How to configure role expiration in Purview
- Maxime Hiez
- Purview , Tutorial
- 10 Aug, 2026
Introduction
In most tenants, Microsoft Purview permissions pile up. An external auditor is granted eDiscovery access for three weeks, a consultant gets the Compliance Administrator role for the duration of a project, and nobody removes the assignment afterwards. Purview now allows an expiration date to be attached to a role group assignment : at the deadline, the assignment is removed automatically and access is revoked without any intervention.
Prerequisites
Required licenses
- Microsoft 365 (all editions).
Administrator role
- An account with the Global Administrator or Role Management role to access the Microsoft Purview Portal.
Step 1 : Sign in to the Microsoft Purview Portal
Sign in to the Microsoft Purview Portal by opening your web browser to https://purview.microsoft.com.
Step 2 : Access the role groups
In the left menu, click Settings, then Roles and scopes, and Role groups.
Select the role group to modify, then click Edit.

Step 3 : Assign the group
Click Add member, and Choose groups (or Choose users) to add the relevant groups (or accounts).

Step 4 : Set an expiration date
Select the added group or groups, and click Edit expiration to set the deadline. The duration can range from a minimum of one day to a maximum of two years from the current date.

info
Step 5 : Update, extend or remove an expiration
An expiration is not set in stone. From the same Edit expiration screen, three actions are possible :
- Update the deadline : Bring forward or push back the date of an existing assignment.
- Extend the assignment : Push back the deadline before it is reached.
- Remove the expiration : Make the assignment permanent.
The My Permissions page lets the user check the latest expiration date among their active assignments.
What to check before rolling it out broadly
Several behaviors are worth knowing before applying the principle to all role groups :
- Two exceptions : All built-in and custom role groups accept an expiration, except eDiscovery Administrator and eDiscovery Manager.
- No notification : Neither the user nor the administrator receives an alert before the deadline. The loss of access is silent.
- Independent assignments : If a user gets the same role group through an individual assignment and through a security group, each assignment keeps its own deadline. Access remains active as long as one of the two is valid.
- Inheritance through a security group : When a role group is assigned to a security group, any new member inherits the deadline attached to that assignment.
- Ongoing actions preserved : At expiration, operations already completed or in progress are not affected, only new operations are refused.
The most structuring point is the absence of notification. A temporary assignment placed on a genuinely operational role, for example a DLP administrator in the middle of a deployment campaign, can interrupt a project without warning. The counterpart of this automation is therefore a need for follow-up on the organization side, with a schedule of deadlines maintained outside Purview.
Conclusion
You now know how to configure, extend and remove an expiration date on role group assignments in Microsoft Purview.
Sources
Microsoft Learn - Permissions in the Microsoft Purview portal
Did you enjoy this post ? If you have any questions, comments or suggestions, please feel free to send me a message from the contact form.
Don’t forget to follow us and share this post.