First-line device support, Remote device troubleshooting, Password reset and device unlock, App assignment for users, Device location for lost devices ### Read Only Operator URL: https://rbacmap.com/roles/intune-readonly/ Privilege: Standard Description: Views user, device, enrollment, configuration, and application information. Cannot make changes to Intune. Permissions: All Intune areas - Read only, Device compliance policies - Read + View reports, Device configurations - Read + View reports, Managed devices - Read + View reports, Mobile apps - Read, Endpoint Analytics - Read, Security baselines - Read, Audit data - Read, Remote tasks - Get FileVault key only Use Cases: Auditors reviewing Intune configuration, Managers needing visibility without change capability, Reporting and analytics users, Compliance monitoring ## Category: Endpoint Privilege Management ### Endpoint Privilege Manager URL: https://rbacmap.com/roles/intune-epm-mgr/ Privilege: Standard Description: Manages Endpoint Privilege Management (EPM) policies in the Intune console. Full control over elevation rules and requests. Permissions: Endpoint Privilege Management Policy Authoring - Full CRUD + Assign + View reports, Endpoint Privilege Management Elevation Requests - Modify + View, Managed devices - Read, Organization - Read Use Cases: Creating EPM elevation rules, Approving/denying user elevation requests, Managing support-approved elevations, Configuring default elevation behavior ### Endpoint Privilege Reader URL: https://rbacmap.com/roles/intune-epm-reader/ Privilege: Standard Description: Views Endpoint Privilege Management (EPM) policies and elevation requests. Cannot make changes. Permissions: Endpoint Privilege Management Policy Authoring - Read + View reports, Endpoint Privilege Management Elevation Requests - View only, Managed devices - Read, Organization - Read Use Cases: Auditing EPM policies and rules, Viewing elevation request history, Compliance monitoring for least privilege, Reporting on elevation activity ## Category: Role Administration ### Intune Role Administrator URL: https://rbacmap.com/roles/intune-role-admin/ Privilege: HIGH Description: Manages custom Intune roles and adds assignments for built-in Intune roles. The only Intune role that can assign permissions to administrators. Permissions: Roles - Full CRUD + Assign, Organization - Read Use Cases: Creating custom Intune roles, Assigning built-in and custom roles to groups, Managing role scope tags, Delegating Intune administration ## Category: Cloud PC (Windows 365) ### Cloud PC Administrator URL: https://rbacmap.com/roles/intune-cloudpc-admin/ Privilege: Standard Description: Has Read and Write access to all Cloud PC features located within the Cloud PC area. Requires Windows 365 subscription. Permissions: Cloud PC - Full Read and Write access, Provisioning policies - Create, modify, delete, assign, User settings - Configure Cloud PC user experience, Network settings - Manage Azure network connections, Device images - Manage custom images, Cloud PC management - Reprovision, resize, restart Use Cases: Setting up Windows 365 for the organization, Creating provisioning policies, Managing Cloud PC lifecycle, Configuring user and network settings ### Cloud PC Reader URL: https://rbacmap.com/roles/intune-cloudpc-reader/ Privilege: Standard Description: Has Read access to all Cloud PC features. Cannot make changes. Requires Windows 365 subscription. Permissions: Cloud PC - Read access to all features, Provisioning policies - View only, User settings - View only, Network settings - View only, Device images - View only, Cloud PC status - View health and connectivity Use Cases: Auditing Cloud PC configuration, Viewing Cloud PC health and status, Reporting on Cloud PC usage, Monitoring without change capability =============================================================================== # 5. SHAREPOINT & ONEDRIVE (16 roles, 6 categories) # URL: https://rbacmap.com/services/sharepoint/ =============================================================================== ## Category: Tenant Administration ### SharePoint Administrator URL: https://rbacmap.com/roles/spo-admin/ Privilege: HIGH Description: Full access to the SharePoint admin center. Can create and manage sites, designate site admins, manage sharing settings, and manage Microsoft 365 groups. Permissions: SharePoint admin center - Full access to all settings and features, Sites - Create, delete, and manage all SharePoint sites, Site admins - Add and remove site collection administrators, Sharing settings - Configure organization-wide sharing policies, Microsoft 365 groups - Create, delete, restore, and change owners, Storage - Manage site storage limits and quotas, Access control - Configure unmanaged device and network policies, Self-access - Can grant themselves access to any site or OneDrive Use Cases: Managing SharePoint tenant settings, Creating and configuring team sites, Setting up external sharing policies, Managing storage quotas and limits ### Global Reader (SharePoint) URL: https://rbacmap.com/roles/spo-global-reader/ Privilege: Standard Description: Read-only access to SharePoint admin center settings and configurations. Cannot make changes but can view all settings. Permissions: SharePoint admin center - View all settings and configurations, Sites - View site details and properties, Sharing settings - View organization-wide policies, Storage - View storage usage and quotas, Reports - Access SharePoint usage reports Use Cases: Auditing SharePoint configuration, Compliance reviews and assessments, Executive dashboard access, Troubleshooting without change rights ### Migration Administrator URL: https://rbacmap.com/roles/spo-migration-admin/ Privilege: Standard Description: Manages content migration to Microsoft 365 including SharePoint sites, OneDrive, and Teams from sources like Google Drive, Dropbox, and Box. Permissions: Migration Manager - Full access in Microsoft 365 admin center, Migration sources - Select and configure Google Drive, Dropbox, Box, Egnyte, Migration inventories - Create and manage user lists and mappings, SharePoint sites - Create destination sites if they don't exist, SharePoint lists - Create and update items during migration, Migration lifecycle - Schedule, execute, and monitor migrations, Permission mappings - Configure source to destination mappings Use Cases: Migrating from Google Workspace to Microsoft 365, Consolidating content from multiple cloud sources, Large-scale organizational migrations, Scheduled batch migrations ## Category: Site Management ### Site Collection Administrator URL: https://rbacmap.com/roles/spo-site-admin/ Privilege: HIGH Description: Full control over a specific SharePoint site collection. Can manage all site settings, permissions, and content within their assigned site(s). Permissions: Site settings - Full access to all site configuration options, Permissions - Add/remove users and manage permission levels, Content - Full control over all lists, libraries, and pages, Site features - Activate and deactivate site features, Recycle bin - Access and restore deleted items (including second-stage), Storage - View site storage usage, Subsites - Create, manage, and delete subsites Use Cases: Department or team site administration, Project site management, Hub site administration, Intranet portal management ### Term Store Administrator URL: https://rbacmap.com/roles/spo-term-store-admin/ Privilege: Standard Description: Manages the organizational term store - a directory of common terms used across the organization for metadata and content classification. Permissions: Term store - Create and manage term groups and term sets, Terms - Add, modify, and delete terms, Synonyms - Create term synonyms and translations, Term set permissions - Delegate management to contributors, Import/Export - Import and export term sets Use Cases: Creating enterprise metadata taxonomy, Managing content types and classifications, Supporting information architecture, Enabling consistent tagging across sites ### Hub Site Administrator URL: https://rbacmap.com/roles/spo-hub-admin/ Privilege: Standard Description: Manages hub site registration and association. Can associate sites with hubs and configure hub-wide navigation and branding. Permissions: Hub registration - Register sites as hub sites, Site association - Associate/disassociate sites with hubs, Hub navigation - Configure shared navigation, Hub branding - Apply consistent branding to associated sites, Hub permissions - Control who can associate sites Use Cases: Creating departmental or regional hub sites, Building intranet navigation structure, Applying consistent branding across related sites, Connecting team sites to organizational hubs ## Category: Content & Permissions ### Site Owner URL: https://rbacmap.com/roles/spo-site-owner/ Privilege: Standard Description: Full control permission level on a SharePoint site. Can manage site settings, create lists and libraries, and control permissions for site members. Permissions: Site settings - Access most site configuration options, Lists and libraries - Create, modify, and delete, Pages - Create and edit site pages, Permissions - Manage site member and visitor permissions, Apps - Add and remove apps from the site, Subsites - Create subsites (if enabled) Use Cases: Team site ownership, Project site management, Department collaboration spaces, Community site administration ### Site Member URL: https://rbacmap.com/roles/spo-site-member/ Privilege: Standard Description: Edit permission level on a SharePoint site. Can add, edit, and delete content in lists and libraries but cannot manage site settings. Permissions: Lists and libraries - Add, edit, and delete items, Pages - Edit pages (if granted), Documents - Upload, edit, and delete files, Views - Create personal views, Alerts - Create alerts for changes Use Cases: Team collaboration, Document co-authoring, Project participation, Content contribution ### Site Visitor URL: https://rbacmap.com/roles/spo-site-visitor/ Privilege: Standard Description: Read permission level on a SharePoint site. Can view content but cannot add, edit, or delete items. Permissions: Content - View pages, lists, and documents, Views - View default and public views, Download - Download documents (unless blocked), Versions - View version history Use Cases: Intranet portal readers, Policy and procedure viewers, Executive dashboard access, External stakeholder read access ### Microsoft 365 Group Owner URL: https://rbacmap.com/roles/spo-m365-group-owner/ Privilege: HIGH Description: Owners of a Microsoft 365 group automatically become site collection administrators of the connected SharePoint team site. Permissions: SharePoint site - Site collection administrator rights, Group membership - Add and remove group members and owners, Teams - Manage connected Microsoft Teams (if any), Mailbox - Access group mailbox and calendar, Planner - Access group Planner plans Use Cases: Team collaboration spaces, Cross-service resource management, Modern team sites, Teams-connected sites ## Category: Sharing & External Access ### Sharing Settings Manager URL: https://rbacmap.com/roles/spo-sharing-admin/ Privilege: HIGH Description: Manages external sharing settings at organization and site levels. Controls how content can be shared with people outside the organization. Permissions: Organization sharing - Configure tenant-wide sharing policies, Site sharing - Set sharing levels for individual sites, Link settings - Configure anonymous link expiration and permissions, Domain restrictions - Allow/block specific email domains, Guest access - Manage guest user policies Use Cases: Enabling external collaboration, Restricting sharing for sensitive sites, Setting up partner sharing policies, Compliance-driven sharing restrictions ### Access Control Manager URL: https://rbacmap.com/roles/spo-access-control-admin/ Privilege: Standard Description: Manages access control settings including unmanaged device policies, network location restrictions, and app access controls. Permissions: Unmanaged devices - Allow, limit, or block access, Network location - Configure IP-based access restrictions, App access - Control third-party app access, Idle session - Set session timeout policies, Modern authentication - Enforce modern auth requirements Use Cases: Securing access from personal devices, Restricting access to corporate networks, Blocking legacy authentication, Preventing data download on untrusted devices ## Category: OneDrive Management ### OneDrive Administrator URL: https://rbacmap.com/roles/spo-onedrive-admin/ Privilege: HIGH Description: Manages OneDrive-specific settings including storage limits, sync policies, retention, and user OneDrive administration. Permissions: Storage limits - Set default and per-user storage quotas, Sync settings - Configure sync client policies and restrictions, Retention - Set OneDrive retention for deleted users, Notifications - Configure sharing notification settings, User OneDrive - Access and manage individual user OneDrive Use Cases: Managing OneDrive storage allocation, Configuring sync client group policies, Handling departed user OneDrive content, Troubleshooting individual user issues ### Sync Client Administrator URL: https://rbacmap.com/roles/spo-sync-admin/ Privilege: Standard Description: Configures OneDrive sync client settings via Group Policy or Intune. Controls sync behavior, file types, and bandwidth settings. Permissions: Sync policies - Configure via Group Policy or Intune, File exclusions - Block specific file types from sync, Bandwidth throttling - Set upload/download limits, Files On-Demand - Enable/disable on managed devices, Known Folder Move - Configure automatic folder backup, Tenant restrictions - Limit sync to approved organizations Use Cases: Enterprise sync client deployment, Restricting sync to managed devices, Bandwidth management for remote workers, Data protection via Known Folder Move ## Category: Advanced Management ### SharePoint Advanced Management Administrator URL: https://rbacmap.com/roles/spo-sam-admin/ Privilege: HIGH Description: Manages SharePoint Advanced Management (SAM) features including data access governance, content lifecycle management, and advanced access controls. Permissions: Data access governance - View oversharing and sensitivity reports, Site lifecycle - Manage inactive site policies, Block download - Apply download restrictions to sites, Conditional access - Configure authentication contexts for sites, Restricted site creation - Control who can create sites, Catalog management - Organize sites into governance groups Use Cases: Preparing for Copilot deployment, Reducing oversharing and data exposure, Managing inactive and stale sites, Implementing advanced access controls ### Restricted Site Creation Manager URL: https://rbacmap.com/roles/spo-restricted-creation-admin/ Privilege: Standard Description: Configures which users and apps can create SharePoint and OneDrive sites. Uses allow or deny mode with security groups. Permissions: User restrictions - Allow/deny groups for site creation, App restrictions - Allow/deny third-party apps for site creation, Site types - Configure policies per site type (Team, Communication, OneDrive), PowerShell management - Full Set/Get-SPORestrictedSiteCreation access Use Cases: Preventing site sprawl, Controlling shadow IT, Centralizing site provisioning, Meeting compliance requirements =============================================================================== # 6. MICROSOFT DEFENDER XDR (7 roles, 4 categories) # URL: https://rbacmap.com/services/defender/ =============================================================================== Defender XDR uses a Unified RBAC model where roles are tenant-defined. The entries below are suggested role compositions for common Defender scenarios — guidance, not Microsoft built-in role groups. ## Category: Security Operations ### Security Analyst URL: https://rbacmap.com/roles/defender-security-analyst/ Privilege: Standard Description: Investigates security incidents, hunts for threats, and analyzes alerts. Read-focused role with hunting and investigation capabilities. Permissions: Security data basics (read) - View incidents, alerts, investigations, devices, hunting data, Alerts (read) - View and triage alerts, Email & collaboration metadata (read) - View email data in hunting scenarios, Basic live response (manage) - Initiate sessions, download files for investigation Use Cases: Tier 1/2 SOC analysts triaging and investigating alerts, Threat hunters proactively searching for threats, Security researchers analyzing attack patterns ### Security Operations Manager URL: https://rbacmap.com/roles/defender-security-ops-manager/ Privilege: HIGH Description: Full access to security operations including all data, response actions, live response, and email security. Senior SOC leadership role. Permissions: Security data basics (read) - View all incidents, alerts, investigations, hunting, devices, Alerts (manage) - Manage alerts, start investigations, run scans, manage device tags, Response (manage) - Take response actions, approve/dismiss remediation, manage block lists, Advanced live response (manage) - Full live response with file uploads and script execution, File collection (manage) - Collect executable files for analysis, Email & collaboration quarantine (manage) - View and release quarantined email, Email & collaboration advanced actions (manage) - Move/delete email including hard delete, Email & collaboration metadata (read) - View email data in hunting and threat explorer, Email & collaboration content (read) - View and download email content and attachments, Data (manage) - Manage Sentinel data lake retention and connectors, Analytics job schedule (manage) - Schedule and manage analytics jobs Use Cases: SOC team leads managing security operations, Senior security analysts with full investigation authority, Security architects overseeing security posture ### Threat Hunting Analyst URL: https://rbacmap.com/roles/defender-threat-hunting-analyst/ Privilege: Standard Description: Proactively hunts for threats using advanced hunting queries, analyzes attack patterns, and identifies indicators of compromise. Specialized role focused on threat discovery. Permissions: Security data basics (read) - Full read access to all hunting tables, devices, alerts, incidents, Email & collaboration metadata (read) - View email data for hunting across email threats, Email & collaboration content (read) - Access email content for deep threat analysis, Basic live response (manage) - Investigate devices during active hunts Use Cases: Proactive threat hunting for unknown threats, Developing new hunting hypotheses and queries, Analyzing attack chains and lateral movement, Identifying indicators of compromise (IOCs) for Detection Engineer, Supporting incident investigations with deep analysis ### Incident Responder URL: https://rbacmap.com/roles/defender-incident-responder/ Privilege: Standard Description: Takes response actions to contain and remediate threats. Can isolate devices, manage quarantine, and perform live response. Permissions: Security data basics (read) - View incidents, alerts, investigations, devices, Alerts (manage) - Manage alerts, start investigations, manage device tags, Response (manage) - Take response actions, approve/dismiss remediation, manage block lists, Basic live response (manage) - Initiate sessions, download files, read-only device actions, Advanced live response (manage) - Full live response with file uploads and script execution, File collection (manage) - Collect files for analysis, Email & collaboration quarantine (manage) - View and release quarantined email, Email & collaboration advanced actions (manage) - Move/delete email to junk, deleted items Use Cases: Incident responders handling active threats, Tier 2/3 SOC analysts with remediation responsibilities, Emergency response teams ## Category: Security Detections ### Detection Engineer URL: https://rbacmap.com/roles/defender-detection-engineer/ Privilege: HIGH Description: Creates and manages custom detections, alert tuning, threat indicators, and advanced hunting queries. The single role for all detection-related activities. Permissions: Security data basics (read) - Full read access to hunting, devices, reports for detection development, Detection tuning (manage) - Manage custom detections, alert tuning, threat indicators, Email & collaboration metadata (read) - View email data for detection queries Use Cases: Detection engineers building custom detection rules, Threat intelligence teams managing indicators of compromise (IOCs), SOC teams tuning alert noise and false positives, Threat hunters creating reusable queries ## Category: XDR System Administration ### XDR SysAdmin URL: https://rbacmap.com/roles/defender-xdr-sysadmin/ Privilege: HIGH Description: Manages Defender XDR system including RBAC roles, device groups, core settings, and system configuration. The single administrative role for XDR platform management. Permissions: Authorization (manage) - Full management of device groups, custom roles, and role assignments, Core security settings (manage) - View and manage security settings across workloads, System settings (manage) - View and manage general portal settings and configurations Use Cases: IT security administrators managing Defender RBAC, IAM teams implementing least privilege access, Security architects designing role structures, Platform administrators configuring Defender settings ## Category: Security Posture Management ### Security Posture Manager URL: https://rbacmap.com/roles/defender-posture-manager/ Privilege: HIGH Description: Manages vulnerability management, exposure management, and security posture across the organization. The single role for all posture-related activities. Permissions: Vulnerability management (read) - View software inventory, vulnerabilities, weaknesses, missing KBs, Exception handling (manage) - Create and manage security recommendation exceptions, Remediation handling (manage) - Create remediation tickets and manage remediation activities, Application handling (manage) - Block/unblock vulnerable applications organization-wide, Security baseline assessment (manage) - Create and manage security baseline profiles, Exposure management (manage) - Manage exposure insights, Secure Score recommendations, and initiatives Use Cases: Vulnerability management team leads, Security posture improvement program owners, IT security teams coordinating remediation, Risk management teams prioritizing vulnerabilities, Secure Score optimization initiatives =============================================================================== # 7. MICROSOFT FABRIC (8 roles, 4 categories) # URL: https://rbacmap.com/services/fabric/ =============================================================================== Microsoft Fabric is a unified data platform built on OneLake. Workspaces are the primary unit of permission; capacities provide compute; governance domains group workspaces by business function. ## Category: Tenant Administration ### Fabric Administrator URL: https://rbacmap.com/roles/fabric-administrator/ Privilege: HIGH Description: Tenant-wide Fabric administration. Enable/disable Fabric features, configure tenant settings, monitor usage, manage audit logs, and govern embed codes. Cross-listed from Microsoft Entra ID (this is the same role as the entra-fabric-admin entry). Permissions: Tenant settings - Configure all Fabric tenant-level settings, Feature governance - Enable or disable Fabric features org-wide, Usage metrics - View tenant-wide adoption and consumption data, Audit logs - Review and manage Fabric audit activity (surfaces in Purview portal), Workspaces - View and govern all workspaces in the tenant, Embed codes - Manage embed codes for sharing reports publicly, Capacity - Pause, resume, and scale capacities Use Cases: Initial Fabric tenant configuration, Org-wide policy enforcement (data classification, export controls, sharing limits), Audit and compliance reporting on Fabric usage, Capacity planning and cost management ## Category: Capacity Administration ### Capacity Administrator URL: https://rbacmap.com/roles/fabric-capacity-admin/ Privilege: Standard Description: Per-capacity administration. Assigned when a Fabric/Power BI capacity is created. Controls workspace assignment to the capacity and workload-level memory configuration. Permissions: Workspaces - Assign or unassign workspaces to this capacity, Capacity permissions - Manage who can use the capacity, Workloads - Configure memory and workload-specific settings on the capacity, Refresh summary - View capacity refresh schedules and history Use Cases: Departmental capacity admin (e.g. one capacity per business unit), Delegating Fabric capacity ops without giving full tenant access, Managing capacity-bound workspaces during reorganisations ## Category: Workspace Roles ### Workspace Admin URL: https://rbacmap.com/roles/fabric-workspace-admin/ Privilege: Standard Description: Highest workspace role. Full control over a Fabric workspace including settings, identity, Git integration, and member management. Permissions: Workspace settings - Update and delete the workspace, Members - Add or remove members, contributors, viewers, and other admins, Reshare - Allow others to reshare items, Items - Create, modify, write, and delete all item types (notebooks, pipelines, warehouses, lakehouses, eventhouses, ML models, semantic models, reports), Workspace identity - Create and manage workspace identity for secure connections, Git integration - Connect workspace to an Azure DevOps or GitHub repository, Read all data - OneLake APIs, Spark, TDS endpoints, Lakehouse explorer, Execute - Run notebooks, pipelines, Spark jobs, ML experiments, Gateways - Schedule refreshes and modify gateway connection settings Use Cases: Workspace owner / data product lead, Lifecycle management (workspace creation, deletion, Git setup), Onboarding/offboarding workspace members ### Member URL: https://rbacmap.com/roles/fabric-workspace-member/ Privilege: Standard Description: Add members or others with lower permissions and reshare items. Full item authoring rights but cannot delete the workspace or manage workspace identity. Permissions: Members - Add Members, Contributors, Viewers (but not Admins), Reshare - Allow others to reshare items, Items - Create, modify, write, and delete all item types, Read all data - OneLake APIs, Spark, TDS endpoints, Lakehouse explorer, Execute - Run notebooks, pipelines, Spark jobs, ML experiments, Gateways - Schedule refreshes and modify gateway connection settings Use Cases: Senior data engineers or analysts on a team, Day-to-day workspace operations without admin responsibility ### Contributor URL: https://rbacmap.com/roles/fabric-workspace-contributor/ Privilege: Standard Description: Create and modify items, execute notebooks/pipelines, read all data. Cannot add members, reshare items, or manage workspace settings. Permissions: Items - Create, modify, write, and delete all item types, Read all data - OneLake APIs, Spark, TDS endpoints, Lakehouse explorer, Execute - Run notebooks, pipelines, Spark jobs, ML experiments, Gateways - Schedule refreshes and modify gateway connection settings Use Cases: Data engineers building pipelines, notebooks, and warehouses, Analysts building reports and semantic models, Most common day-to-day authoring role ### Viewer URL: https://rbacmap.com/roles/fabric-workspace-viewer/ Privilege: Standard Description: Read-only access to workspace items. View reports, notebooks, pipelines, and execution output. Read data through TDS endpoints but not through Spark or OneLake APIs. Permissions: View - Read content of pipelines, notebooks, Spark job definitions, ML models, experiments, eventstreams, View - Read content of KQL databases, KQL querysets, real-time dashboards, Read data (TDS) - Read Lakehouse and Data Warehouse data through SQL analytics endpoint (T-SQL ReadData level), View execution output - Pipelines, notebooks, ML models and experiments Use Cases: Report consumers, Auditors and compliance reviewers, Business stakeholders viewing dashboards without authoring rights ## Category: Governance Domains ### Domain Admin URL: https://rbacmap.com/roles/fabric-domain-admin/ Privilege: Standard Description: Full administration of a Fabric governance domain. Assign workspaces to the domain, configure domain settings, manage domain contributors, and govern the data products published into the domain. Permissions: Domain settings - Configure domain name, description, image, contributors, Workspace assignment - Add or remove workspaces from the domain, Subdomain management - Create and manage subdomains, Delegated tenant settings - Override certain tenant settings within the domain (when delegated by Fabric Administrator), Domain default workspace - Set the default workspace for domain content Use Cases: Business unit data lead governing their unit's Fabric workspaces, Decentralised data mesh implementations (domain per data product team), Federated governance model where tenant Fabric Admin delegates per-domain ops ### Domain Contributor URL: https://rbacmap.com/roles/fabric-domain-contributor/ Privilege: Standard Description: Contribute to a Fabric governance domain. Can assign their own workspaces to the domain and publish content into it, but cannot manage domain settings or other contributors. Permissions: Workspace association - Associate owned workspaces with the domain, Domain content - Publish content to the domain, View domain - See domain settings and membership (read-only) Use Cases: Workspace owners publishing data products to a shared domain, Citizen data engineers contributing to a business unit's domain catalogue =============================================================================== # 8. MICROSOFT SECURITY COPILOT (3 roles, 2 categories) # URL: https://rbacmap.com/services/copilotsec/ =============================================================================== Microsoft Security Copilot is a generative-AI security assistant. The native authorization surface is small (Copilot Owner / Contributor) plus a bootstrap entry-point used to provision the tenant before native roles take over. ## Category: Platform Roles ### Copilot Owner URL: https://rbacmap.com/roles/copilotsec-owner/ Privilege: HIGH Description: Full control over the Security Copilot workspace. Manages role assignments, plugin governance, file uploads, prompt history, and audit settings. Permissions: Workspace management - Configure all Copilot workspace settings, Role assignments - Add or remove Owners and Contributors, Plugins - Install, enable, disable, and govern plugins (Microsoft and third-party), File uploads - Manage uploaded files and configure upload settings, Prompt history - View prompt history across all users, Audit - Review Copilot audit logs (also surfaces in Purview), Capacity - Manage provisioned Copilot capacity (SCUs) Use Cases: Initial Security Copilot provisioning and configuration, Governing which plugins are available to users, Tier 3 SOC lead managing Copilot for the security team, Compliance review of Copilot prompt history ### Copilot Contributor URL: https://rbacmap.com/roles/copilotsec-contributor/ Privilege: Standard Description: Use Security Copilot to investigate threats, run prompts, and create promptbooks. Cannot manage workspace settings, plugins, or other users. Permissions: Prompts - Submit prompts to Copilot in the standalone portal, Promptbooks - Create, edit, and run promptbooks (saved prompt sequences), Sessions - View own session history, Shared sessions - View sessions explicitly shared with the user, Plugins - Use enabled plugins (cannot install or govern), File uploads - Upload files to Copilot if enabled by an Owner Use Cases: SOC analyst running incident-investigation prompts, Threat hunter using promptbooks for repeatable hunting workflows, Security engineer using Copilot to write or explain KQL queries, Compliance analyst using Copilot to summarise audit findings ## Category: Bootstrap & Entry-Point Roles ### Security Administrator (Bootstrap) URL: https://rbacmap.com/roles/copilotsec-bootstrap-secadmin/ Privilege: Standard Description: The Entra ID Security Administrator role is the bootstrap entry point for Security Copilot — it provisions Copilot capacity and assigns the first Copilot Owner. Cross-listed from Entra ID for discoverability. Permissions: Capacity provisioning - Create Security Copilot capacity in Azure, Initial Owner assignment - Assign the first Copilot Owner role, All other Entra Security Administrator permissions (see Entra ID map) Use Cases: Initial Copilot rollout, Adding capacity for growing SOC usage =============================================================================== # 9. MICROSOFT POWER PLATFORM (14 roles, 3 categories) # URL: https://rbacmap.com/services/powerplatform/ =============================================================================== Microsoft Power Platform spans Power Apps, Power Automate, Power BI, Power Pages, and Dataverse. Authorization happens at three layers: tenant-wide administrators, per-environment roles, and Dataverse security roles assigned inside an environment. ## Category: Tenant Administration ### Power Platform Administrator URL: https://rbacmap.com/roles/pp-platform-admin/ Privilege: HIGH Description: Tenant-wide administration of Power Platform: manage all environments, capacity, DLP policies, tenant settings. Cross-listed from Microsoft Entra ID. Permissions: Environments - Create, manage, and delete all environments in the tenant, DLP policies - Configure tenant-wide Data Loss Prevention policies for connectors, Capacity - Manage Power Platform capacity (storage, API requests, AI Builder credits), Tenant settings - Configure tenant-level Power Platform settings, Admin center - Full access to https://admin.powerplatform.microsoft.com, Analytics - View tenant-wide usage analytics, Recommendations - Manage tenant-level recommendations and best practices, Connections & gateways - Govern enterprise data gateways Use Cases: Platform owner / Centre of Excellence (CoE) lead, Org-wide DLP policy enforcement for citizen developers, Cross-environment governance and reporting ### Dynamics 365 Administrator URL: https://rbacmap.com/roles/pp-d365-admin/ Privilege: Standard Description: Tenant-wide administration of Dynamics 365 apps and the Dataverse environments hosting them. Cross-listed from Microsoft Entra ID. Permissions: Environments - Manage Dataverse environments hosting D365 apps, D365 apps - Configure Sales, Customer Service, Field Service, Marketing, Finance, Business Central, etc., Service health - View Dynamics 365 service health, Admin center - Access https://admin.powerplatform.microsoft.com, Support - Open Dynamics 365 support requests Use Cases: D365 platform lead, Solution architect for D365 deployments ### Power Apps Administrator URL: https://rbacmap.com/roles/pp-powerapps-admin/ Privilege: Standard Description: Tenant-wide administration of Power Apps. Lower-privilege alternative to Power Platform Administrator for organisations only using Power Apps. Cross-listed from Microsoft Entra ID. Permissions: Environments - Manage Power Apps environments, Apps - View and govern apps across the tenant, Flows - View and govern Power Automate flows, Admin center - Access Power Platform admin center for Power Apps scope Use Cases: Power Apps-only organisations, Delegated admin for the Power Apps footprint when D365 is admin-managed separately ## Category: Environment Roles ### Environment Admin URL: https://rbacmap.com/roles/pp-env-admin/ Privilege: Standard Description: Full administration of a single Power Platform environment. Manage members, environment settings, Dataverse provisioning, backups, and capacity allocation. Permissions: Members - Add or remove environment members and assign security roles, Settings - Configure environment-level settings (region, type, security), Dataverse - Add or remove a Dataverse database to the environment, Backups - Create on-demand backups and restore points, Capacity - Allocate capacity to the environment, Apps & flows - View and manage all apps and flows in the environment, Connections - Manage connection references and shared connections Use Cases: Business unit IT lead managing their team's environment, Solution architect during a Power Apps project, Delegated environment ownership in a federated governance model ### Environment Maker URL: https://rbacmap.com/roles/pp-env-maker/ Privilege: Standard Description: Create apps, flows, custom connectors, and other resources in an environment. Standard role for citizen developers. Permissions: Apps - Create canvas apps, model-driven apps, and Power Pages sites, Flows - Create Power Automate cloud flows and desktop flows, Custom connectors - Create and manage custom connectors, Connection references - Create and manage connections, Environment resources - Create and own resources without managing other members Use Cases: Citizen developers in a managed environment, Pro developers building apps without admin responsibility, Default role for licensed Power Apps users ## Category: Dataverse Security Roles ### System Administrator URL: https://rbacmap.com/roles/pp-dv-sysadmin/ Privilege: HIGH Description: Highest Dataverse security role. Full control over the Dataverse environment including schema, security roles, and all data. Permissions: Schema - Create, modify, and delete tables, columns, relationships, Security roles - Create and assign Dataverse security roles, All records - Full create, read, update, delete, append, append-to, assign, share on all tables, Solutions - Import, export, and manage solutions, Business units - Manage the business unit hierarchy, Field security - Configure column-level security profiles Use Cases: Dataverse platform owner, Solution implementer (typically removed post-deployment) ### System Customizer URL: https://rbacmap.com/roles/pp-dv-syscustomizer/ Privilege: Standard Description: Full schema customisation rights but limited to user-owned records for data operations. Common role for app makers and Dataverse developers. Permissions: Schema - Create, modify, and delete tables, columns, relationships, forms, views, Solutions - Create, import, and export solutions, Customisations - Configure business rules, workflows, processes, Records - Create/Read/Write/Delete on user-owned records (NOT all records like System Administrator) Use Cases: App maker building a model-driven app, Dataverse developer creating tables and forms, Solution architect during development ### Basic User URL: https://rbacmap.com/roles/pp-dv-basic-user/ Privilege: Standard Description: Baseline Dataverse role. Run apps, create user-owned records, read shared records. Required minimum for any Dataverse user. Permissions: Apps - Run model-driven apps the user is shared on, Records - Create, read, update, delete user-owned records, Activities - Create and manage own activities, Personal views - Create and manage own views and charts Use Cases: Default role for end users of a model-driven app, Pair with custom security roles for table-specific access ### Delegate URL: https://rbacmap.com/roles/pp-dv-delegate/ Privilege: Standard Description: Run apps and flows on behalf of another user. Used by Power Automate child flows and impersonation scenarios. Permissions: Impersonation - Act on behalf of another user in Dataverse, Used by Power Automate "Run as" patterns Use Cases: Service account that runs flows on behalf of users, Custom integrations that need elevated impersonation ### Environment Maker (Dataverse role) URL: https://rbacmap.com/roles/pp-dv-env-maker-dv/ Privilege: Standard Description: Dataverse-side security role granted automatically when Environment Maker is assigned at the environment level. Creates apps that store data in Dataverse. Permissions: Apps - Create canvas and model-driven apps storing data in Dataverse, Custom connectors - Create custom connectors, Solutions - Create unmanaged solutions Use Cases: Auto-assigned when a user is added as Environment Maker at the platform level ### App Opener URL: https://rbacmap.com/roles/pp-dv-app-opener/ Privilege: Standard Description: Allows a user to open and run a model-driven app but does not grant access to data inside the app. Always paired with another role that grants the actual data access. Permissions: Apps - Open and run model-driven apps the user is shared on, No data privileges - Must be combined with another role for read/write/delete access Use Cases: Lightweight role for users who need to launch an app without baseline Dataverse table access, Pair with custom security roles for narrow per-app access ### Office Collaborator URL: https://rbacmap.com/roles/pp-dv-office-collab/ Privilege: Standard Description: Legacy Microsoft 365 collaboration role for Dataverse. Grants minimal Dataverse access to support O365 integration scenarios. Rarely assigned in modern deployments. Permissions: Read access to specific tables required for Office 365 collaboration features, Limited scope - mostly used by Dataverse-Outlook / Dataverse-SharePoint integrations Use Cases: Legacy O365 + Dataverse integration scenarios, Rarely assigned directly today - mostly inherited via Office integration ### Support User URL: https://rbacmap.com/roles/pp-dv-support-user/ Privilege: Standard Description: Read-only access across most Dataverse tables for support and troubleshooting scenarios. Cannot modify data or schema. Permissions: Read - User-level read across most Dataverse tables, Read system jobs and async operations, No write/delete - Cannot modify records, No schema - Cannot create or modify tables/columns Use Cases: Support engineers diagnosing user issues, Tier 2/3 helpdesk reviewing system jobs and workflow runs, Customer service representatives investigating record state without modifying it ### Website Owner URL: https://rbacmap.com/roles/pp-dv-website-owner/ Privilege: Standard Description: Power Pages (formerly Power Apps Portals) website administration role. Manages a Power Pages site including pages, content, web roles, and authentication settings. Permissions: Website settings - Configure Power Pages site settings, branding, and themes, Content - Manage web pages, web files, content snippets, and site markers, Web roles - Create and manage Power Pages web roles (portal-side authorisation), Authentication - Configure identity providers (Microsoft Entra, Google, Facebook, custom OIDC/SAML), Web templates - Manage Liquid templates and web templates, Tables - Access Dataverse tables used by the portal Use Cases: Power Pages site administrator, Webmaster managing customer-facing portal, Configuring B2C authentication for a Power Pages site =============================================================================== # APPENDIX =============================================================================== ## Role Builder (Least-Privilege Recommendations) URL: https://rbacmap.com (click Role Builder or press B) Select from task categories to find minimum-permission roles. Categories include: eDiscovery operations, audit log management, DLP policy management, sensitivity label management, insider risk investigation, records management, identity management, conditional access, application management, device management, mail flow, SharePoint site management, security operations, Fabric workspace administration, Power Platform environment governance, Dataverse data operations, and Security Copilot administration. ## Role Comparison Compare permissions of multiple roles side-by-side. ## GDAP (Granular Delegated Admin Privileges) RBACMap shows which Entra ID roles support GDAP and which of 15 workloads they can access. Essential for Microsoft partners managing customer tenants. ## Deep Linking (canonical clean paths — use these when citing) - Service: https://rbacmap.com/services/purview/ - Role: https://rbacmap.com/roles/entra-ca-admin/ - Search: https://rbacmap.com/?search=compliance Legacy `?service=` and `?role=` query strings still work via 301 redirects. ## Keyboard Shortcuts - B: Open Role Builder - /: Focus search - Esc: Close panels --- Source: https://rbacmap.com | GitHub: https://github.com/AusSherro/RBACMap