Role Required To create and manage Security Profiles you need to be assigned to the Application Administrator or Records Manager role.
Security Profiles only apply to users with the Records Visitor role in Azure Active directory. Adding a User to a Security Profile does not automatically give the user access to Records365. For more information about assigning roles see User Roles and Permissions. Any user with the Record Manager or Application Manager Azure AD Role will ignore the permissions defined in a Security Profile.
Security Profiles are used to give users with the Records Visitor role elevated privileges to view additional pages or perform additional actions in Records365.
User’s with the Record Visitor role by default are only able to view the Record Browse and Advanced Search pages and are not able to perform any actions within Records365. By placing these users in a Security Profile it is possible to give them access to additional pages and the ability to perform certain actions.
A Security Profile can have either Users or Groups from your Azure Active Directory (AAD) added to it. When adding an AAD group all direct members of the group will be assigned the privileges granted by the Security Profile. Nested AAD group (groups within groups) members will not be given additional privileges. Users can be assigned to multiple Security Profiles. Security profiles always grant additional access so a combination of all the users Security Profiles is applied.
A user’s UPN is typically their email address. Please contact your organizations Identity Administrator to find out what the UPN is for a given User. To obtain the Group ID you can find more details here.