Bilješka
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati da se prijavite ili promijenite direktorije.
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati promijeniti direktorije.
Use the Configuration management permissions page to assign or remove permissions for the Tenant Configuration Management service. The service uses these permissions to create snapshots and run monitors.
Configure service permissions before you create snapshots or monitors that include the corresponding workload resources. Missing service permissions can cause a snapshot to be incomplete or a monitor run to fail.
When you create a monitor or snapshot, the Permissions step shows whether the service has the least-privilege permissions for the resource types you selected. This step is read-only. If the wizard shows that required least-privilege permissions are missing, use the Configuration management permissions page to add them.
Prerequisites
- A Microsoft Entra role that can assign or remove app-only permissions for service principals in your tenant, such as Global Administrator or Privileged Role Administrator. To see which roles can perform this task, see the Microsoft Entra built-in roles reference.
Open Configuration management permissions
To open the permissions page, follow these steps:
- Sign in to the Microsoft Entra admin center.
- Browse to Tenant Governance > Configuration management permissions.
Assign permissions
Assign permissions based on the workloads that contain the resources you want to snapshot or monitor:
Microsoft Entra ID or Intune resources: On the Application permissions tab, add the app-only permissions for the relevant Microsoft Graph resources.
- For the permissions required to snapshot or monitor Microsoft Entra resources, see Supported Microsoft Entra resources for Tenant Configuration Management.
- For the permissions required to snapshot or monitor Intune resources, see Supported Microsoft Intune resources for Tenant Configuration Management.
Teams resources: On the Entra roles tab, assign the Teams Reader Microsoft Entra role.
Exchange Online resources: On the Application permissions tab, assign Exchange.ManageAsApp. Then use Exchange Online PowerShell to assign Exchange roles to the Tenant Configuration Management service principal. For the steps, see App-only authentication in Exchange Online PowerShell and Security & Compliance PowerShell.
For the permissions required to snapshot or monitor Exchange resources, see Supported Microsoft Exchange resources for Tenant Configuration Management.
Defender or Purview resources: On the Application permissions tab, assign Exchange.ManageAsApp. Then use Security & Compliance PowerShell to assign Security and Compliance (Defender and Purview) roles to the Tenant Configuration Management service principal. For the steps, see Connect to Security & Compliance PowerShell.
For the permissions required to snapshot or monitor Defender or Purview resources, see Supported Microsoft Security and Compliance resources for Tenant Configuration Management.
Note
The Configuration management permissions page doesn't show workload permissions that are assigned to the service within Exchange Online, Defender, or Purview. Use Exchange Online PowerShell or Security & Compliance PowerShell to assign and remove those permissions.
Remove permissions
To remove a permission or a Microsoft Entra role, select the checkbox next to its name, and then select Remove in the command bar.
Related content
- Configuration management
- Set up authentication for Tenant Configuration Management APIs
- Exchange Online RBAC for applications
- Microsoft Defender unified role-based access control (RBAC)
- Microsoft Purview permissions
- Use Microsoft Teams administrator roles to manage Teams
- Role-based access control (RBAC) with Microsoft Intune