Forum Discussion

SKadish's avatar
SKadish
Brass Contributor
Feb 15, 2024
Solved

Security Operator, but can add to TABL

I currently have the Entra ID Security Operator PIM role activated, and I am able to add email addresses to the TABL, as well as managing Anti-Spam and Anti-Phishing policies.  In the past, I've need...
  • G_Wilson3468's avatar
    Feb 21, 2024

    SKadish 

    According to the documentation you need to be a member in one of these role groups:

    Exchange Online permissions:
     1. Organization Management or Security Administrator

     2. Security Operator (Tenant AllowBlockList Manager)

     

    Entra ID permissions:

     Global Admin, Security Admin, Global Reader, Security Reader

     

    https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/tenant-allow-block-list-email-spoof-configure?view=o365-worldwide

     

    My impression here is that because of the unified RBAC model this role had to be modified to work. 

     

    Hope this helps.

     

    G.

     

Resources