Role in Entra ID versus Role given via Role Group in Purview

Julien 5 Reputation points
2025-01-15T10:56:11.11+00:00

Hi,

I would like to understand the difference between assigning a role - let's say "Compliance Administrator" - to a user via Entra ID versus asssgning this role via a Group Role (either "Compliance Administrator" or "Compliance Data Administrator" Role Group) via the Purview portal.

Are they both required, or is only one required ? Are they mutually exclusive ?

If the role is being granted through a Purview's Group Role, it does not appear as being being assigned to this user in Entra ID. Is it an intended behaviour ?

Also, we do have some restrictions in Entra ID for this "Compliance Administrator" role (activation and justification required ; can only be activated for X hours ; periodic recertification ...), but it appears that those restrictions are not enforced if the role has been granted through a Purview's Group Role, is that correct ?

Thanks for your highlights !

Best Regards

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,360 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,037 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 151.6K Reputation points MVP
    2025-01-15T12:35:49.9666667+00:00

    The roles in Purview are specific to the RBAC needed within Purview and not necessarily the same as the Entra Directory Roles:

    https://learn.microsoft.com/en-us/purview/purview-permissions

    User's image

    The roles in the Purview Center that are also Entra roles are listed in that doc:

    https://learn.microsoft.com/en-us/purview/purview-permissions#azure-roles-in-the-purview-portal

    So to your question, it depends :)

    If you need to leverage PIM for a Purview role group, you can do that following this:

    https://learn.microsoft.com/en-us/defender-office-365/pim-in-mdo-configure

    Note this however:

    https://learn.microsoft.com/en-us/purview/purview-portal#permissions-and-subscriptions

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.