Purview is now assigning workload admin roles in Microsoft Entra

Microsoft began assigning new Purview workload admin roles to Entra ID user accounts. As a reminder, last December, Microsoft published three new Entra admin roles for Microsoft Purview.

Read:  New Entra admin roles for Microsoft Purview, managed through Purview role assignments 

These roles are managed through Purview role assignments. Any manual assignment in Entra is overwritten by Purview.
Over the past few days, some administrators may have received PIM role assignment emails like the one below. This is due to the roles published last December.

  • The Purview Workload Content Reader role for the …. directory was assigned outside of PIM
  • The Purview Workload Content Writer role for the …. directory was assigned outside of PIM
  • The Purview Workload Content Administrator role for the …. directory was assigned outside of PIM
PIM role assignment notification
PIM role assignment notification

Checking the admin role confirms a direct assignment.

One of the three new roles: Purview Workload Content Administrator
One of the three new roles: Purview Workload Content Administrator

The assignment is also in the Entra audit logs, executed by the PurviewRoleAssignmentMigrator service principal (as mentioned in the notification). The principal ID is 9c5a4e30-19ea-49df-8965-06c1c80e7e89. Filter for the RoleManagement category to list these updates.

Microsoft Entra Audit logs
Microsoft Entra Audit logs

It is a first-party service principal created when the first Purview workload assignment was processed.

PurviewRoleAssignmentMigrator service principal
PurviewRoleAssignmentMigrator service principal

Below is the table from the December post, summarizing which Entra admin roles are mapped to Purview roles.

Purview roleMapped Entra roleEntra role descriptionEntra role template ID
Insider Risk Management AnalysisPurview Workload Content ReaderMembers can read data from Microsoft 365 (such as SharePoint, Teams, OneDrive, or Exchange) when accessing from the Microsoft Purview portal.e07494ad-1654-4dd2-922e-6f81a71bf00f
Insider Risk Management Investigation
Compliance Search
Export
Privacy Management Admin
Privacy Management Analysis
Privacy Management Investigation
Privacy Management Permanent Contribution
Privacy Management Temporary Contribution
Privacy Management Viewer
HoldPurview Workload Content WriterMembers can read and edit Microsoft 365 data (such as SharePoint, Teams, OneDrive, or Exchange) when accessing from the Microsoft Purview portal.02d5655b-c1cf-4e5f-98da-5fb919085bf6
Privacy Management Investigation
Search and PurgePurview Workload Content AdministratorMembers can manage or purge Microsoft 365 data (such as SharePoint, Teams, OneDrive, or Exchange) when accessing from the Microsoft Purview portal.3f04f91a-4ad7-4bd3-bcfa-49882ea1a88a
Export + Search And Purge
(both roles together)

As stated in my December post:

As an example, if your account has the Purview role “Privacy Management Investigation”, you will automatically receive the Purview Workload Content Writer role in Entra. If an account has multiple Purview roles, it will receive the highest privilege Entra role in the following order: Administrator > Writer > Reader.

That is why Purview assigned the highest workload role in Microsoft Entra to my account.
The account has the Purview roles “Search and Purge” or “Export + Search and Purge” assigned. These roles are included in two Purview role groups:

  • Data Investigator
  • Organization Management
Accounts with the Purview role groups "Data Investigator" or "Organization Management" are assigned the Purview Workload Content Administrator role in Microsoft Entra
Accounts with the Purview role groups “Data Investigator” or “Organization Management” are assigned the Purview Workload Content Administrator role in Microsoft Entra
Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *