diff --git a/defender-office-365/scc-permissions.md b/defender-office-365/scc-permissions.md index 4e2dddcbe0..046d677583 100644 --- a/defender-office-365/scc-permissions.md +++ b/defender-office-365/scc-permissions.md @@ -77,7 +77,7 @@ Managing permissions in Defender for Office 365 or Microsoft Purview gives users |**Data Estate Insights Readers**|Provides read-only access to all insights reports across platforms and providers.|Data Map Reader

Insights Reader| |**Data Governance**|Grants access to data governance roles within Microsoft Purview.|Data Governance Administrator| |**Data Investigator**|Perform searches on mailboxes, SharePoint Online sites, and OneDrive for Business locations.|Communication

Compliance Search

Custodian

Data Investigation Management

Export

Preview

Review

RMS Decrypt

Search And Purge| -|**Data Security Management**| View all Data Security Analytics insights, use CoPilot for Security, and manage Microsoft Purview data security solutions (Data Loss Prevention, Information Protection, and Insider Risk Management).| Case Management

Custodian

Data Classification Content Viewer

Data Classification List Viewer

Data Connector Admin

Data Map Reader

Data Security Viewer

Information Protection Admin

Information Protection Analyst

Information Protection Investigator

Information Protection Reader

Insider Risk Management Admin

Insider Risk Management Analysis

Insider Risk Management Approval

Insider Risk Management Audit

Insider Risk Management Investigation

Insider Risk Management Reports Administrator

Insider Risk Management Sessions

Insights Reader

Purview Evaluation Administrator

Review

Scan Reader

Source Reader

View-Only Case | +|**Data Security Management**| View all Data Security Posture Management insights, use CoPilot for Security, and manage Microsoft Purview data security solutions (Data Loss Prevention, Information Protection, and Insider Risk Management).| Case Management

Custodian

Data Classification Content Viewer

Data Classification List Viewer

Data Connector Admin

Data Map Reader

Data Security Viewer

Information Protection Admin

Information Protection Analyst

Information Protection Investigator

Information Protection Reader

Insider Risk Management Admin

Insider Risk Management Analysis

Insider Risk Management Approval

Insider Risk Management Audit

Insider Risk Management Investigation

Insider Risk Management Reports Administrator

Insider Risk Management Sessions

Insights Reader

Purview Evaluation Administrator

Review

Scan Reader

Source Reader

View-Only Case | |**Data Source Administrators**|Manage data sources and data scans.|Credential Reader

Credential Writer

Scan Reader

Scan Writer

Source Reader

Source Writer| |**eDiscovery Manager**|Members can perform searches and place holds on mailboxes, SharePoint Online sites, and OneDrive for Business locations. Members can also create and manage eDiscovery cases, add and remove members to a case, create and edit Content Searches associated with a case, and access case data in eDiscovery (Premium).

An eDiscovery Administrator is a member of the eDiscovery Manager role group who has been assigned additional permissions. In addition to the tasks that an eDiscovery Manager can perform, an eDiscovery Administrator can:

The primary difference between an eDiscovery Manager and an eDiscovery Administrator is that an eDiscovery Administrator can access all cases that are listed on the **eDiscovery cases** page in the compliance portal. An eDiscovery manager can only access the cases they created or cases they're a member of. For more information about making a user an eDiscovery Administrator, see [Assign eDiscovery permissions in the compliance portal](/purview/ediscovery-assign-permissions).|Case Management

Communication

Compliance Search

Custodian

Export

Hold

Manage Review Set Tags

Preview

Review

RMS Decrypt| |**Exact Data Match Upload Admins**|Upload data for Exact Data Match.|Exact Data Match Upload Admin| @@ -160,7 +160,7 @@ Roles that aren't assigned to the Organization Management role group by default |\***Data Investigation Management**|Create, edit, delete, and control access to data investigation.|Compliance Administrator

Data Investigator| |\***Data Map Reader**|Read actions on data map objects.|Compliance Administrator

Data Catalog Curators

Data Estate Insights Readers

Information Protection

Information Protection Admins

Information Protection Analysts

Information Protection Investigators| |\***Data Map Writer**|Create, read, modify, and delete actions on data map objects and establish relationships between objects.|Data Catalog Curators| -| **Data Security Viewer** | View access to Data Security Analytics dashboard insights. Allows users to use Copilot for Security to view details.| Data Security Management | +| **Data Security Viewer** | View access to Data Security Posture Management dashboard insights. Allows users to use Copilot for Security to view details.| Data Security Management | |**Device Management**|View and edit settings and reports for device management features.|Compliance Administrator

Compliance Data Administrator

Organization Management

Security Administrator| |\***Disposition Management**|Control permissions for accessing Manual Disposition in the Defender and compliance portals.|Compliance Administrator

Compliance Data Administrator

Records Management| |**DLP Compliance Management**|View and edit settings and reports for data loss prevention (DLP) policies.|Compliance Administrator

Compliance Data Administrator

Organization Management

Security Administrator|