Share via

Role in Entra ID versus Role given via Role Group in Purview

Julien 5 Reputation points
2025-01-15T10:56:11.11+00:00

Hi,

I would like to understand the difference between assigning a role - let's say "Compliance Administrator" - to a user via Entra ID versus asssgning this role via a Group Role (either "Compliance Administrator" or "Compliance Data Administrator" Role Group) via the Purview portal.

Are they both required, or is only one required ? Are they mutually exclusive ?

If the role is being granted through a Purview's Group Role, it does not appear as being being assigned to this user in Entra ID. Is it an intended behaviour ?

Also, we do have some restrictions in Entra ID for this "Compliance Administrator" role (activation and justification required ; can only be activated for X hours ; periodic recertification ...), but it appears that those restrictions are not enforced if the role has been granted through a Purview's Group Role, is that correct ?

Thanks for your highlights !

Best Regards

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Purview

1 answer

Sort by: Most helpful
  1. Andy David - MVP 160.2K Reputation points MVP Volunteer Moderator
    2025-01-15T12:35:49.9666667+00:00

    The roles in Purview are specific to the RBAC needed within Purview and not necessarily the same as the Entra Directory Roles:

    https://learn.microsoft.com/en-us/purview/purview-permissions

    User's image

    The roles in the Purview Center that are also Entra roles are listed in that doc:

    https://learn.microsoft.com/en-us/purview/purview-permissions#azure-roles-in-the-purview-portal

    So to your question, it depends :)

    If you need to leverage PIM for a Purview role group, you can do that following this:

    https://learn.microsoft.com/en-us/defender-office-365/pim-in-mdo-configure

    Note this however:

    https://learn.microsoft.com/en-us/purview/purview-portal#permissions-and-subscriptions

    User's image

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.