Understanding the Microsoft Purview Permission Model

Learn how tenant-level roles, Unified Catalog permissions and Data Map domain or collection permissions work together in Microsoft Purview.

Microsoft Purview data governance uses several permission layers rather than one universal administrator role.

Tenant or organisation level

Role groups such as Purview Administrators, Data Governance and Data Source Administrators provide broad capabilities across the Purview environment.

Unified Catalog

Catalog and Governance Domain roles control activities such as governance-domain creation, ownership, stewardship, data products and data health.

Data Map

Domains and collections control access to sources, technical assets and Data Map operations. Permissions can inherit down the hierarchy unless inheritance is restricted.

Why this matters

A user can have the right Unified Catalog role but still be unable to work with a technical asset if they do not have the necessary Data Map access. Likewise, Data Map access does not automatically grant governance-authoring rights in Unified Catalog.

Learning with Data SkyLab Studio

Follow practical Microsoft Purview and Data Governance learning from Data SkyLab Studio on YouTube.