Microsoft Purview: Role Group changes in Purview
- Vendor
- Microsoft
- Product
- Microsoft Purview
- Type
- Security
- Announcement date
- 2026-02-04
- Effective date
- Date not published
- Impact
- Affected
In brief
Microsoft Purview: Role Group changes in Purview
What the source says
We are introducing a new Microsoft Purview RBAC role—Purview Agent Deployment—and adding it to various existing built in role groups used by analysts and admins across Purview. This change enables users who use built-in role analyst groups to deploy Security Copilot Agents in Purview without needing any additional roles. If your organization prefers to limit agent deployment permissions, you can create a custom role group that does not include the Purview Agent Deployment role and assign that custom role group to analysts who should not be able to deploy agents. This update does not change default data access or expand visibility into customer content. All other permissions within each role group remain unchanged. Analysts who are assigned to custom role groups will not be able to deploy agents unless the Purview Agent Deployment role is explicitly added to those custom groups. We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these change We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these changes. GA date: February CY2026 Launched General Availability Worldwide (Standard Multi-Tenant) Microsoft Purview Web
Read the primary source
Choose your reading
The role changes the reading angle, not the facts, date or level of evidence.
Reading for a salesperson
Who is affected: The audience described by the Microsoft update is represented by: Microsoft Purview: Role Group changes in Purview We are introducing a new Microsoft Purview RBAC role—Purview Agent Deployment—and adding it to various existing built in role groups used by analysts and admins across Purview. This change enables users who use built-in role analyst groups to deploy Security Copilot Agents in Purview without needing any additional roles. If your organization prefers to limit agent deployment permissions, you can create a custom role group that does not include the
Why it matters: The change matters because the official source describes: Microsoft Purview: Role Group changes in Purview We are introducing a new Microsoft Purview RBAC role—Purview Agent Deployment—and adding it to various existing built in role groups used by analysts and admins across Purview. This change enables users who use built-in role analyst groups to deploy Security Copilot Agents in Purview without needing any additional roles. If your organization prefers to limit agent deployment permissions, you can create a custom role group that does not include the
Urgency: Monitor
Next action: Review affected accounts with the customer using the official announcement.
Commercial opportunities
- Use the verified change to open a scoped customer conversation.
Technical actions
- Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
- Does this documented change affect a product or workload in scope?
Risks and objections
- The official source does not establish facts beyond the quoted material.
Points to confirm
- The effective date is unknown and must be confirmed before scheduling action.
Evidence and traceability
Each excerpt is linked to the primary source and retained for verification.
- Raw capture
2026-08-29T09:22:49.319599+00:00
- Event
Microsoft Purview: Role Group changes in Purview We are introducing a new Microsoft Purview RBAC role—Purview Agent Deployment—and adding it to various existing built in role groups used by analysts and admins across Purview. This change enables users who use built-in role analyst groups to deploy Security Copilot Agents in Purview without needing any additional roles. If your organization prefers to limit agent deployment permissions, you can create a custom role group that does not include the Purview Agent Deployment role and assign that custom role group to analysts who should not be able to deploy agents. This update does not change default data access or expand visibility into customer content. All other permissions within each role group remain unchanged. Analysts who are assigned to custom role groups will not be able to deploy agents unless the Purview Agent Deployment role is explicitly added to those custom groups. We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these change We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these changes. GA date: February CY2026 Launched General Availability Worldwide (Standard Multi-Tenant) Microsoft Purview Web
source - Product Microsoft Purview
Microsoft Purview: Role Group changes in Purview We are introducing a new Microsoft Purview RBAC role—Purview Agent Deployment—and adding it to various existing built in role groups used by analysts and admins across Purview. This change enables users who use built-in role analyst groups to deploy Security Copilot Agents in Purview without needing any additional roles. If your organization prefers to limit agent deployment permissions, you can create a custom role group that does not include the Purview Agent Deployment role and assign that custom role group to analysts who should not be able to deploy agents. This update does not change default data access or expand visibility into customer content. All other permissions within each role group remain unchanged. Analysts who are assigned to custom role groups will not be able to deploy agents unless the Purview Agent Deployment role is explicitly added to those custom groups. We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these change We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these changes. GA date: February CY2026 Launched General Availability Worldwide (Standard Multi-Tenant) Microsoft Purview Web
source - Insight a salesperson
Microsoft Purview: Role Group changes in Purview We are introducing a new Microsoft Purview RBAC role—Purview Agent Deployment—and adding it to various existing built in role groups used by analysts and admins across Purview. This change enables users who use built-in role analyst groups to deploy Security Copilot Agents in Purview without needing any additional roles. If your organization prefers to limit agent deployment permissions, you can create a custom role group that does not include the Purview Agent Deployment role and assign that custom role group to analysts who should not be able to deploy agents. This update does not change default data access or expand visibility into customer content. All other permissions within each role group remain unchanged. Analysts who are assigned to custom role groups will not be able to deploy agents unless the Purview Agent Deployment role is explicitly added to those custom groups. We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to reflect these change We recommend reviewing and updating your organization’s RBAC documentation, internal processes, or onboarding guides to
source
Back to the public feed