Use Dynamic Data Masking access control to define the operations that a user can perform on Management Console tree nodes and Dynamic Data Masking configuration.
You can set permissions on domain, database, and security rule set nodes to define the users that can edit the nodes.
A Dynamic Data Masking user can be a privileged user or a non-privileged user. The type of user and type of permissions the user has on a node in the Management Console tree determines whether the user can view or make changes to the node.