Role management allows you to make additional role assignments for roles in Azure Active Directory partial scopes.
To assign a role assignment to a role
- In the Manager, select the Azure Active Directory > Roles category.
- Select the role in the result list.
- Select the Add or remove role assignments task.
- Click Add and enter the following information.
- Principal: The main principal whose accesses are to be assigned such as a group or single user.
- Application scope: The application scope for which the principal should be given access. - OR -
Directory scope: The directory scope for which the principal should be given access.
- Specify whether this assignment is a Direct assignment.
NOTES: The Indirect assignment and Assignment request options are set by processes and cannot be set manually.
- Request procedure: References the request procedure that results in the assignment.
NOTE: The request procedure is set by processes and cannot be set manually.
NOTE: There is more information available about role assignments for roles in PIM mode (Azure AD P2 license).
Related topics
To edit the main data of a role assignment
-
In the Manager, select the Azure Active Directory > Role assignments category.
-
Select the role assignment in the result list.
-
Select the Change main data task.
-
Edit the main data of the role assignment.
-
Save the changes.
To delete a role assignment
-
In the Manager, select the Azure Active Directory > Role assignments category.
-
Select the role assignment in the result list.
-
Click in the result list.
- Confirm the security prompt with Yes.
-
Save the changes.
In Azure Active Directory, active role assignments for groups can be assigned in specified partial scopes.
To assign a system role to scope
-
In the Manager, select the Azure Active Directory > Scoped role assignments category.
-
Select the role in the result list.
-
Select the Assign system roles task.
-
In the Add assignments pane, assign system roles.
TIP: In the Remove assignments pane, you can remove assigned system roles.
To remove an assignment
-
Save the changes.
To assign a business role to a scope
-
In the Manager, select the Azure Active Directory > Scoped role assignments category.
-
Select the role in the result list.
-
Select the Assign business roles task.
-
In the Add assignments pane, select the role class and assign business roles.
TIP: In the Remove assignments pane, you can remove assigned business roles.
To remove an assignment
-
Save the changes.
To assign an organization to a scope
-
In the Manager, select the Azure Active Directory > Scoped role assignments category.
-
Select the role in the result list.
-
Select the Assign organizations task.
In the Add assignments pane, assign the organizations:
-
On the Departments tab, assign departments.
-
On the Locations tab, assign locations.
-
On the Cost centers tab, assign cost centers.
TIP: In the Remove assignments pane, you can remove assigned organizations.
To remove an assignment
-
Save the changes.
Related topics