Home > Functional Roles > View and Update Functional Role Details

Export to PDF

View and Update Functional Role Details

Clicking a functional role will redirect you to the Functional role details page where you can view and manage the functional role details.

Cloud Functional Role

Switch among the following tabs to update function role details:

  • Basics – Under the Basics tab, you can update the functional role’s display name and description if needed. If the functional role is dynamic, you can also update the rules if required.

  • Members – Under the Members tab, you can manage functional role members. If the functional role is dynamic, you cannot add or remove members.

  • Distribution groups – This tab displays all distribution groups within the tenant.

    To add this functional role to a specific distribution group, enable the toggle; to remove this functional role from a specific distribution group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Licenses – Under the Licenses tab, you can assign or remove licenses for the functional role members. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    Note the following:

    • License assignments will be blocked if no user seats are available and the tenant is not connected to a marketplace.

    • If the tenant is connected to a marketplace, license assignment remains available even with zero available units. Selecting a license will automatically create a license request. For detailed instructions on connecting a tenant to a marketplace, refer to Marketplace.

  • Security groups – This tab displays all security groups within the tenant.

    To add this functional role to a specific security group, enable the toggle; to remove this functional role from a specific security group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Mail-enabled security groups – This tab displays all mail-enabled security groups within the tenant.

    To add this functional role to a specific mail-enabled security group, enable the toggle; to remove this functional role from a specific mail-enabled security group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Shared mailboxes– This tab displays all shared mailboxes within the tenant.

    To add mailbox permissions, click the name of a shared mailbox. From the Permissions drop-down list, select one or multiple permissions, and click Apply. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    • Full access – Allows a user to open and read/delete emails, manage folders, and act as the mailbox owner. It does not allow sending emails on behalf of the mailbox owner.

    • Send as – Allows a user to send emails as if they were the mailbox.

    • Send on behalf – Allows a user to send emails on behalf of the mailbox owner.

  • Equipment mailboxes – This tab displays all equipment mailboxes within the tenant.

    To add mailbox permissions, click the name of a shared mailbox. From the Permissions drop-down list, select one or multiple permissions, and click Apply. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    • Full access – Allows a user to open and read/delete emails, manage folders, and act as the mailbox owner. It does not allow sending emails on behalf of the mailbox owner.

    • Send as – Allows a user to send emails as if they were the mailbox.

    • Send on behalf – Allows a user to send emails on behalf of the mailbox owner.

  • Room mailboxes – This tab displays all room mailboxes within the tenant.

    To add mailbox permissions, click the name of a shared mailbox. From the Permissions drop-down list, select one or multiple permissions, and click Apply. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    • Full access – Allows a user to open and read/delete emails, manage folders, and act as the mailbox owner. It does not allow sending emails on behalf of the mailbox owner.

    • Send as – Allows a user to send emails as if they were the mailbox.

    • Send on behalf – Allows a user to send emails on behalf of the mailbox owner.

  • Application groups – This tab displays all application groups (security groups) within the tenant.

    To add this functional role to a specific application group, enable the toggle; to remove this functional role from a specific application group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    To export application groups, click Export. A process will start to export the records. To view the process status, you can go to Process center.

  • Azure applications – This tab displays all Azure applications within the tenant.

    To add this functional role to a specific Azure application, enable the toggle; to remove functional role user from a specific Azure application, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • SharePoint – This tab displays all SharePoint sites within the tenant. Clicking a site name will redirect you to a new page where its subsites are displayed.

    To add this functional role to the site visitors, site members, or site owners group of a subsite, turn on the toggle of the corresponding group; to remove this functional role from the site visitors, site members, or site owners group of a subsite, turning off the toggle of the corresponding group. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Portal access roles – Refer to the section below.

  • Compliance policies – This tab displays compliance policies assigned to the functional role. Compliance policies are managed in the device management module. For detailed instructions, refer to Manage Policies.

    To assign a compliance policy to a functional role, click Assign policy, select the compliance policies to be assigned, and click Assign.

    To unassign a compliance policy from a functional role, select the compliance policy from the table, click Unassign policy, and then click Unassign policy in the confirmation message.

  • Intune apps – This tab displays Intune apps assigned to the functional role. Intune apps are managed in the device management module. For detailed instructions, refer to Manage Apps.

    To assign an Intune app to a functional role, click Assign app, select the Intune apps to be assigned, and click Assign.

    To unassign an Intune app from a functional role, select the Intune app from the table, click Unassign app, and then click Unassign app in the confirmation message.

  • Configuration profiles – This tab displays configuration profiles assigned to the functional role. Configuration profiles are managed in the device management module. For detailed instructions, refer to Manage Policies.

    To assign a configuration profile to a functional role, click Assign profile, select the configuration profiles to be assigned, and click Assign.

    To unassign a configuration profile from a functional role, select the configuration profile from the table, click Unassign profile, and then click Unassign profile in the confirmation message.

  • Teams – This tab displays Teams.

    To add this functional role to a specific team, enable the toggle; to remove this functional role from a specific team, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Audit Logs – This tab displays all action records performed to the current functional role.

On-Premises/Hybrid Functional Role

Switch among the following tabs to update function role details:

  • Basics – Under the Basics tab, you can update the functional role’s display name and description if needed. If the functional role is dynamic, you can also update the rules if required.

  • Members – Under the Members tab, you can manage functional role members. If the functional role is dynamic, you cannot add or remove members.

  • Local distribution groups – This tab displays all local distribution groups within the tenant.

    To add this functional role to a specific local distribution group, enable the toggle; to remove this functional role from a specific local distribution group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Licenses – Under the Licenses tab, you can assign or remove licenses for the functional role members. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    Note the following:

    • License assignments will be blocked if no user seats are available and the tenant is not connected to a marketplace.

    • If the tenant is connected to a marketplace, license assignment remains available even with zero available units. Selecting a license will automatically create a license request. For detailed instructions on connecting a tenant to a marketplace, refer to Marketplace.

  • Local Security groups – This tab displays all local security groups within the tenant.

    To add this functional role to a specific local security group, enable the toggle; to remove this functional role from a specific local security group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

  • Local application groups – This tab displays all local application groups (security groups) within the tenant.

    To add this functional role to a specific local application group, enable the toggle; to remove this functional role from a specific local application group, disable the toggle. A value changed icon will appear in each updated field. There is a message bar indicating the number of changes under the tab. When ready, you can click Apply changes to apply the updates in batch.

    To export application groups, click Export. A process will start to export the records. To view the process status, you can go to Process center.

  • Audit Logs – This tab displays all action records performed to the current functional role.