Skip to content

Commit 29834b3

Browse files
authored
Merge pull request #27056 from MicrosoftDocs/main
Publish main to live, Tuesday 3:30PM PST, 11/19
2 parents 4370440 + 6ad80b1 commit 29834b3

24 files changed

Lines changed: 230 additions & 167 deletions

copilot/copilot-prompt-gallery.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ Each suggested prompt in the prompt Gallery includes additional information abou
3737

3838
Copilot Prompt Gallery processes and manages data in a structured manner to ensure compliance and security. The following are key data flows and compliance considerations:
3939

40-
:::image type="content" source="media/copilot-lab-tech-diagram.png" alt-text="Diagram showing the data flow for Copilot Prompt Gallery." lightbox="media/copilot-lab-tech-diagram.png":::
40+
:::image type="content" source="media/copilot-prompt-gallery-diagram.png" alt-text="Diagram showing the data flow for Copilot Prompt Gallery." lightbox="media/copilot-prompt-gallery-diagram.png":::
4141

4242
- Copilot Prompt Gallery is both a website and a feature of Copilot that allows users to discover, manage, use, and share Copilot prompts.
4343
- A user accesses Copilot Prompt Gallery, either via the Copilot Prompt Gallery website or in Copilot through an app.
96.2 KB
Loading

microsoft-365/admin/manage/manage-feedback-ms-org.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ f1.keywords:
55
ms.author: kwekua
66
author: kwekuako
77
manager: scotv
8-
ms.date: 10/21/2024
8+
ms.date: 11/19/2024
99
audience: Admin
1010
ms.topic: article
1111
ms.service: microsoft-365-business
@@ -98,7 +98,7 @@ The following information only applies to United States government customers usi
9898
### GCC environment
9999

100100
- Cloud Policy service for Microsoft 365 is available in this environment as of September 24, 2024.
101-
- Not all products currently support feedback collection in this environment. We anticipate most products will support feedback collection by November 15, 2024. To prepare for this rollout, we recommend you review and configure the policy settings in the way that is appropriate for your organization.
101+
- Not all products currently support feedback collection in this environment, but we're working to implement that support. To prepare for feedback collection, we recommend you review and configure the policy settings in the way that is appropriate for your organization.
102102
- When the **Allow users to submit feedback to Microsoft** policy is set to **Not Configured** in this environment, it has the same effect as if you set the policy to **Disabled**.
103103
- The Feedback portal and in-product surveys aren’t available in this environment, so setting these policies won’t have any effect at this time.
104104
- The following policies are always treated as **Disabled** in this environment regardless of how you set the policies:

microsoft-365/lighthouse/m365-lighthouse-overview-of-permissions.md

Lines changed: 57 additions & 55 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.author: sharik
55
author: SKjerland
66
manager: scotv
77
ms.reviewer: taylorau
8-
ms.date: 10/31/2024
8+
ms.date: 11/19/2024
99
audience: Admin
1010
ms.topic: concept-article
1111
ms.service: microsoft-365-lighthouse
@@ -48,67 +48,69 @@ The following table provides an overview of each Lighthouse RBAC role. For a lis
4848
| Lighthouse RBAC role | Overview |
4949
|---|---|
5050
| Account Manager | Account Managers have full access to Sales Advisor pages and data across the entire partner tenant.<br><br>Account Managers can export Sales Advisor data. |
51-
| Administrator | Administrators have full administrative permissions in Lighthouse. <br><br>Administrators can manage RBAC and GDAP permissions and can create baselines, tags, and alerts.<br><br>Administrators are automatically assigned the Privileged Role Administrator, User Administrator, and Group Administrator roles in Microsoft Entra ID and the Admin Agent role in Partner Center. |
51+
| Administrator | Administrators have full administrative permissions in Lighthouse. <br><br>Administrators can manage RBAC and GDAP permissions, view audit logs, and create baselines, tags, and alerts.<br><br>Administrators are automatically assigned the Privileged Role Administrator, User Administrator, and Group Administrator roles in Microsoft Entra ID and the Admin Agent role in Partner Center. |
52+
| Author | Authors can manage tenants, tags, alert rules, and baselines to deploy tenant configurations. |
5253
| Operator | Operators manage customer tenants in Lighthouse based on the GDAP permissions assigned to them for each customer tenant that they manage.<br><br>Operators can view high-level customer tenant status and manage alerts.<br><br>Lighthouse users who hold at least one Microsoft Entra role are automatically assigned the Operator role.<br><br>**Note:** Lighthouse Administrators can use templates on the **Delegated access** page to assign GDAP permissions to Lighthouse users. |
5354
| Reader | Readers have read-only access to data in Lighthouse.<br><br>Lighthouse Readers can view high-level customer tenant status and alerts. |
5455

5556
## Lighthouse RBAC roles and capabilities
5657

5758
The following table describes the actions that each Lighthouse RBAC role can perform in Lighthouse. For some actions, you need to hold a Microsoft Entra role in addition to a Lighthouse RBAC role. For other actions, only a Microsoft Entra role is required. Microsoft Entra role requirements are indicated in the last column of the table. For a complete list of Microsoft Entra roles and the actions they can perform, see [Microsoft Entra built-in roles](/azure/active-directory/roles/permissions-reference).
5859

59-
| Area | Actions | Account&nbsp;Manager | Administrator | Operator | Reader | Need Microsoft Entra&nbsp;role? |
60-
|---|---|:---:|:---:|:---:|:---:|:---:|
61-
| **Home page** | View data on cards | | | | | Yes |
62-
| | Add users | | | | | Yes |
63-
| | Reset password | | | | | Yes |
64-
| | Offboard users | | | | | Yes |
65-
| **Alerts** | View alerts and alert rules | &check; | &check; | | &check; | No |
66-
| | Manage alerts (change severity, status, or assignment) | | &check; | | | No |
67-
| | Create, edit, and delete alert rules | | &check; | | | No |
68-
| **Copilot insights** | View opportunities and adoption data | | | | | Yes|
69-
| **Tenants** | View the **Tenants** page | &check; | &check; | &check; | &check; | No |
70-
| | View tenant details | | | | | Yes |
71-
| | Export data | &check; | &check; | &check; | &check; | No |
72-
| | View tags | &check; | &check; | &check; | &check; | No |
73-
| | Create, update, and delete tags in Lighthouse | | &check; | | | No |
74-
| | Assign and remove tags from tenants | | &check; | | | No |
75-
| | Activate and inactivate a tenant | | &check; | | | No |
76-
| | View delegated access status | &check; | &check; | &check; | &check; | No |
77-
| | View Microsoft Secure Score | | | | | Yes |
78-
| | View baseline assignments | &check; | &check; | &check; | &check; | No |
79-
| | View deployment status | | | &check; | | Yes |
80-
| | View apps and services usage | | | &check; | | Yes |
81-
| | View and edit customer contact and website info | &check; | &check; | &check; | &check; | No |
82-
| **Users** | Search for users | | | | | Yes |
83-
| | View user metrics | | | | | Yes |
84-
| | Onboard new users | | | | | Yes |
85-
| | Offboard users | | | | | Yes |
86-
| | View inactive users | | | | | Yes |
87-
| | View shared mailboxes | | | | | Yes |
88-
| | View and manage risky users | | | | | Yes |
89-
| | View and manage multifactor authentication | | | | | Yes |
90-
| | View and manage self-service password reset | | | | | Yes |
91-
| **Devices** | View device security data | | | | | Yes |
92-
| | View vulnerability management data | | | | | Yes |
93-
| | View device compliance data | | | | | Yes |
94-
| | View threat management data | | | | | Yes |
95-
| | View device health data | | | | | Yes |
96-
| | View Windows 365 data | | | | | Yes |
97-
| | View Windows event logs | | | | | Yes |
98-
| **Apps** | View app performance and app management data | | | | | Yes |
99-
| **Quarantined messages** | View and manage quarantined messages | | | | | Yes |
100-
| **Baselines** | View baselines (default, custom) and task details | | &check; | &check; | &check; | No|
101-
| | Create, clone, edit, and assign baselines | | &check; | | | No |
102-
| | View deployment insights | | | | | Yes |
103-
| **Service&nbsp;health** | Monitor service health<sup>1</sup> | | | | | No |
104-
| **Support** | Create and manage service requests<sup>2</sup> | | | | | No |
105-
| **Audit logs** | View audit logs | | &check; | | | Yes
106-
| **Permissions** | View the **Lighthouse Permissions** page | | &check; | | | No|
107-
| | Set up and manage Lighthouse permissions | | &check; | | | No |
108-
| | View, set up, and manage GDAP on the **Delegated access** page | | &check; | | | No |
109-
| **Sales Advisor** | View opportunities | &check; | &check; | | | No |
110-
| | View subscription renewals | &check; | &check; | | | No |
111-
| | View license requests | &check; | &check; | | | No |
60+
| Area | Actions | Account&nbsp;Manager | Administrator | Author | Operator | Reader | Need Microsoft Entra&nbsp;role? |
61+
|---|---|:---:|:---:|:---:|:---:|:---:|:---:|
62+
| **Home page** | View data on cards | | | | | | Yes |
63+
| | Add users | | | | | | Yes |
64+
| | Reset password | | | | | | Yes |
65+
| | Offboard users | | | | | | Yes |
66+
| **Alerts** | View alerts and alert rules | &check; | &check; | &check; | | &check; | No |
67+
| | Manage alerts (change severity, status, or assignment) | | &check; | &check; | | | No |
68+
| | Create, edit, and delete alert rules | | &check; | &check; | | | No |
69+
| **Copilot insights** | View opportunities and adoption data | | | | | | Yes|
70+
| **Tenants** | View the **Tenants** page | &check; | &check; | &check; | &check; | &check; | No |
71+
| | View tenant details | | | | | | Yes |
72+
| | Export data | &check; | &check; | &check; | &check; | &check; | No |
73+
| | View tags | &check; | &check; | &check; | &check; | &check; | No |
74+
| | Create, update, and delete tags in Lighthouse | | &check; | &check; | | | No |
75+
| | Assign and remove tags from tenants | | &check; | &check; | | | No |
76+
| | Activate and inactivate a tenant | | &check; | &check; | | | No |
77+
| | View delegated access status | &check; | &check; | &check; | &check; | &check; | No |
78+
| | View Microsoft Secure Score | | | | | | Yes |
79+
| | View baseline assignments | &check; | &check; | &check; | &check; | &check; | No |
80+
| | View deployment status | | | | &check; | | Yes |
81+
| | View apps and services usage | | | | &check; | | Yes |
82+
| | View and edit customer contact and website info | &check; | &check; | | &check; | &check; | No |
83+
| **Users** | Search for users | | | | | | Yes |
84+
| | View user metrics | | | | | | Yes |
85+
| | Onboard new users | | | | | | Yes |
86+
| | Offboard users | | | | | | Yes |
87+
| | View inactive users | | | | | | Yes |
88+
| | View shared mailboxes | | | | | | Yes |
89+
| | View and manage risky users | | | | | | Yes |
90+
| | View and manage multifactor authentication | | | | | | Yes |
91+
| | View and manage self-service password reset | | | | | | Yes |
92+
| **Devices** | View device security data | | | | | | Yes |
93+
| | View vulnerability management data | | | | | | Yes |
94+
| | View device compliance data | | | | | | Yes |
95+
| | View threat management data | | | | | | Yes |
96+
| | View device health data | | | | | | Yes |
97+
| | View Windows 365 data | | | | | | Yes |
98+
| | View Windows event logs | | | | | | Yes |
99+
| **Apps** | View app performance and app management data | | | | | | Yes |
100+
| **Quarantined messages** | View and manage quarantined messages | | | | | | Yes |
101+
| **Baselines** | View baselines (default, custom) and task details | | &check; | &check; | &check; | &check; | No |
102+
| | Create, clone, edit, and assign baselines | | &check; | &check; | | | No |
103+
| | Extract a task from a tenant to add to a baseline | | &check; | &check; | | | Yes |
104+
| | View deployment insights | | | | | | Yes |
105+
| **Service&nbsp;health** | Monitor service health<sup>1</sup> | | | | | | No |
106+
| **Support** | Create and manage service requests<sup>2</sup> | | | | | | No |
107+
| **Audit logs** | View audit logs | | &check; | | | | Yes
108+
| **Permissions** | View the **Lighthouse Permissions** page | | &check; | | | | No |
109+
| | Set up and manage Lighthouse permissions | | &check; | | | | No |
110+
| | View, set up, and manage GDAP on the **Delegated access** page | | &check; | | | | No |
111+
| **Sales Advisor** | View opportunities | &check; | &check; | | | | No |
112+
| | View subscription renewals | &check; | &check; | | | | No |
113+
| | View license requests | &check; | &check; | | | | No |
112114

113115
<sup>1</sup> To monitor service health, Lighthouse users must hold at least one Microsoft Entra role in the partner tenant with the following property set: **microsoft.office365.serviceHealth/allEntities/allTasks**. The users must also have at least the Admin Agent role or Helpdesk Agent role assigned to them in Partner Center.
114116

microsoft-365/lighthouse/m365-lighthouse-whats-new.md

Lines changed: 27 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.author: sharik
55
author: SKjerland
66
manager: scotv
77
ms.reviewer: sharonchoi
8-
ms.date: 10/07/2024
8+
ms.date: 11/19/2024
99
audience: Admin
1010
ms.topic: whats-new
1111
ms.service: microsoft-365-lighthouse
@@ -32,6 +32,32 @@ We're continuously adding new features to [Microsoft 365 Lighthouse](m365-lighth
3232
>
3333
> To see which new features are currently available in your partner tenant, go to the **Home** page of Microsoft 365 Lighthouse, and then either select the **What's new** link in the upper-right corner of the page or select **What's new** on the **What's new & learning resources** card.
3434
35+
## November 2024
36+
37+
### New Lighthouse RBAC roles to manage partner tenant permissions
38+
39+
Microsoft 365 Lighthouse now includes the following role-based access control (RBAC) roles that you can use to manage partner tenant permissions in Lighthouse. To assign these roles, you must be a Lighthouse Administrator or a Privileged Role Administrator in Microsoft Entra ID in the partner tenant.
40+
41+
- Lighthouse Account Manager
42+
- Lighthouse Administrator
43+
- Lighthouse Author
44+
- Lighthouse Operator (automatically assigned to users with GDAP permissions for a customer tenant)
45+
- Lighthouse Reader
46+
47+
Each role has a set of permissions that determines which data users can access and change within the partner tenant. For example, you can assign the Lighthouse Account Manager role to users who require access to Sales Advisor.
48+
49+
To assign RBAC roles, in the left navigation pane in Lighthouse, select **Permissions** > **Lighthouse permissions**.
50+
51+
[Go to the Lighthouse permissions page now](https://lighthouse.microsoft.com/#view/Microsoft_Intune_MTM/RBAC.ReactView)
52+
53+
To learn more, see [Overview of permissions in Microsoft 365 Lighthouse](m365-lighthouse-overview-of-permissions.md).
54+
55+
## October 2024
56+
57+
### Easily access tenant details from any page in Lighthouse
58+
59+
We've made it easy for you to access customer tenant details from any page in Lighthouse. Previously, you had to go to the **Tenants** page and then select a tenant from the list to view the details for that tenant. Now, when you select a tenant from the **Tenants** filter on any page, a link appears next to the filter that takes you directly to the details page for the selected tenant. This functionality helps you more efficiently manage your customer tenants by giving you one-click access to important tenant information no matter where you are in Lighthouse.
60+
3561
## September 2024
3662

3763
### Delegated access page
74.6 KB
Loading
57.8 KB
Loading
83.2 KB
Loading
53 KB
Loading
94.7 KB
Loading

0 commit comments

Comments
 (0)