Role Assignment and Least Privilege

Learn how to delegate Microsoft Purview roles at the correct scope while avoiding unnecessary tenant, domain or collection-level permissions.

Microsoft recommends using the roles with the fewest permissions required for the task.

Start with the responsibility

Identify what the person needs to do before assigning a role. Governance authors, source administrators, Data Map readers and platform administrators do not require the same permissions.

Choose the correct scope

Where possible, grant access at the relevant Governance Domain, Data Map domain or collection rather than using a broad tenant-level role.

Consider inheritance

High-level Data Map assignments can flow down to child collections, so administrators should review the effective access created by inheritance.

Operational controls

  • Prefer groups over individual assignments where appropriate.
  • Document role purpose and ownership.
  • Review privileged assignments regularly.
  • Remove access that is no longer required.
  • Allow for permission-propagation time when testing new assignments.

Learning with Data SkyLab Studio

Follow practical Microsoft Purview and Data Governance learning from Data SkyLab Studio on YouTube.