Identifying roles and permissions for administering sensitivity labels
It is important to give members of the IT administration team the relevant permissions to allow them to create and manage sensitivity labels within the Microsoft Purview Compliance Portal and, in some cases, from the older Security & Compliance Center.
All global admins can administer both the compliance center and the Security & Compliance Center by default. They can then assign the relevant permissions to the compliance officer or any other user without granting them access to the entire tenant. There are three roles to which you can add users that will grant them the relevant permissions to access both the Microsoft Purview Compliance Portal and the older Security & Compliance Center:
- Compliance Data Administrator role group
- Compliance Administrator role group
- Security Administrator role group
There is also an alternative option to using the standard roles, which is to create...