Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Role-based access control (RBAC) in Dragon admin center helps you manage who can perform specific actions on specific capabilities and features. RBAC helps organizations apply the principles of least-privilege access, separate duties based on roles, and meet compliance needs.
You assign roles to individual users or to Microsoft Entra security groups. Use group-based assignment to simplify onboarding and offboarding at scale. You can leverage the same security groups you created for license assignment.
Note
The roles in Dragon admin center are not Microsoft Entra roles. While they're modeled on the same RBAC principles, they're specific to Dragon admin center, with a narrower, lower-privileged scope.
Dragon admin center offers the following types of roles:
| Experience | User | Environment administrator | Analytics reader |
|---|---|---|---|
| Dragon Copilot (physicians) | Roles are available in all supported regions except the US and will be enforced by August 2026. | Roles are available in all supported regions except the US and will be enforced by August 2026. | Roles are available in all supported regions except the US and will be enforced by August 2026. |
| Dragon Copilot (nurses) | Not available yet | Not available yet | Not available yet |
| Dragon Copilot (radiologists) | N/A | N/A | N/A |
User roles
User roles are required for users to access Dragon Copilot. They determine which Dragon Copilot experience is available and which environments they can access.
Important
Every Dragon Copilot user must have a user role assigned. Users without an assigned role won't be able to access the app.
To assign user roles, you must have one of the following roles assigned to you:
- User administrator (Microsoft Entra role)
- Dragon administrator (Microsoft Entra role)
- Global administrator (Microsoft Entra role)
- Environment administrator (Dragon admin center role)
Assign a role to every Dragon Copilot end user:
- Dragon Copilot (physicians) user: Grants users access to Dragon Copilot (physicians) in their assigned environments.
- Dragon Copilot (nurses) user: Grants users access to Dragon Copilot (nurses) in their assigned environments.
- Dragon Copilot (radiologists) user: Grants users access to Dragon Copilot (radiologists) in their assigned environments.
Admin roles
Admin roles are Dragon admin center-specific roles that restrict administrative permissions to individual environments. They differ from the Microsoft Entra built-in roles - Global administrator, Dragon administrator, and User administrator - which grant broad, tenant-wide access to Dragon admin center. Use the admin roles in Dragon admin center to delegate access to specific personas without assigning a privileged Microsoft Entra role.
Environment administrator
The Environment administrator is an optional role that's useful when you want to delegate management of one or more environments to specific individuals without granting them tenant-wide access. An environment administrator can be assigned to one or more environments.
To assign the Environment administrator role, you must have one of the following roles assigned to you in your Microsoft 365 tenant:
- User administrator (Microsoft Entra role)
- Dragon administrator (Microsoft Entra role)
- Global administrator (Microsoft Entra role)
| Permission | Details |
|---|---|
| Provision and deprovision | Provision and deprovision Dragon Copilot capabilities within the assigned environment. |
| Manage organization hierarchy | Create, read, update, and delete hierarchy levels in the assigned environment. |
| Manage settings | Configure Dragon Copilot settings for users in the assigned environment, including managing user roles. |
| Manage connectors | Add, read, update, configure, and delete clinical app connectors for the assigned environment. |
| Manage AI apps and agents | Read, update, and configure AI apps and agents that have been activated for the assigned environment. |
| Manage library items | Create, read, update, and delete library items for users in the assigned environment. |
| View analytics | View, edit, and take action on analytics within the assigned environment. |
| Assign roles | Assign roles within the assigned environment. |
Note
Environment administrators don't have permission to manage nursing content in the Flowsheet manager. They're not allowed to create, read, update, and delete flowsheet template configurations, read and update guides, and read the flowsheet schema import history. To perform these actions, you must have the Dragon administrator Microsoft Entra role assigned.
Analytics reader
Assign the Analytics reader role to users who need read-only access to analytics in a specific environment.
To assign the Analytics reader role in Dragon admin center, you must have one of the following roles assigned to you:
- User administrator (Microsoft Entra role)
- Dragon administrator (Microsoft Entra role)
- Global administrator (Microsoft Entra role)
- Environment administrator (Dragon admin center role)
| Permission | Details |
|---|---|
| View analytics | Read-only access to embedded Power BI reports in the assigned environment. |
| View environments | Read-only access to the assigned environment. |
Manage roles
Use the Roles page in Dragon admin center to view role details and permissions, assign roles to users and groups, and remove assignments. The Roles page has the following tabs:
- User roles
- Admin roles
View details for a role
- In the Management section of the navigation pane, select Roles.
- Select the User roles or Admin roles tab.
- Select a role.
On the role details page, you see a short description of the role, a complete list of permissions associated with the role, and all current assignments for the role. To search for a specific assignment, enter the name of the user or group in the search field.
Use the filter options to filter the list:
- Scope: Filter by environment to show only assignments scoped to a particular environment.
- Assignee type: Filter by assignee type to show only individual users or only Microsoft Entra security groups.
To clear all active filters, select Reset all.
You can sort the list by any column by selecting the column header.
Assign a role
- In the Management section of the navigation pane, select Roles.
- Select the User roles or Admin roles tab.
- Select the role you want to assign.
- Select Add assignments.
- In the Search Microsoft Entra dropdown list, search for the user or Microsoft Entra security group you want to assign the role to.
- In the Scope section, select one of the following options:
- All environments: The assignment applies to all environments in your tenant.
- Select environments: Select one or more environments from the list.
- Select Save.
Remove a role assignment
- In the Management section of the navigation pane, select Roles.
- Select the User roles or Admin roles tab.
- Select the role you want to remove from a user or group.
- Select the checkbox next to the assignment you want to remove.
- Select Remove assignments.