EmDash uses two independent checks: a tenant must have the relevant licensed module, and your bundled role must grant the required permission. A role never unlocks an unlicensed module.

Modules

Module Main capability
ICES Mail telemetry, message investigation, incidents, quarantine, Email Posture, and detection models.
DMARC Domain authentication reporting, sources, alignment, policy, and recommendations.
SAT Security Awareness Training content, assignments, learner access, and reports.
XDR Microsoft Defender security detections and related response views.

Review current entitlement state in Settings → Modules. Module cards show whether a capability is active and provide context for unavailable pages.

Bundled roles

Roles are bundled permission sets that make common job responsibilities easy to assign and review. Read the complete tenant role catalogue for each role’s purpose, capabilities, and limits.

Only Tenant Global Admins can invite users and change tenant roles. Use Settings → User Management to review memberships and current permissions.

Read versus manage

Read access lets a person view a page or status. Manage permissions are checked separately for actions such as changing thresholds, running an assessment, taking a quarantine action, sending an invitation, or changing a connection. Never treat a visible page as proof that a mutation will be allowed.

Some useful read keys are audit:read, integrations:read, billing:read, users:read, dmarc:read, posture:read, and sat:read. The portal uses these keys internally; administrators assign the bundled role that grants them rather than composing arbitrary permissions.

Missing access

If the required module or role is missing, the page shows a generic unavailable message and a link to /. Navigation also hides links that your session cannot open. Ask a Tenant Global Admin to check both the module entitlement and your role; do not work around the message by guessing alternate URLs.