Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Microsoft Purview compliance portal: View-only role management enhancements

Message ID
MC1403403
View in Message Center
Service
Microsoft Purview
Category
Stay Informed
Tags
New featureAdmin impact
Rollout
August 2026September 2026

Summary

Microsoft Purview now allows Global Reader and Security Reader roles to view role assignments and scopes in Purview and Defender portals with read-only access, enhancing compliance transparency without changing permissions. This feature rolls out globally from late August to September 2026 and requires no user action.

Details

Updated July 29, 2026: We have updated the content. Thank you for your patience.

[What and Why:]

Microsoft Purview is introducing a new view-only role management capability that enables administrators with Global Reader and Security Reader roles to view role assignments and scopes within the Microsoft Purview portal and Microsoft Defender portal. This update improves visibility and transparency of compliance role configurations without granting additional permissions, supporting audit readiness and strengthening enterprise security governance.

Rollout Schedule:

  • Worldwide (General Availability), GCC, GCC High, DoD: Beginning in late August 2026 and expect to complete by late September 2026

[Impact on Your Organization:]

Who is affected: Administrators assigned Global Reader or Security Reader roles in Microsoft Entra ID and Microsoft Purview

Platforms/Services:

  • Microsoft Purview compliance portal (web)
  • Microsoft Defender portal (web)
  • Microsoft Entra ID

What will happen:

  • Users with Global Reader and Security Reader roles will gain read-only access to the following settings
    • Roles and scope pages in the Microsoft Purview portal
    • Permissions page in the Purview portal
  • Admins can view all role memberships and assignments without being able to modify them.
  • The feature will be enabled automatically for eligible roles.
  • No changes are made to existing permissions or role assignments.
  • There is no impact to user workflows.

[Action Required/Recommendations:]

  • No action is required.
  • Review internal governance or auditing processes to determine if additional stakeholders should be assigned Global Reader or Security Reader roles for visibility.
  • Inform compliance or security teams of increased transparency capabilities.
  • Update internal documentation if referencing role visibility limitations.

Learn more: Permissions in the Microsoft Purview portal | Microsoft Learn (will be updated before rollout)

[Compliance considerations:]

AreaExplanation
Does the change alter how admins can monitor, report on, or demonstrate compliance activities?Admins gain expanded visibility into role assignments and scopes within the Purview portal, improving compliance transparency and audit support.
Does the change include an admin control and, can it be controlled through Entra ID group membership?Access is governed through existing Global Reader and Security Reader roles, which can be managed via Entra ID role assignments (including group-based assignment), or role group management in the Microsoft Purview portal.

Change History

Show
July 29, 2026 at 8:31 PM Updated
Summary
Previous
Microsoft Purview adds view-only role management for Global Reader and Security Reader roles, enabling read-only access to role assignments and scopes in Purview and Defender portals. This enhances compliance visibility without permission changes. Rollout starts late August 2026, requiring no action but recommending governance review.
New
Microsoft Purview now allows Global Reader and Security Reader roles to view role assignments and scopes in Purview and Defender portals with read-only access, enhancing compliance transparency without changing permissions. This feature rolls out globally from late August to September 2026 and requires no user action.
Last Updated Date
Previous
2026-07-28T22:02:24.743Z
New
2026-07-29T19:50:39.277Z
Body Content
Previous
<p>Updated July 28, 2026: We have updated the timeline. Thank you for your patience.</p><p><b>[What and Why:]</b></p><p>Microsoft Purview is introducing a new <b>view-only role management capability</b> that enables administrators with <b>Global Reader</b> and <b>Security Reader</b> roles to view role assignments and scopes within the Microsoft Purview portal and Microsoft Defender portal. This update improves visibility and transparency of compliance role configurations without granting additional permissions, supporting audit readiness and strengthening enterprise security governance.</p> <p><b>Rollout Schedule:</b></p><ul> <li>Worldwide (General Availability), GCC, GCC High, DoD: Beginning in<b> late August 2026</b> and expect to complete by<b> late September 2026</b></li> </ul> <p><b>[Impact on Your Organization:]</b></p> <p><b>Who is affected:&nbsp;</b>Administrators assigned Global Reader or Security Reader roles in Microsoft Entra ID and Microsoft Purview</p> <p><b>Platforms/Services:</b></p> <ul> <li>Microsoft Purview compliance portal (web)</li> <li>Microsoft Entra ID</li> </ul> <p><b>What will happen:</b></p> <ul> <li>Users with <b>Global Reader</b> and <b>Security Reader</b> roles will gain <b>read-only access</b> to the following settings<ul><li>Roles and scope pages in the Microsoft Purview portal</li><li>Permissions page in the Purview portal</li></ul></li> <li>Admins can <b>view all role memberships and assignments</b> without being able to modify them.</li> <li>The feature will be enabled automatically for eligible roles.</li><li>No changes are made to existing permissions or role assignments.</li><li>There is no impact to user workflows.</li> </ul> <p><b>[Action Required/Recommendations:]</b></p> <ul> <li>No action is required.</li><li>Review internal governance or auditing processes to determine if additional stakeholders should be assigned <b>Global Reader</b> or <b>Security Reader</b> roles for visibility.</li><li>Inform compliance or security teams of increased transparency capabilities.</li><li>Update internal documentation if referencing role visibility limitations.</li> </ul> <p><b>Learn more: </b><a href="https://learn.microsoft.com/purview/purview-permissions" target="_blank">Permissions in the Microsoft Purview portal | Microsoft Learn</a>&nbsp;(will be updated before rollout)</p><p><b>[Compliance considerations:]</b></p><table class="table table-bordered"><tbody><tr><td><b>Area</b></td><td><b>Explanation</b></td></tr><tr><td>Does the change alter how admins can monitor, report on, or demonstrate compliance activities?</td><td>Admins gain expanded visibility into role assignments and scopes within the Purview portal, improving compliance transparency and audit support.</td></tr><tr><td>Does the change include an admin control and, can it be controlled through Entra ID group membership?</td><td>Access is governed through existing Global Reader and Security Reader roles, which can be managed via Entra ID role assignments (including group-based assignment), or role group management in the Microsoft Purview portal.</td></tr></tbody></table>
New
<p>Updated July 29, 2026: We have updated the content. Thank you for your patience.</p><p><b>[What and Why:]</b></p><p>Microsoft Purview is introducing a new <b>view-only role management capability</b> that enables administrators with <b>Global Reader</b> and <b>Security Reader</b> roles to view role assignments and scopes within the Microsoft Purview portal and Microsoft Defender portal. This update improves visibility and transparency of compliance role configurations without granting additional permissions, supporting audit readiness and strengthening enterprise security governance.</p> <p><b>Rollout Schedule:</b></p><ul> <li>Worldwide (General Availability), GCC, GCC High, DoD: Beginning in<b> late August 2026</b> and expect to complete by<b> late September 2026</b></li> </ul> <p><b>[Impact on Your Organization:]</b></p> <p><b>Who is affected:&nbsp;</b>Administrators assigned Global Reader or Security Reader roles in Microsoft Entra ID and Microsoft Purview</p> <p><b>Platforms/Services:</b></p> <ul> <li>Microsoft Purview compliance portal (web)</li><li>Microsoft Defender portal (web)</li> <li>Microsoft Entra ID</li> </ul> <p><b>What will happen:</b></p> <ul> <li>Users with <b>Global Reader</b> and <b>Security Reader</b> roles will gain <b>read-only access</b> to the following settings<ul><li>Roles and scope pages in the Microsoft Purview portal</li><li>Permissions page in the Purview portal</li></ul></li> <li>Admins can <b>view all role memberships and assignments</b> without being able to modify them.</li> <li>The feature will be enabled automatically for eligible roles.</li><li>No changes are made to existing permissions or role assignments.</li><li>There is no impact to user workflows.</li> </ul> <p><b>[Action Required/Recommendations:]</b></p> <ul> <li>No action is required.</li><li>Review internal governance or auditing processes to determine if additional stakeholders should be assigned <b>Global Reader</b> or <b>Security Reader</b> roles for visibility.</li><li>Inform compliance or security teams of increased transparency capabilities.</li><li>Update internal documentation if referencing role visibility limitations.</li> </ul> <p><b>Learn more: </b><a href="https://learn.microsoft.com/purview/purview-permissions" target="_blank">Permissions in the Microsoft Purview portal | Microsoft Learn</a>&nbsp;(will be updated before rollout)</p><p><b>[Compliance considerations:]</b></p><table class="table table-bordered"><tbody><tr><td><b>Area</b></td><td><b>Explanation</b></td></tr><tr><td>Does the change alter how admins can monitor, report on, or demonstrate compliance activities?</td><td>Admins gain expanded visibility into role assignments and scopes within the Purview portal, improving compliance transparency and audit support.</td></tr><tr><td>Does the change include an admin control and, can it be controlled through Entra ID group membership?</td><td>Access is governed through existing Global Reader and Security Reader roles, which can be managed via Entra ID role assignments (including group-based assignment), or role group management in the Microsoft Purview portal.</td></tr></tbody></table>
July 28, 2026 at 10:30 PM Updated
Title
Previous
Microsoft Purview compliance portal: View-only role management enhancements
New
(Updated) Microsoft Purview compliance portal: View-only role management enhancements
Summary
Previous
Microsoft Purview will enable Global Reader and Security Reader roles to view role assignments and scopes in the Purview and Defender portals with read-only access, enhancing compliance visibility without permission changes. Rollout begins late July 2026, requiring no user action but recommending governance review.
New
Microsoft Purview adds view-only role management for Global Reader and Security Reader roles, enabling read-only access to role assignments and scopes in Purview and Defender portals. This enhances compliance visibility without permission changes. Rollout starts late August 2026, requiring no action but recommending governance review.
Last Updated Date
Previous
2026-06-24T22:27:51.313Z
New
2026-07-28T22:02:24.743Z
Tags
Previous
New feature,Admin impact
New
Updated message,New feature,Admin impact
Body Content
Previous
<p><b>[What and Why:]</b></p><p>Microsoft Purview is introducing a new <b>view-only role management capability</b> that enables administrators with <b>Global Reader</b> and <b>Security Reader</b> roles to view role assignments and scopes within the Microsoft Purview portal and Microsoft Defender portal. This update improves visibility and transparency of compliance role configurations without granting additional permissions, supporting audit readiness and strengthening enterprise security governance.</p> <p><b>Rollout Schedule:</b></p> <ul> <li>Worldwide (General Availability): Beginning in <b>late July 2026</b> and expect to complete by <b>late August 2026</b></li> <li>GCC, GCC High, DoD: Beginning in<b> late August 2026</b> and expect to complete by<b> late September 2026</b></li> </ul> <p><b>[Impact on Your Organization:]</b></p> <p><b>Who is affected:&nbsp;</b>Administrators assigned Global Reader or Security Reader roles in Microsoft Entra ID and Microsoft Purview</p> <p><b>Platforms/Services:</b></p> <ul> <li>Microsoft Purview compliance portal (web)</li> <li>Microsoft Entra ID</li> </ul> <p><b>What will happen:</b></p> <ul> <li>Users with <b>Global Reader</b> and <b>Security Reader</b> roles will gain <b>read-only access</b> to the following settings<ul><li>Roles and scope pages in the Microsoft Purview portal</li><li>Permissions page in the Purview portal</li></ul></li> <li>Admins can <b>view all role memberships and assignments</b> without being able to modify them.</li> <li>The feature will be enabled automatically for eligible roles.</li><li>No changes are made to existing permissions or role assignments.</li><li>There is no impact to user workflows.</li> </ul> <p><b>[Action Required/Recommendations:]</b></p> <ul> <li>No action is required.</li><li>Review internal governance or auditing processes to determine if additional stakeholders should be assigned <b>Global Reader</b> or <b>Security Reader</b> roles for visibility.</li><li>Inform compliance or security teams of increased transparency capabilities.</li><li>Update internal documentation if referencing role visibility limitations.</li> </ul> <p><b>Learn more: </b><a href="https://learn.microsoft.com/purview/purview-permissions" target="_blank">Permissions in the Microsoft Purview portal | Microsoft Learn</a>&nbsp;(will be updated before rollout)</p><p><b>[Compliance considerations:]</b></p><table class="table table-bordered"><tbody><tr><td><b>Area</b></td><td><b>Explanation</b></td></tr><tr><td>Does the change alter how admins can monitor, report on, or demonstrate compliance activities?</td><td>Admins gain expanded visibility into role assignments and scopes within the Purview portal, improving compliance transparency and audit support.</td></tr><tr><td>Does the change include an admin control and, can it be controlled through Entra ID group membership?</td><td>Access is governed through existing Global Reader and Security Reader roles, which can be managed via Entra ID role assignments (including group-based assignment), or role group management in the Microsoft Purview portal.</td></tr></tbody></table>
New
<p>Updated July 28, 2026: We have updated the timeline. Thank you for your patience.</p><p><b>[What and Why:]</b></p><p>Microsoft Purview is introducing a new <b>view-only role management capability</b> that enables administrators with <b>Global Reader</b> and <b>Security Reader</b> roles to view role assignments and scopes within the Microsoft Purview portal and Microsoft Defender portal. This update improves visibility and transparency of compliance role configurations without granting additional permissions, supporting audit readiness and strengthening enterprise security governance.</p> <p><b>Rollout Schedule:</b></p><ul> <li>Worldwide (General Availability), GCC, GCC High, DoD: Beginning in<b> late August 2026</b> and expect to complete by<b> late September 2026</b></li> </ul> <p><b>[Impact on Your Organization:]</b></p> <p><b>Who is affected:&nbsp;</b>Administrators assigned Global Reader or Security Reader roles in Microsoft Entra ID and Microsoft Purview</p> <p><b>Platforms/Services:</b></p> <ul> <li>Microsoft Purview compliance portal (web)</li> <li>Microsoft Entra ID</li> </ul> <p><b>What will happen:</b></p> <ul> <li>Users with <b>Global Reader</b> and <b>Security Reader</b> roles will gain <b>read-only access</b> to the following settings<ul><li>Roles and scope pages in the Microsoft Purview portal</li><li>Permissions page in the Purview portal</li></ul></li> <li>Admins can <b>view all role memberships and assignments</b> without being able to modify them.</li> <li>The feature will be enabled automatically for eligible roles.</li><li>No changes are made to existing permissions or role assignments.</li><li>There is no impact to user workflows.</li> </ul> <p><b>[Action Required/Recommendations:]</b></p> <ul> <li>No action is required.</li><li>Review internal governance or auditing processes to determine if additional stakeholders should be assigned <b>Global Reader</b> or <b>Security Reader</b> roles for visibility.</li><li>Inform compliance or security teams of increased transparency capabilities.</li><li>Update internal documentation if referencing role visibility limitations.</li> </ul> <p><b>Learn more: </b><a href="https://learn.microsoft.com/purview/purview-permissions" target="_blank">Permissions in the Microsoft Purview portal | Microsoft Learn</a>&nbsp;(will be updated before rollout)</p><p><b>[Compliance considerations:]</b></p><table class="table table-bordered"><tbody><tr><td><b>Area</b></td><td><b>Explanation</b></td></tr><tr><td>Does the change alter how admins can monitor, report on, or demonstrate compliance activities?</td><td>Admins gain expanded visibility into role assignments and scopes within the Purview portal, improving compliance transparency and audit support.</td></tr><tr><td>Does the change include an admin control and, can it be controlled through Entra ID group membership?</td><td>Access is governed through existing Global Reader and Security Reader roles, which can be managed via Entra ID role assignments (including group-based assignment), or role group management in the Microsoft Purview portal.</td></tr></tbody></table>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.