Neue RBAC-Berechtigungen für Information Protection

Im Microsoft 365 Compliance Center wurden 5 neue, vordefinierte RBAC-Berechtigungsgruppen für Information Protection hinzugefügt.

Administratoren von Information Protection Inhalten wie Sensitivity Labels oder Data Loss Prevention (DLP) Policies können mit den neuen, vordefinierten Rollen Berechtigungen zielgerichteter einschränken.
Compliance Center Berechtigungsrollen werden über das Role-based Access Control (RBAC) Model definiert. Berechtigungsrollen werden in eine Berechtigungsgruppe eingefügt, die Berechtigungsgruppe an Benutzerkonten zugewiesen. Darüber erhalten Mitarbeitende die für ihre Arbeit notwendigen Berechtigungen. An Benutzerkonten zugeteilt werden die Gruppen über das M365 Compliance Center > Permissions > Compliance Center Roles.
Für die aktuelle Anpassung wurden für Information Protection 4 neue Berechtigungsrollen in 5 Berechtigungsgruppen vordefiniert. Für Microsoft Prüfungen könnten die aktualisierten Berechtigungen auch ein Thema sein.

4 neue Berechtigungsrollen
Berechtigungsrolle
Beschreibung
Information Protection AdminCreate, edit, and delete DLP policies, sensitivity labels and their policies, and all classifier types. Manage endpoint DLP settings and simulation mode for auto-labeling policies.
Information Protection AnalystAccess and manage DLP alerts and activity explorer. View-only access to DLP policies, sensitivity labels and their policies, and all classifier types.
Information Protection InvestigatorAccess and manage DLP alerts, activity explorer, and content explorer. View-only access to DLP policies, sensitivity labels and their policies, and all classifier types
Information Protection ReaderView-only access to reports for DLP policies and sensitivity labels and their policies.
Neue Information Protection Rollen im M365 Compliance Center
5 neue Berechtigungsgruppen

BerechtigungsgruppeBeschreibungInkludierte
Berechtigungsrollen
Information ProtectionFull control over all information protection features, including sensitivity labels and their policies, DLP, all classifier types, activity and content explorers, and all related reports.
  • Data Classification Content Viewer
  • Data Classification List Viewer
  • Information Protection Admin
  • Information Protection Analyst
  • Information Protection Investigator
  • Information Protection Reader
  • Information Protection AdminsCreate, edit, and delete DLP policies, sensitivity labels and their policies, and all classifier types. Manage endpoint DLP settings and simulation mode for auto-labeling policies.
  • Information Protection Admin
  • Information Protection InvestigatorsAccess and manage DLP alerts, activity explorer, and content explorer. View-only access to DLP policies, sensitivity labels and their policies, and all classifier types.
  • Data Classification Content Viewer
  • Data Classification List Viewer
  • Information Protection Analyst
  • Information Protection Investigator
  • Information Protection AnalystsAccess and manage DLP alerts and activity explorer. View-only access to DLP policies, sensitivity labels and their policies, and all classifier types.
  • Data Classification List Viewer
  • Information Protection Analyst
  • Information Protection ReadersView-only access to reports for DLP policies and sensitivity labels and their policies.
  • Information Protection Reader
  • Neue Information Protection Gruppen im M365 Compliance Center

    Share
    Avatar photo

    Tobias Asböck

    Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

    Leave a Reply

    Your email address will not be published. Required fields are marked *