Uredi

Configure configuration management service permissions

Use the Configuration management permissions page to assign or remove permissions for the Tenant Configuration Management service. The service uses these permissions to create snapshots and run monitors.

Configure service permissions before you create snapshots or monitors that include the corresponding workload resources. Missing service permissions can cause a snapshot to be incomplete or a monitor run to fail.

When you create a monitor or snapshot, the Permissions step shows whether the service has the least-privilege permissions for the resource types you selected. This step is read-only. If the wizard shows that required least-privilege permissions are missing, use the Configuration management permissions page to add them.

Prerequisites

Open Configuration management permissions

To open the permissions page, follow these steps:

  1. Sign in to the Microsoft Entra admin center.
  2. Browse to Tenant Governance > Configuration management permissions.

Assign permissions

Assign permissions based on the workloads that contain the resources you want to snapshot or monitor:

Note

The Configuration management permissions page doesn't show workload permissions that are assigned to the service within Exchange Online, Defender, or Purview. Use Exchange Online PowerShell or Security & Compliance PowerShell to assign and remove those permissions.

Remove permissions

To remove a permission or a Microsoft Entra role, select the checkbox next to its name, and then select Remove in the command bar.