Cybersecurity dashboard showing a central shield, user profiles, document protection, and compliance analytics.
Microsoft Purview diagnostics no longer need to be a Global Administrator-only task under Microsoft 365 Roadmap item 500396. Microsoft’s roadmap entry says access has expanded to the Compliance Administrator, Security Administrator, and Organization Management roles for worldwide standard multi-tenant tenants, with preview dated October 2025 and general availability dated December 2025.

For security and compliance teams, the practical payoff is straightforward: day-to-day troubleshooting of labels, encryption, data loss prevention, and related Purview configuration can move away from a tenant’s highest-privilege identity. But administrators should not treat the roadmap wording as a blanket permission grant for every diagnostic surfaced anywhere in Purview. Microsoft’s current documentation shows that access still depends on which diagnostic is being run and where it is launched.

The dated roadmap status also obscures an important detail. This is an older broad portal entitlement, not the most recent Purview diagnostics change. Microsoft subsequently published a separate Data Loss Prevention-specific rollout under Roadmap ID 500894, with a Message Center notice that placed its worldwide deployment from early February through mid-March 2026. The newer item widened access to DLP diagnostics further than the three roles named in Roadmap 500396.

Roadmap 500396 reduces Global Administrator dependency​

Microsoft originally described Roadmap 500396 in August 2025 as an expansion of Microsoft Purview Compliance Portal diagnostics beyond Global Administrator accounts. The entry’s final milestone was December 2025, and the item is now marked launched.

That is a welcome correction to a common Microsoft 365 administration problem: many diagnostic and support workflows historically required Global Administrator credentials even when the person investigating the issue was responsible only for security, compliance, or information protection. A Global Administrator has broad directory and service control, including the ability to manage role assignments and, in some cases, elevate access across Azure resources. Using such an account for routine policy troubleshooting runs against Microsoft’s own guidance to keep the number of Global Administrators low.

Microsoft Entra’s role documentation describes Compliance Administrator and Security Administrator as privileged roles. Compliance Administrators can manage compliance features and reports across Purview and related Microsoft 365 services, while Security Administrators can manage security policies, investigate threats, and access reports in Purview and Microsoft Defender. Organization Management is a Purview role group with broad administrative authority inside the compliance service.

The change therefore supports separation of duties: the people who own a control can investigate its configuration without borrowing a break-glass-level identity. It does not turn Purview diagnostics into a read-only function, nor does it make those newly eligible roles low privilege.


Diagnostics can expose configuration, even when they do not alter it​

Microsoft Learn describes Purview self-help diagnostics as tools that identify known configuration problems and provide remediation guidance. Some diagnostic workflows can resolve configuration issues, but Microsoft says they do not change tenant settings without consent.

The diagnostics are more substantive than a portal health check. On Purview solution pages, they can test sensitivity-label and label-policy visibility, email encryption settings, DLP policy scope, endpoint DLP policy synchronization, DLP alert configuration, SharePoint and OneDrive file evaluation, Exchange Online message handling, and Outlook on the web policy-tip problems.

Behind the portal interface, Microsoft says solution-page diagnostics run the Check-PurviewConfig PowerShell cmdlet first, then invoke additional checks suited to the selected issue. A DLP investigation, for example, can retrieve policy and rule configuration; a label diagnostic can enumerate available labels and policies; an encryption test can assess Information Rights Management and mail-flow configuration.

That makes delegated access useful, but it also means the people assigned these roles may see sensitive operational metadata: user identities, mailbox or policy names, SharePoint site names, file paths, message subjects, and configuration results. Microsoft says the diagnostic service does not access customer content such as email bodies, documents, or chats, and that data processed for a diagnostic is deleted after the diagnostic finishes. Those limits reduce exposure, but they do not eliminate the need to restrict access to personnel with a defined operational role.

The current role matrix is more complicated than the roadmap entry​

The wording in Roadmap 500396 is simple: Compliance Administrator, Security Administrator, and Organization Management gain access. Microsoft’s current Purview diagnostics documentation is not.

For Information Protection diagnostics run from Purview solution pages, Microsoft lists Compliance Administrator and Security Administrator as the roles required to run the tools. The documentation does not list Organization Management in that specific requirement.

For DLP diagnostics on solution pages, Microsoft lists an even broader collection of eligible roles: Compliance Administrator, Security Administrator, Organization Configuration, View-Only Configuration, Security Reader, DLP Compliance Management, View-Only DLP Compliance Management, Insider Risk Management Administrator, Information Protection Administrator, Information Protection Analyst, Information Protection Investigator, and Data Security AI Administrator.

There are two implications for tenants reviewing their permissions.

First, Roadmap 500396 should not be used as the definitive role matrix. The current Microsoft Learn article is the operational record for a specific diagnostic page, and it may be updated as Purview adds tests or reshapes permissions.

Second, similarly named roles are not interchangeable. Organization Management is the role group named in the roadmap item. Organization Configuration, which appears in the current DLP diagnostic requirements, is a different Purview role group. An administrator who assigns one while intending to grant the other may either fail to solve the access issue or grant broader capabilities than the immediate troubleshooting task requires.

Microsoft’s subsequent DLP-specific announcement illustrates how quickly this area has changed. Its Message Center notice, associated with Roadmap 500894 rather than 500396, said DLP diagnostics would become available to Compliance Administrator, Security Administrator, and Organization Management without manual enablement. Yet the current Learn page lists more roles than that announcement did. The documentation is more useful than the roadmap when deciding who can run a particular tool today.


Help-pane diagnostics still have separate minimum roles​

The newer solution-page permissions do not automatically apply to diagnostics initiated through the Help pane in the Microsoft Purview portal or Microsoft 365 admin center.

Microsoft’s documentation still assigns different minimum roles for several Help-pane tests. Mailbox-hold and grace eDiscovery-hold diagnostics require Compliance Administrator. The eDiscovery RBAC check and several Exchange-related diagnostics can run with any Microsoft 365 administrator role. By contrast, the Help-pane diagnostics for DLP policy and rule configuration, DLP policy tips, sensitivity-label configuration, and audit configuration still identify Global Administrator as the minimum role.

This is the central operational caveat missing from the one-line roadmap description: the same broad troubleshooting category can have different permission requirements depending on the entry point. A Compliance Administrator may be able to run a DLP diagnostic from the DLP solution page but find that a Help-pane workflow remains unavailable without Global Administrator access.

That disparity is not necessarily an error. Help-pane diagnostics can gather different inputs and run different checks than the scenario-specific tests on a Purview solution page. But administrators should expect it, document it, and avoid reflexively restoring Global Administrator to a daily-use account when the issue is simply that they launched the wrong diagnostic.

What Purview administrators should change​

Organizations that still rely on Global Administrator accounts for routine Purview troubleshooting should review their role assignments and test actual workflows using a non-Global Administrator account. Start with the narrowest role that maps to the team’s responsibility and the diagnostic being used.

  • Compliance teams should validate Information Protection and DLP diagnostics with a dedicated Compliance Administrator account rather than a Global Administrator account.
  • Security operations teams should test the relevant Purview diagnostic paths under Security Administrator, particularly where DLP and security-policy troubleshooting overlap.
  • Teams using Organization Management should confirm that the assignment is intentional, because it is a broad Purview role group and is not merely a diagnostic-reader entitlement.
  • Administrators should test both a solution-page diagnostic and a Help-pane diagnostic before removing an emergency Global Administrator dependency from a runbook.
  • Role reviews should include the wider DLP list in Microsoft Learn, especially Security Reader and view-only-oriented groups, where a team needs investigation capability without broad configuration authority.

The feature is enabled by default, so there is no tenant switch to configure. The administrative work is in validating entitlement boundaries, updating support runbooks, and making sure privileged access management policies do not leave routine diagnostics dependent on permanent Global Administrator assignments.

Roadmap 500396 is best understood as the start of that delegation effort, not its final permission blueprint. Microsoft’s current Purview documentation shows a more granular reality: access has expanded, but the exact role required still follows the diagnostic, the portal surface, and the service area being investigated.