Forum Discussion

adabud6267's avatar
adabud6267
Copper Contributor
Oct 12, 2019

O365 RBAC for DLP in Security & Compliance Center

Hi,

 

I’m struggling to find the right set of roles https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center#roles-in-the-security--compliance-center to grant the  necessary permissions to change, create new DLP policies and sensitive information types in O365.

 

I’ve tried with the DLP Compliance Management Role as it seamed to be the right one since it allows to view and edit settings and reports for DLP policies but although I can see the edit settings I have now view in to the incidents and reports. What roles would I have to assign to be also able to view the DLP audit logs e.g. to see how changed a policy setc. 

 

 

Thanks! 

  • You probably need to add permissions to run the corresponding ExO cmdlets (the Get-DLP*report ones)

    • adabud6267's avatar
      adabud6267
      Copper Contributor

      VasilMichev Thanks. So there's no other way to access it via the O365 web interface? How would one track changes to DLP policies or sensitive information types ? 

      • VasilMichev's avatar
        VasilMichev
        MVP

        Let's see if the suggestion above works, then we can think about other solutions. I'm traveling atm so I cannot test it, let us know if it works.

Resources