EmDash tenant roles are bundled permission sets for people who administer or use a tenant. Assign the least-privileged role that fits the person’s work, then confirm the result in Settings → User Management.

Before assigning a role

  • A role does not grant an unlicensed capability. The tenant must also have the required module entitlement; review Settings → Modules.
  • Read access and manage access are separate. A person may be able to view a page without being able to change settings, start an assessment, modify an incident, or perform a quarantine action.
  • Only Tenant Global Admin can invite users, change tenant roles, or remove memberships. Role assignment is a tenant-wide administrative change, so review the resulting Audit Trail event.
  • SAT learners are not tenant administrators. They use a separate training identity and assignment flow described in Security Awareness Training.

Tenant administration

Role Intended for Main capabilities and boundaries
Tenant Global Admin The people accountable for the whole tenant Full tenant administration across users, security, settings, integrations, licensed modules, billing, and SAT. This is the only role that administers memberships. It should be limited to trusted administrators.
Tenant Global Reader Broad read-only oversight Read-only visibility across tenant pages, reports, security summaries, integrations, licensing, billing, Audit Trail, and SAT reporting. It cannot change settings, manage users, expose sensitive message content, or perform response actions.

Security operations

Role Intended for Main capabilities and boundaries
Security Reader People who monitor security status Read dashboard security aggregates, incident summaries, and quarantine status. It does not grant investigation detail, message-body access, or response actions.
Security Investigator Analysts investigating suspicious activity Run threat hunts, inspect message metadata and structured findings, investigate incidents, and request permitted URL or attachment checks. It does not grant message bodies, excerpts, screenshots, AI analysis, or destructive response actions.
Security Operator Analysts who also take approved response actions Investigate incidents, add analyst feedback, manage permitted incident and quarantine actions, and run operational security checks. Provider-side completion and any separate action permission still apply.
Quarantine Operator People responsible for held-message workflows Review quarantine evidence and manage permitted quarantine actions without receiving tenant-wide administration access.
Detection Administrator People tuning detection behavior Review and manage detection models, thresholds, signal inputs, and readiness validation. This role is not a substitute for incident investigation or tenant administration.

Protection and identity

Role Intended for Main capabilities and boundaries
DMARC Reports Reader People who review email authentication posture Read DMARC domains, aggregate reports, sending sources, alignment findings, policies, and recommendations. It cannot change DMARC configuration.
DMARC Administrator People who operate DMARC Configure DMARC domains, policies, reporting, sending-source decisions, and recommendations. Domain ownership and DNS changes remain subject to their own verification steps.
Authentication Administrator People who manage tenant sign-in Review and manage authentication settings, verified domains, and authentication tests. This role does not automatically grant Microsoft 365 or Entra integration administration.
Integration Administrator People who connect and maintain services Manage Microsoft 365, Entra ID, Defender, consent, probes, connection tests, and integration health. Provider consent and module requirements still apply.
Domain Administrator People who manage domain ownership and DNS setup Add domains, complete ownership verification, review DNS configuration, and use Domain Connect. It does not grant DMARC policy management unless that permission is also assigned.
Posture Administrator People who run email-posture assessments View and manage Email Posture assessments and findings. Microsoft 365 connection health, licensing, and provider permissions can still make individual checks unavailable.

Reporting and billing

Role Intended for Main capabilities and boundaries
Audit Reader People who need an administrative history Read the tenant-scoped Audit Trail, filters, event details, and redacted metadata. It cannot change tenant data or audit records.
Licensing Reader People who monitor entitlements and usage View module status, quantities, renewal dates, usage, and over-allocation. It cannot change licences or assign roles.
Billing Reader People who need invoice visibility View issued invoice history, totals, statuses, billing details, and PDF downloads. It cannot edit billing profiles or contacts.
Billing Administrator People who manage tenant billing details View invoices and manage the billing profile and named billing contacts. Issuing, voiding, and recording payments remain staff billing workflows.

Security Awareness Training

Role Intended for Main capabilities and boundaries
SAT Creator People who author training content Create, edit, preview, publish, and archive tenant SAT learning content. It does not grant assignment, settings, notification, or report-export administration.
SAT Administrator People who run the training programme Manage SAT content, assignments, learner access, settings, notifications, reports, and exports. Learner sign-in and completion still happen through the separate training experience.

When access is missing

The portal checks the required module and role permission before loading a protected page. If either is missing, direct navigation shows the generic message “The required module or role is missing for this page.” and a link back to the homepage. Navigation also hides pages the current session cannot open. Ask a Tenant Global Admin to review both the module entitlement and your role rather than trying alternate URLs.

Changing a role safely

Start with the narrowest role that supports the person’s job. If responsibilities change, update the membership in User Management, confirm the new page visibility, and review the Audit Trail. Keep sensitive investigation permissions and broad administration roles limited to people who need them.