A unified data governance solution that helps manage, protect, and discover data across your organization
Hi SudhakarReddy Marepalli,
Thankyou for reaching Microsoft Q&A!
Based on the activities you’re enabling in Microsoft Purview, you can proceed with the following role assignments to unblock implementation.
For working with data products, including creating and managing custom attributes and defining business concept attributes, you’ll need Data Curator access on the target collection. This role provides the required permissions to manage metadata, glossary terms, and custom attributes in the Unified Catalog. If delegation or access control needs to be handled within the collection, Collection Administrator can be assigned in addition.
For data observability scenarios such as profiling, data quality checks, and anomaly detection, ensure that a Data Source Administrator is assigned to register sources and run scans, as scans are what enable profiling and data extraction. Alongside this, Data Curator access is required to configure rules, enrich metadata, and work with the results. Access to view data health and insights is covered through standard read permissions on the catalog.
For sensitivity labels, these are created and managed through Microsoft Purview Information Protection. To create and publish labels, assign either Information Protection Administrator or Compliance Administrator in Microsoft 365. Once labels are configured and scans are in place, they will be visible in Purview, and users with catalog access (such as Data Curator or Data Reader) will be able to view them on assets.
For workflow automation, including approval and stewardship workflows, assign the Workflow Administrator role to users who will design and manage workflows. They should also have at least read access to the catalog to associate workflows with the relevant assets.
assigning Data Curator (for governance and metadata), Data Source Administrator (for scanning and observability enablement), Workflow Administrator (for workflows), and the appropriate Microsoft 365 roles for sensitivity labeling will cover the scenarios you outlined. Additionally, please ensure that Data Quality/Data Health and workflow features are enabled in your Purview account, and that the required licensing for sensitivity labeling is in place.
For reference:
https://dotnet.territoriali.olinfo.it/purview/data-governance-roles-permissions https://dotnet.territoriali.olinfo.it/azure/purview/catalog-permissions
https://dotnet.territoriali.olinfo.it/purview/purview-information-protection-overview
Please let me know if you’d like help validating role assignments for a specific collection or scenario.