Skip to main content

Security Operator

Type: Admin role

Membership in this role group is synchronized across services and managed centrally. This role group is not manageable through Microsoft Exchange or Security and Compliance Center (SCC). Members of this role group may include cross-service administrators that have access beyond Exchange and SCC. By default, this group is not assigned any roles. However, it will be a member of the 'Records Management' and 'Compliance Management' role groups in Exchange and 'Compliance Data Administrator' role group in SCC. It will inherit the permissions of these role groups.

RoleGroupRoleRole Description
Security OperatorTenant AllowBlockList ManagerLets people manage tenant allow block list settings.
CmdletRoleCmdlet Description
Get-ArcConfigTenant AllowBlockList Manager
Get-TenantAllowBlockListItemsTenant AllowBlockList ManagerYou need to be assigned permissions before you can run this cmdlet. Although this topic lists all parameters for the cmdlet, you may not have access to some parameters if they're not included in the permissions assigned to you. To find the permissions required to run any cmdlet or parameter in your organization, see Find the permissions required to run any Exchange cmdlet (https://docs.microsoft.com/powershell/exchange/find-exchange-cmdlet-permissions).
Get-TenantAllowBlockListSpoofItemsTenant AllowBlockList Manager
New-TenantAllowBlockListItemsTenant AllowBlockList ManagerYou need to be assigned permissions before you can run this cmdlet. Although this topic lists all parameters for the cmdlet, you may not have access to some parameters if they're not included in the permissions assigned to you. To find the permissions required to run any cmdlet or parameter in your organization, see Find the permissions required to run any Exchange cmdlet (https://docs.microsoft.com/powershell/exchange/find-exchange-cmdlet-permissions).
New-TenantAllowBlockListSpoofItemsTenant AllowBlockList Manager
Remove-TenantAllowBlockListItemsTenant AllowBlockList ManagerYou need to be assigned permissions before you can run this cmdlet. Although this topic lists all parameters for the cmdlet, you may not have access to some parameters if they're not included in the permissions assigned to you. To find the permissions required to run any cmdlet or parameter in your organization, see Find the permissions required to run any Exchange cmdlet (https://docs.microsoft.com/powershell/exchange/find-exchange-cmdlet-permissions).
Remove-TenantAllowBlockListSpoofItemsTenant AllowBlockList Manager
Set-ArcConfigTenant AllowBlockList Manager
Set-TenantAllowBlockListItemsTenant AllowBlockList ManagerYou need to be assigned permissions before you can run this cmdlet. Although this topic lists all parameters for the cmdlet, you may not have access to some parameters if they're not included in the permissions assigned to you. To find the permissions required to run any cmdlet or parameter in your organization, see Find the permissions required to run any Exchange cmdlet (https://docs.microsoft.com/powershell/exchange/find-exchange-cmdlet-permissions).
Set-TenantAllowBlockListSpoofItemsTenant AllowBlockList Manager