Time-limited role group assignments in Microsoft Purview

Microsoft is rolling out the ability to assign a time limit when adding users or security groups to Purview role groups. Administrators can specify an expiration date from one day up to two years, enabling temporary administrative access and supporting least-privilege security practices. This enhancement should help organizations improve governance and compliance while reducing the risk of unnecessary long-term privileged access.

Automatic expiring permissions are optional and available for all Microsoft Purview role groups, except for eDiscovery Administrator and eDiscovery Manager.

Timeline

The rollout should be completed in September 2026.

How does this affect your organization?

Like with Microsoft Entra admin role assignments, compliance administrators can now also assign users or security groups to a Microsoft Purview role group with a defined expiration period, ranging from one day to two years. When the configured expiration date is reached, the assignment is automatically removed, and access is revoked without requiring manual action. The expiration date is evaluated in the local time zone of the administrator who sets it.

The capability applies to both new and existing assignments. Existing assignments are not modified automatically and remain permanent until an administrator explicitly sets an expiration.
To edit an existing assignment, administrators open the role group, select the user or security group, and edit the role group expiration. The role groups eDiscovery Administrator and eDiscovery Manager do not support expiration.

Edit the expiration for a Purview role group assignment

Administrators can set, update, extend, or remove an expiration between one day and two years.

Set, update, extend, or remove an expiration
Set, update, extend, or remove an expiration

The expiration date is also listed in the new Purview Members view.

Read:  New role groups page in the Microsoft Purview admin portal
The Members view now shows expiration information…
The Members view now shows expiration information…


Users do not receive a notification before permissions expire. Users should use the My permissions view in the Purview admin portal to find when their permissions expire.

...as does the My permissions view
…as does the My permissions view

If a user receives the same role group through both an individual assignment and a security group assignment, each assignment retains its own expiration date independently, and access remains active as long as one of the assignments is still valid.

Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Comment