MC1403403 High
(Updated) Microsoft Purview compliance portal: View-only role management enhancements
Summary AI-generated
Microsoft Purview and Defender portals will allow Global Reader and Security Reader admins to view role assignments and scopes, improving compliance transparency without new permissions.
Suggested actions AI-generated
- Review whether to assign Global Reader or Security Reader to more stakeholders
- Inform compliance/security teams of new visibility
- Update documentation on role visibility limits
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1311975 (Updated) Microsoft Purview compliance portal: Role groups user interface (UI) enhancements
- MC1199765 (Updated) Microsoft Purview: Role management update
- MC1411431 (Updated) Microsoft Purview compliance portal: Admin assignment time limit
- MC1226226 (Updated) Microsoft Purview | Role group changes in Microsoft Purview
- MC1473155 Microsoft Purview: permissions audit log improvements
- MC1280552 Expanded visibility for the Teams Reader role in the Teams admin center
Original post from Microsoft
Updated July 29, 2026: We have updated the content. Thank you for your patience.
[What and Why:]
Microsoft Purview is introducing a new view-only role management capability that enables administrators with Global Reader and Security Reader roles to view role assignments and scopes within the Microsoft Purview portal and Microsoft Defender portal. This update improves visibility and transparency of compliance role configurations without granting additional permissions, supporting audit readiness and strengthening enterprise security governance.
Rollout Schedule:
- Worldwide (General Availability), GCC, GCC High, DoD: Beginning in late August 2026 and expect to complete by late September 2026
[Impact on Your Organization:]
Who is affected: Administrators assigned Global Reader or Security Reader roles in Microsoft Entra ID and Microsoft Purview
Platforms/Services:
- Microsoft Purview compliance portal (web)
- Microsoft Defender portal (web)
- Microsoft Entra ID
What will happen:
- Users with Global Reader and Security Reader roles will gain read-only access to the following settings
- Roles and scope pages in the Microsoft Purview portal
- Permissions page in the Purview portal
- Admins can view all role memberships and assignments without being able to modify them.
- The feature will be enabled automatically for eligible roles.
- No changes are made to existing permissions or role assignments.
- There is no impact to user workflows.
[Action Required/Recommendations:]
- No action is required.
- Review internal governance or auditing processes to determine if additional stakeholders should be assigned Global Reader or Security Reader roles for visibility.
- Inform compliance or security teams of increased transparency capabilities.
- Update internal documentation if referencing role visibility limitations.
Learn more: Permissions in the Microsoft Purview portal | Microsoft Learn (will be updated before rollout)
[Compliance considerations:]
| Area | Explanation |
| Does the change alter how admins can monitor, report on, or demonstrate compliance activities? | Admins gain expanded visibility into role assignments and scopes within the Purview portal, improving compliance transparency and audit support. |
| Does the change include an admin control and, can it be controlled through Entra ID group membership? | Access is governed through existing Global Reader and Security Reader roles, which can be managed via Entra ID role assignments (including group-based assignment), or role group management in the Microsoft Purview portal. |
Additional details from Microsoft
- Summary
- Microsoft Purview now allows Global Reader and Security Reader roles to view role assignments and scopes in Purview and Defender portals with read-only access, enhancing compliance transparency without changing permissions. This feature rolls out globally from late August to September 2026 and requires no user action.