Microsoft Purview RBAC Roles
Browse all Microsoft Purview RBAC roles by category. Find least-privilege permissions for compliance, eDiscovery, DLP, insider risk, and information protection.
108 roles across 18 categories. Open the interactive map →
Global & Security Roles
Organization-wide admin and security roles that span all Purview features
-
Global Administrator
Full administrative access to all Microsoft 365 and Purview features. However, Global Admin does NOT automatically grant access to certain Purview role groups.
-
Global Reader
Read-only access across all Microsoft 365 and Purview features without the ability to make changes.
-
Security Administrator
Manage security features across Microsoft 365 including Purview compliance, Defender, identity protection, and security policies without full Global Admin access.
-
Security Reader
Read-only access to security features, reports, and alerts across Microsoft 365 including Purview compliance monitoring.
-
Compliance Administrator
Comprehensive Entra ID role with broad permissions across Microsoft Purview compliance features including DLP, retention, sensitivity labels, eDiscovery, and compliance management.
-
Compliance Data Administrator
Enhanced Entra ID role with all Compliance Administrator permissions PLUS device management, Content Explorer access, and advanced file activity tracking capabilities.
-
Quarantine Administrator
Members can access all quarantine actions in Microsoft Defender for Office 365 and Exchange Online Protection. Can release, delete, preview, and manage quarantined messages and files.
-
Purview Consumption Management
Manage and view Purview consumption billing reports. Provides access to consumption-based licensing reports and usage analytics for Microsoft Purview services.
-
Organization Management
Top-level Purview role group. Members can control permissions for accessing features in the Microsoft Purview, Defender, and compliance portals, and manage settings for device management, data loss…
-
Security Operator
Members can manage security alerts, and also view reports and settings of security features. SOC operator role — focused on alert triage and response without broader security administration…
-
Service Assurance User
Members can access the Service Assurance section in the Microsoft Purview portal. Service Assurance provides reports and documents that describe Microsoft's security practices for customer data…
-
AI Administrators
In addition to the capabilities of the AI Administrator role in Microsoft Entra, this group assigns read-only permissions for AI security insights in Microsoft Purview. Used for governing Microsoft…
-
Billing Administrator
Configure billing features in Microsoft Purview. Used for Purview consumption-based billing configuration (separate from broader Microsoft 365 billing administration).
-
MailFlow Administrator
Members can monitor and view mail flow insights and reports in the Microsoft Defender portal. Read-focused role for understanding mail flow patterns, queues, and delivery issues without permission to…
eDiscovery
Legal hold, content search, and case management for investigations
-
eDiscovery Manager
Create and manage eDiscovery (Standard and Premium) cases with custodian management, review sets, legal hold notifications, advanced indexing, analytics, and ML-powered predictive coding.
-
eDiscovery Administrator
All eDiscovery Manager permissions PLUS organization-wide access to all cases, global eDiscovery settings management, and hold report oversight across entire tenant.
-
Data Investigator
Perform searches and access review sets for investigation without case management capabilities.
-
Reviewer
Access review sets in eDiscovery cases to analyze collected data without search or export capabilities.
-
Custodian
Identify and manage custodians (data owners) for eDiscovery cases and track their data sources.
-
Hold
Place and manage legal holds on content to preserve it during investigations and litigation.
Audit
Activity logging and audit log search across Microsoft 365
-
Audit Manager
Search, manage, and configure audit log settings and retention policies for compliance monitoring.
-
Audit Reader
Search and export audit logs with read-only access, without ability to configure settings.
Records Management
Retention labels, file plans, and regulatory records management
-
Records Management
Configure retention labels for records, file plans, and disposition reviews for formal records management programs with regulatory-grade immutability.
-
Disposition Management
Review and approve content disposition at end of retention period to ensure proper record destruction with proof of disposal and audit trail.
-
View-Only Records Management
Read-only access to records management features for auditing, compliance reporting, and oversight without modification permissions.
Data Lifecycle Management
Retention policies and data lifecycle automation
-
Retention Management
Create and manage retention policies and labels across Microsoft 365 to ensure compliance with data retention requirements.
-
View-Only Retention Management
Read-only access to retention policies, labels, and analytics for auditing, compliance reporting, and oversight without modification permissions.
Communication Compliance
Policy-based monitoring of communications for regulatory compliance
-
Communication Compliance
Full access to configure policies, investigate alerts, remediate violations, and manage all aspects of communication monitoring.
-
Communication Compliance Admins
Configure policies and settings but cannot investigate alerts or view message content - separated administration.
-
Communication Compliance Analysts
Access and investigate alerts, view message metadata, but cannot view full message content - limited investigation access.
-
Communication Compliance Investigators
Investigate alerts, view full messages, and take remediation actions without policy configuration access.
-
Communication Compliance Viewers
View-only access to reports and analytics dashboards without alert or message access.
-
Supervisory Review
Members can create and manage the policies that define which communications are subject to review in an organization. Used for regulatory supervisory review requirements (e.g., FINRA, SEC) where…
Purview Agents (Preview)
AI-powered agents built on Security Copilot that automate alert triage and data security posture tasks. Includes DLP Triage Agent, IRM Triage Agent, and DSPM Posture Agent.
-
Purview Agent Management
Dedicated role group for deploying and enabling all Purview agents. Contains the "Purview Content Analyst" role required to activate the DLP Triage Agent, IRM Triage Agent, and DSPM Posture Agent.
-
Data Security DLP Triage Agent
Combined role requirements for setting up, configuring, and viewing results from the DLP Triage Agent. This agent automatically triages DLP alerts from Exchange, Teams, OneDrive, SharePoint, and…
-
Data Security IRM Triage Agent
Combined role requirements for setting up, configuring, and viewing results from the Insider Risk Management Triage Agent. This agent automatically triages IRM alerts, helping analysts focus on…
-
Data Security DSPM Posture Agent
Combined role requirements for deploying, running, and viewing results from the DSPM Posture Agent (Preview). This agent uses natural language processing to find sensitive data across Microsoft 365,…
Compliance Manager
Assess, monitor, and improve compliance posture with templates, assessments, and improvement actions
-
Compliance Manager Administrators
Manage template creation and modification in Microsoft Purview Compliance Manager. Can create assessments, implement improvement actions, and manage all Compliance Manager content.
-
Compliance Manager Assessors
Create assessments, implement improvement actions, and update test status for improvement actions in Microsoft Purview Compliance Manager.
-
Compliance Manager Contributors
Create assessments and perform work to implement improvement actions in Microsoft Purview Compliance Manager. Cannot manage templates or update test status.
-
Compliance Manager Readers
View all Microsoft Purview Compliance Manager content except for administrator functions. Read-only access to assessments, improvement actions, and compliance score.
Insider Risk Management
Detect and respond to insider threats and risky user activities
-
Insider Risk Management
Full access to all IRM features including policy creation, alert investigation, forensic evidence review, and Adaptive Protection.
-
Insider Risk Management Admins
Configure IRM policies, settings, integrations, and Adaptive Protection without access to investigate individual cases.
-
Insider Risk Management Analysts
Review and investigate alerts, access analytics and case data, configure notice templates without policy configuration or forensic evidence access.
-
Insider Risk Management Investigators
Full investigation access including forensic evidence, Content Explorer, and detailed user activity review without policy configuration.
-
Insider Risk Management Auditors
View and export audit logs for IRM activities to ensure proper program governance, compliance, and ethical oversight.
-
Insider Risk Management Approvers
Approve forensic evidence capturing requests to ensure legal and privacy compliance before evidence collection.
-
Insider Risk Management Session Approvers
Provides controlled approval and oversight of user session-based activities within Microsoft Purview Insider Risk Management, without granting access to investigations, alerts, cases, or sensitive…
-
IRM Contributors
System role group. Visible in the Purview portal but used by background services only — do not assign users directly. Provides permissions that allow Insider Risk Management automation to function…
Data Loss Prevention
DLP policies to prevent sensitive data from leaving the organization
-
DLP Compliance Management
Create, configure, and manage Data Loss Prevention policies to prevent unauthorized sharing of sensitive information across Microsoft 365 and endpoints.
-
Information Protection Admins
Create and edit DLP policies, sensitivity labels, and auto-labeling rules without investigation access.
-
Information Protection Analysts
Access DLP alerts, activity explorer, and investigate incidents without policy modification rights.
-
Information Protection Investigators
Access Content Explorer to view in-place rendering of DLP-matched files for deep investigation.
Information Protection
Sensitivity labels, encryption, and content classification
-
Information Protection
Full control over all information protection features including DLP, sensitivity labels, and classification.
-
Sensitivity Label Administrator
Create and manage sensitivity labels and their policies for document classification and protection.
-
Sensitivity Label Reader
View sensitivity labels and configurations with read-only access for auditing and compliance.
-
Information Protection Readers
View-only access to information protection reports and analytics dashboards.
-
Content Explorer List Viewer
View file metadata and classifications in list format without viewing actual file content.
-
Content Explorer Content Viewer
View actual contents of classified and labeled files for detailed classification verification.
-
Exact Data Match Upload Admins
Upload data for Exact Data Match (EDM) classifiers. EDM classifiers detect sensitive information by matching against an uploaded data set (e.g., customer database, employee records) rather than…
DSPM (Classic)
Classic Data Security Posture Management with dedicated role groups (Data Security Management, Data Security Viewer). Being superseded by DSPM (Preview).
-
Data Security Management
Comprehensive DSPM role with full access to insights, Security Copilot integration, and ability to manage DLP, Information Protection, and Insider Risk Management solutions.
-
Data Security Viewer
Read-only access to DSPM dashboard insights, analytics, and Security Copilot for viewing data security posture without policy modification or investigation.
-
Data Security AI Viewer
Read-only access to DSPM for AI to monitor AI app usage, view insights into Copilot interactions, and track AI-related data security risks without viewing prompts/responses.
-
Data Security AI Content Viewer
View AI interaction prompts and responses for investigation of data security incidents in Copilot, agents, and third-party AI apps.
DSPM (Preview)
Unified Data Security Posture Management (preview) combining classic DSPM and DSPM for AI. Uses different roles than the classic version - requires Compliance Administrator or Security Reader instead of dedicated DSPM role groups.
-
DSPM Full Access (Preview)
[Preview] Full administrative access to the unified Data Security Posture Management. Complete setup tasks, create one-click policies, manage data security objectives, create data risk assessments,…
-
DSPM Viewer (Preview)
[Preview] View-only access to the unified Data Security Posture Management dashboards, reports, objectives, and data risk assessments. Uses Security Reader role group — does NOT require classic Data…
-
AI Administrator (DSPM)
[Preview] Entra ID role providing view-only access to AI-related data in DSPM (Preview) including AI observability, AI activities, AI objectives, and AI-related risk patterns. New role introduced…
-
Data Security AI Admin (Preview)
[Preview] Edit DLP policies related to Copilot and view AI content in the unified DSPM (Preview). Cannot read prompts and responses of AI interactions. Role group: Data Security AI Admins.
Privacy Management (Priva)
Privacy risk management and subject rights request handling
-
Privacy Management Administrators
Full administrative access to Microsoft Priva features including Privacy Risk Management and Subject Rights Requests. Can configure policies, manage settings, and oversee all privacy management…
-
Privacy Management Analysts
Investigate privacy policy matches and view file metadata without accessing file content. Can take remediation actions and manage privacy risk cases. Ideal for privacy analysts who need to triage…
-
Privacy Management Investigators
Full investigative access to privacy policy matches including file content review. Can investigate privacy incidents, view associated file content, and take comprehensive remediation actions.…
-
Privacy Management Viewer
Read-only access to privacy analytics, reports, insights, and policy trends. Can view privacy risk dashboards and compliance metrics without investigative or administrative capabilities. Ideal for…
-
Subject Rights Request Administrators
Full administrative rights to create and manage subject rights requests (SRRs). Can handle GDPR, CCPA, and other privacy regulation requests including access, export, tagged list, and delete…
-
Subject Rights Request Approvers
Can approve subject rights requests to which they are added as an approver. Typically used for approving delete requests or other high-risk SRRs requiring secondary authorization. Provides approval…
-
Privacy Management Contributors
Manage contributor access for privacy management cases in Microsoft Priva. Can perform compliance searches, work with custodian data, export data, and manage review set tags. Cannot configure…
-
Privacy Management
Top-level role group for the Privacy Management (Priva) solution in Microsoft Purview. Manages access control for the entire Privacy Management portal experience — distinct from the more scoped…
Data Security Investigations
Investigate data security incidents with forensic evidence collection
-
Data Security Investigations Administrators
[Preview] Full administrative access to Data Security Investigations. Create and manage all investigations, configure settings, run searches, and coordinate data security incident response.
-
Data Security Investigations Investigators
[Preview] Conduct assigned data security investigations. Create searches, analyze results, manage investigation scope, and develop mitigation plans for assigned cases.
-
Data Security Investigations Reviewers
[Preview] Review and analyze assigned data security investigations. Manage investigation scope, run analysis activities, view data risk graphs, and contribute to mitigation plans without…
Tenant-Level Governance
Tenant-wide Purview administration and domain management
-
Purview Administrators
Tenant-level role group to create, edit, and delete domains and perform role assignments across the Microsoft Purview account.
-
Data Governance (role group)
Tenant-level role group that grants access to data governance roles and delegates permissions for Governance Domain Creators in Unified Catalog.
-
Data Source Administrators (role group)
Tenant-level role group to manage data sources and scans across Microsoft Purview Data Map, including registration, scanning, and integration runtime management.
-
Data Catalog Curators
Tenant-level role group to perform create, read, modify, and delete actions on catalog data objects and establish relationships between objects in the classic Data Catalog.
-
Data Estate Insights Readers
Tenant-level role group providing read-only access to all insights reports across platforms and providers in the classic Data Catalog.
-
Data Estate Insights Admins
Tenant-level role group providing admin access to all insights reports across platforms and providers in the classic Data Catalog.
Data Map Collections
Collection-level access and data source management
-
Domain Admin
Domain-level role to assign permissions within a domain and manage its resources, collections, and role assignments.
-
Collection Administrator
Manage collections, assign roles, and organize data sources and assets within collection hierarchy.
-
Data Curator
Manage assets, create classifications, build glossary terms, and curate data catalog metadata for improved discoverability and understanding.
-
Data Reader
Read-only access to data assets, classifications, glossary terms, and collections for data discovery and search.
-
Data Source Administrator
Manage data sources and scans within assigned collections, including registration, scanning, and credential management.
-
Insights Reader
Read-only access to Data Estate Insights reports and analytics for collections where also assigned Data Reader role.
-
Policy Author
Create, view, update, and delete data access policies through Microsoft Purview Data Policy feature for Azure data sources.
-
Workflow Administrator
Access workflow authoring page in Microsoft Purview governance portal and publish workflows on collections where they have access permissions.
Unified Catalog Governance
Data product governance and catalog curation
-
Data Governance Administrator
Catalog-level role that delegates first level of access for Governance Domain Creators and other catalog permissions.
-
Governance Domain Creator
Create governance domains and delegate governance domain owner role (or remain owner by default).
-
Global Catalog Reader
Read published artifacts across all governance domains that don't have Local Catalog Reader restrictions.
-
Data Health Owner
Create, update, and read artifacts in Data Estate Health management area of Unified Catalog.
-
Data Health Reader
Read artifacts in Data Estate Health management area of Unified Catalog.
-
Governance Domain Owner
Delegate all governance domain permissions, configure data quality alerts, set schedules, and manage access policies.
-
Data Product Owner
Create, update, and read data products within governance domain. Build relationships with concepts across domains.
-
Data Steward
Create, update, and read artifacts and policies within governance domain. Read artifacts from other domains.
-
Governance Domain Reader
Read governance domain metadata for published domains they are added to.
-
Local Catalog Reader
Read published concepts only in assigned governance domain. Limits federated access for regulatory requirements.
-
Data Quality Steward
Manage data quality rules, scanning, insights, scheduling, monitoring, and alerts. Sub-role requiring Governance Domain Reader and Data Product Owner.
-
Data Quality Reader
Browse all data quality insights and rules. Sub-role requiring Governance Domain Reader and catalog reader role.
-
Data Profile Steward
Run data profiling jobs and access profiling insights. Sub-role requiring Governance Domain Reader and Data Product Owner.
-
Data Profile Reader
Browse data profile insights and drill down to column-level statistics. Sub-role requiring Governance Domain Reader and catalog reader.
-
Data Quality Metadata Reader
Browse data quality insights, rule definitions, and scores. Sub-role requiring Governance Domain Reader and catalog reader.