Forum Discussion
Secure Score Admin roles
- Oct 29, 2018
Hi Tony,
The roles are:
- Exchange Administrator
- Global Administrator
- Security Administrator
- Security Reader
- SharePoint Administrator
- Skype for Business Administrator
We are looking to add the Teams Administrator to the list in the future
I read the same article and assumed that Custom Administrator / Reports Reader would give the access. My user is telling me it's not working. Is there a definitive list of which Custom Administrators should get access? Here's the possibilities:
- Billing administrator
- Dynamics 365 service administrator
- Customer Lockbox access approver
- Exchange administrator
- Password administrator
- License administrator
- Skype for Business administrator
- Message Center reader
- Power BI service administrator
- Reports reader
- Service administrator
- SharePoint administrator
- User management administrator
Hi Tony,
The user needs to be a workload (Exchange, SharePoint, etc) admin or have a security role. You might want to grant the user Security Reader rights via Azure AD to see if that meets their needs.
The other option is to leverage the Secure Score API and build out a dashboard in Power BI or another tool to show them just the data they need. There are some YouTube videos here and here that might help with this.
- Bilal_AchahbarDec 03, 2018Copper Contributor
Is everything in the tool available for users with that roles granted?
Or do you need any kind of specific lincense for extra functions? - computxOct 25, 2018Gold Contributor
Can you elaborate specifically on which of the above-mentioned are "workload" besides Exchange and SharePoint?
- Anthony-SmithOct 29, 2018
Microsoft
Hi Tony,
The roles are:
- Exchange Administrator
- Global Administrator
- Security Administrator
- Security Reader
- SharePoint Administrator
- Skype for Business Administrator
We are looking to add the Teams Administrator to the list in the future
- computxOct 29, 2018Gold Contributor
Perfect.
For the record, the option of "...grant the user Security Reader rights via Azure AD..." also worked.