Microsoft Purview RBAC Roles

Browse all Microsoft Purview RBAC roles by category. Find least-privilege permissions for compliance, eDiscovery, DLP, insider risk, and information protection.

108 roles across 18 categories. Open the interactive map →

Global & Security Roles

Organization-wide admin and security roles that span all Purview features

  • Global Administrator

    Full administrative access to all Microsoft 365 and Purview features. However, Global Admin does NOT automatically grant access to certain Purview role groups.

  • Global Reader

    Read-only access across all Microsoft 365 and Purview features without the ability to make changes.

  • Security Administrator

    Manage security features across Microsoft 365 including Purview compliance, Defender, identity protection, and security policies without full Global Admin access.

  • Security Reader

    Read-only access to security features, reports, and alerts across Microsoft 365 including Purview compliance monitoring.

  • Compliance Administrator

    Comprehensive Entra ID role with broad permissions across Microsoft Purview compliance features including DLP, retention, sensitivity labels, eDiscovery, and compliance management.

  • Compliance Data Administrator

    Enhanced Entra ID role with all Compliance Administrator permissions PLUS device management, Content Explorer access, and advanced file activity tracking capabilities.

  • Quarantine Administrator

    Members can access all quarantine actions in Microsoft Defender for Office 365 and Exchange Online Protection. Can release, delete, preview, and manage quarantined messages and files.

  • Purview Consumption Management

    Manage and view Purview consumption billing reports. Provides access to consumption-based licensing reports and usage analytics for Microsoft Purview services.

  • Organization Management

    Top-level Purview role group. Members can control permissions for accessing features in the Microsoft Purview, Defender, and compliance portals, and manage settings for device management, data loss…

  • Security Operator

    Members can manage security alerts, and also view reports and settings of security features. SOC operator role — focused on alert triage and response without broader security administration…

  • Service Assurance User

    Members can access the Service Assurance section in the Microsoft Purview portal. Service Assurance provides reports and documents that describe Microsoft's security practices for customer data…

  • AI Administrators

    In addition to the capabilities of the AI Administrator role in Microsoft Entra, this group assigns read-only permissions for AI security insights in Microsoft Purview. Used for governing Microsoft…

  • Billing Administrator

    Configure billing features in Microsoft Purview. Used for Purview consumption-based billing configuration (separate from broader Microsoft 365 billing administration).

  • MailFlow Administrator

    Members can monitor and view mail flow insights and reports in the Microsoft Defender portal. Read-focused role for understanding mail flow patterns, queues, and delivery issues without permission to…

eDiscovery

Legal hold, content search, and case management for investigations

  • eDiscovery Manager

    Create and manage eDiscovery (Standard and Premium) cases with custodian management, review sets, legal hold notifications, advanced indexing, analytics, and ML-powered predictive coding.

  • eDiscovery Administrator

    All eDiscovery Manager permissions PLUS organization-wide access to all cases, global eDiscovery settings management, and hold report oversight across entire tenant.

  • Data Investigator

    Perform searches and access review sets for investigation without case management capabilities.

  • Reviewer

    Access review sets in eDiscovery cases to analyze collected data without search or export capabilities.

  • Custodian

    Identify and manage custodians (data owners) for eDiscovery cases and track their data sources.

  • Hold

    Place and manage legal holds on content to preserve it during investigations and litigation.

Audit

Activity logging and audit log search across Microsoft 365

  • Audit Manager

    Search, manage, and configure audit log settings and retention policies for compliance monitoring.

  • Audit Reader

    Search and export audit logs with read-only access, without ability to configure settings.

Records Management

Retention labels, file plans, and regulatory records management

  • Records Management

    Configure retention labels for records, file plans, and disposition reviews for formal records management programs with regulatory-grade immutability.

  • Disposition Management

    Review and approve content disposition at end of retention period to ensure proper record destruction with proof of disposal and audit trail.

  • View-Only Records Management

    Read-only access to records management features for auditing, compliance reporting, and oversight without modification permissions.

Data Lifecycle Management

Retention policies and data lifecycle automation

  • Retention Management

    Create and manage retention policies and labels across Microsoft 365 to ensure compliance with data retention requirements.

  • View-Only Retention Management

    Read-only access to retention policies, labels, and analytics for auditing, compliance reporting, and oversight without modification permissions.

Communication Compliance

Policy-based monitoring of communications for regulatory compliance

  • Communication Compliance

    Full access to configure policies, investigate alerts, remediate violations, and manage all aspects of communication monitoring.

  • Communication Compliance Admins

    Configure policies and settings but cannot investigate alerts or view message content - separated administration.

  • Communication Compliance Analysts

    Access and investigate alerts, view message metadata, but cannot view full message content - limited investigation access.

  • Communication Compliance Investigators

    Investigate alerts, view full messages, and take remediation actions without policy configuration access.

  • Communication Compliance Viewers

    View-only access to reports and analytics dashboards without alert or message access.

  • Supervisory Review

    Members can create and manage the policies that define which communications are subject to review in an organization. Used for regulatory supervisory review requirements (e.g., FINRA, SEC) where…

Purview Agents (Preview)

AI-powered agents built on Security Copilot that automate alert triage and data security posture tasks. Includes DLP Triage Agent, IRM Triage Agent, and DSPM Posture Agent.

  • Purview Agent Management

    Dedicated role group for deploying and enabling all Purview agents. Contains the "Purview Content Analyst" role required to activate the DLP Triage Agent, IRM Triage Agent, and DSPM Posture Agent.

  • Data Security DLP Triage Agent

    Combined role requirements for setting up, configuring, and viewing results from the DLP Triage Agent. This agent automatically triages DLP alerts from Exchange, Teams, OneDrive, SharePoint, and…

  • Data Security IRM Triage Agent

    Combined role requirements for setting up, configuring, and viewing results from the Insider Risk Management Triage Agent. This agent automatically triages IRM alerts, helping analysts focus on…

  • Data Security DSPM Posture Agent

    Combined role requirements for deploying, running, and viewing results from the DSPM Posture Agent (Preview). This agent uses natural language processing to find sensitive data across Microsoft 365,…

Compliance Manager

Assess, monitor, and improve compliance posture with templates, assessments, and improvement actions

  • Compliance Manager Administrators

    Manage template creation and modification in Microsoft Purview Compliance Manager. Can create assessments, implement improvement actions, and manage all Compliance Manager content.

  • Compliance Manager Assessors

    Create assessments, implement improvement actions, and update test status for improvement actions in Microsoft Purview Compliance Manager.

  • Compliance Manager Contributors

    Create assessments and perform work to implement improvement actions in Microsoft Purview Compliance Manager. Cannot manage templates or update test status.

  • Compliance Manager Readers

    View all Microsoft Purview Compliance Manager content except for administrator functions. Read-only access to assessments, improvement actions, and compliance score.

Insider Risk Management

Detect and respond to insider threats and risky user activities

  • Insider Risk Management

    Full access to all IRM features including policy creation, alert investigation, forensic evidence review, and Adaptive Protection.

  • Insider Risk Management Admins

    Configure IRM policies, settings, integrations, and Adaptive Protection without access to investigate individual cases.

  • Insider Risk Management Analysts

    Review and investigate alerts, access analytics and case data, configure notice templates without policy configuration or forensic evidence access.

  • Insider Risk Management Investigators

    Full investigation access including forensic evidence, Content Explorer, and detailed user activity review without policy configuration.

  • Insider Risk Management Auditors

    View and export audit logs for IRM activities to ensure proper program governance, compliance, and ethical oversight.

  • Insider Risk Management Approvers

    Approve forensic evidence capturing requests to ensure legal and privacy compliance before evidence collection.

  • Insider Risk Management Session Approvers

    Provides controlled approval and oversight of user session-based activities within Microsoft Purview Insider Risk Management, without granting access to investigations, alerts, cases, or sensitive…

  • IRM Contributors

    System role group. Visible in the Purview portal but used by background services only — do not assign users directly. Provides permissions that allow Insider Risk Management automation to function…

Data Loss Prevention

DLP policies to prevent sensitive data from leaving the organization

Information Protection

Sensitivity labels, encryption, and content classification

DSPM (Classic)

Classic Data Security Posture Management with dedicated role groups (Data Security Management, Data Security Viewer). Being superseded by DSPM (Preview).

  • Data Security Management

    Comprehensive DSPM role with full access to insights, Security Copilot integration, and ability to manage DLP, Information Protection, and Insider Risk Management solutions.

  • Data Security Viewer

    Read-only access to DSPM dashboard insights, analytics, and Security Copilot for viewing data security posture without policy modification or investigation.

  • Data Security AI Viewer

    Read-only access to DSPM for AI to monitor AI app usage, view insights into Copilot interactions, and track AI-related data security risks without viewing prompts/responses.

  • Data Security AI Content Viewer

    View AI interaction prompts and responses for investigation of data security incidents in Copilot, agents, and third-party AI apps.

DSPM (Preview)

Unified Data Security Posture Management (preview) combining classic DSPM and DSPM for AI. Uses different roles than the classic version - requires Compliance Administrator or Security Reader instead of dedicated DSPM role groups.

  • DSPM Full Access (Preview)

    [Preview] Full administrative access to the unified Data Security Posture Management. Complete setup tasks, create one-click policies, manage data security objectives, create data risk assessments,…

  • DSPM Viewer (Preview)

    [Preview] View-only access to the unified Data Security Posture Management dashboards, reports, objectives, and data risk assessments. Uses Security Reader role group — does NOT require classic Data…

  • AI Administrator (DSPM)

    [Preview] Entra ID role providing view-only access to AI-related data in DSPM (Preview) including AI observability, AI activities, AI objectives, and AI-related risk patterns. New role introduced…

  • Data Security AI Admin (Preview)

    [Preview] Edit DLP policies related to Copilot and view AI content in the unified DSPM (Preview). Cannot read prompts and responses of AI interactions. Role group: Data Security AI Admins.

Privacy Management (Priva)

Privacy risk management and subject rights request handling

  • Privacy Management Administrators

    Full administrative access to Microsoft Priva features including Privacy Risk Management and Subject Rights Requests. Can configure policies, manage settings, and oversee all privacy management…

  • Privacy Management Analysts

    Investigate privacy policy matches and view file metadata without accessing file content. Can take remediation actions and manage privacy risk cases. Ideal for privacy analysts who need to triage…

  • Privacy Management Investigators

    Full investigative access to privacy policy matches including file content review. Can investigate privacy incidents, view associated file content, and take comprehensive remediation actions.…

  • Privacy Management Viewer

    Read-only access to privacy analytics, reports, insights, and policy trends. Can view privacy risk dashboards and compliance metrics without investigative or administrative capabilities. Ideal for…

  • Subject Rights Request Administrators

    Full administrative rights to create and manage subject rights requests (SRRs). Can handle GDPR, CCPA, and other privacy regulation requests including access, export, tagged list, and delete…

  • Subject Rights Request Approvers

    Can approve subject rights requests to which they are added as an approver. Typically used for approving delete requests or other high-risk SRRs requiring secondary authorization. Provides approval…

  • Privacy Management Contributors

    Manage contributor access for privacy management cases in Microsoft Priva. Can perform compliance searches, work with custodian data, export data, and manage review set tags. Cannot configure…

  • Privacy Management

    Top-level role group for the Privacy Management (Priva) solution in Microsoft Purview. Manages access control for the entire Privacy Management portal experience — distinct from the more scoped…

Data Security Investigations

Investigate data security incidents with forensic evidence collection

  • Data Security Investigations Administrators

    [Preview] Full administrative access to Data Security Investigations. Create and manage all investigations, configure settings, run searches, and coordinate data security incident response.

  • Data Security Investigations Investigators

    [Preview] Conduct assigned data security investigations. Create searches, analyze results, manage investigation scope, and develop mitigation plans for assigned cases.

  • Data Security Investigations Reviewers

    [Preview] Review and analyze assigned data security investigations. Manage investigation scope, run analysis activities, view data risk graphs, and contribute to mitigation plans without…

Tenant-Level Governance

Tenant-wide Purview administration and domain management

  • Purview Administrators

    Tenant-level role group to create, edit, and delete domains and perform role assignments across the Microsoft Purview account.

  • Data Governance (role group)

    Tenant-level role group that grants access to data governance roles and delegates permissions for Governance Domain Creators in Unified Catalog.

  • Data Source Administrators (role group)

    Tenant-level role group to manage data sources and scans across Microsoft Purview Data Map, including registration, scanning, and integration runtime management.

  • Data Catalog Curators

    Tenant-level role group to perform create, read, modify, and delete actions on catalog data objects and establish relationships between objects in the classic Data Catalog.

  • Data Estate Insights Readers

    Tenant-level role group providing read-only access to all insights reports across platforms and providers in the classic Data Catalog.

  • Data Estate Insights Admins

    Tenant-level role group providing admin access to all insights reports across platforms and providers in the classic Data Catalog.

Data Map Collections

Collection-level access and data source management

  • Domain Admin

    Domain-level role to assign permissions within a domain and manage its resources, collections, and role assignments.

  • Collection Administrator

    Manage collections, assign roles, and organize data sources and assets within collection hierarchy.

  • Data Curator

    Manage assets, create classifications, build glossary terms, and curate data catalog metadata for improved discoverability and understanding.

  • Data Reader

    Read-only access to data assets, classifications, glossary terms, and collections for data discovery and search.

  • Data Source Administrator

    Manage data sources and scans within assigned collections, including registration, scanning, and credential management.

  • Insights Reader

    Read-only access to Data Estate Insights reports and analytics for collections where also assigned Data Reader role.

  • Policy Author

    Create, view, update, and delete data access policies through Microsoft Purview Data Policy feature for Azure data sources.

  • Workflow Administrator

    Access workflow authoring page in Microsoft Purview governance portal and publish workflows on collections where they have access permissions.

Unified Catalog Governance

Data product governance and catalog curation

  • Data Governance Administrator

    Catalog-level role that delegates first level of access for Governance Domain Creators and other catalog permissions.

  • Governance Domain Creator

    Create governance domains and delegate governance domain owner role (or remain owner by default).

  • Global Catalog Reader

    Read published artifacts across all governance domains that don't have Local Catalog Reader restrictions.

  • Data Health Owner

    Create, update, and read artifacts in Data Estate Health management area of Unified Catalog.

  • Data Health Reader

    Read artifacts in Data Estate Health management area of Unified Catalog.

  • Governance Domain Owner

    Delegate all governance domain permissions, configure data quality alerts, set schedules, and manage access policies.

  • Data Product Owner

    Create, update, and read data products within governance domain. Build relationships with concepts across domains.

  • Data Steward

    Create, update, and read artifacts and policies within governance domain. Read artifacts from other domains.

  • Governance Domain Reader

    Read governance domain metadata for published domains they are added to.

  • Local Catalog Reader

    Read published concepts only in assigned governance domain. Limits federated access for regulatory requirements.

  • Data Quality Steward

    Manage data quality rules, scanning, insights, scheduling, monitoring, and alerts. Sub-role requiring Governance Domain Reader and Data Product Owner.

  • Data Quality Reader

    Browse all data quality insights and rules. Sub-role requiring Governance Domain Reader and catalog reader role.

  • Data Profile Steward

    Run data profiling jobs and access profiling insights. Sub-role requiring Governance Domain Reader and Data Product Owner.

  • Data Profile Reader

    Browse data profile insights and drill down to column-level statistics. Sub-role requiring Governance Domain Reader and catalog reader.

  • Data Quality Metadata Reader

    Browse data quality insights, rule definitions, and scores. Sub-role requiring Governance Domain Reader and catalog reader.