A bundle of Microsoft Purview roles. Any user or security group you add gets every permission in the bundle; you manage them from Settings > Roles and scopes.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Role group in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Security group
Kind of Entra group used to grant resource access. Its members, added by assignment or by dynamic rules, may be users, devices or service principals.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES.
Related terms
- Content Explorer List Viewer
Members of this Purview role group get only the list view in Content explorer and Data explorer: they can see what items exist and where, but not what is inside them.
- eDiscovery Manager
Members of this Purview role group can set up and run eDiscovery cases they own, including searching, holding and exporting content. eDiscovery Administrator is a subgroup of it.
- Information Protection Admins
A role group in Microsoft Purview whose members create, change and remove DLP policies, sensitivity labels, label policies and every kind of classifier. They also look after endpoint DLP settings.
- Information Protection Analysts
People in this Microsoft Purview role group work with activity explorer and DLP alerts. They can look at, but not change, classifiers, sensitivity labels and DLP policies.
- Information Protection Investigators
A Purview role group that has everything the Information Protection Analysts group has, and adds content explorer access so members can view what items actually contain.
- Information Protection Readers
A role group in Microsoft Purview that can only view reports about sensitivity labels and DLP policies.
- Insider Risk Management Admins
Members of this role group configure Insider Risk Management, covering policies, global settings and assigning people to role groups. Investigating cases or alerts is outside what they can do.
- Insider Risk Management Approvers
A role group in Insider Risk Management, usually given to legal or HR staff, whose members accept or turn down requests to capture forensic evidence.