Role Required for M365 Management

100 views
Skip to first unread message

Charles F Sullivan

unread,
Sep 11, 2023, 12:39:37 PM9/11/23
to ntsys...@googlegroups.com
For someone to fully manage M365, it appears that the Global Admin Azure AD role is required. Am I correct, or is there a way to get more granular? Is more information needed for an answer?  

--

Charlie Sullivan

Principal Windows Systems Administrator

Orlebeck, Geoffrey

unread,
Sep 11, 2023, 12:51:26 PM9/11/23
to ntsys...@googlegroups.com

I think that depends on how you define “fully manage”. There are areas of M365 where the Global Admin role does not have permissions, though GA would let you assign the relevant role(s) that can access those areas.

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CAEuHzznz5EB%2BxEyWrsq%2Beitquf5X-6j15t98i6G1MpU8%3DaTCLw%40mail.gmail.com.

Confidentiality Notice: This is a transmission from Montage Health. This message and any attached documents may be confidential and contain information protected by state and federal medical privacy statutes. They are intended only for the use of the addressee. If you are not the intended recipient, any disclosure, copying, or distribution of this information is strictly prohibited. If you received this transmission in error, please accept our apologies and notify the sender. Thank you.

Charles F Sullivan

unread,
Sep 11, 2023, 3:13:34 PM9/11/23
to ntsys...@googlegroups.com
My concern is more like the reverse of that. We are hoping there are more granular ways to give a small number of users the ability to manage M365. 

Management is hoping to remove these users from the Global Admin role. So far from what I'm reading they would need that role, but I'm hoping someone here can confirm.

Michael B. Smith

unread,
Sep 11, 2023, 3:15:08 PM9/11/23
to ntsys...@googlegroups.com

To the best of my knowledge, EVERYTHING can be delegated.

 

What specific activity(ies) lead you to believe otherwise?

Charles F Sullivan

unread,
Sep 11, 2023, 4:02:36 PM9/11/23
to ntsys...@googlegroups.com
This is an example of the kind of thing I keep coming up with:
“Assign the Global admin role to users who need global access to most management features and data across Microsoft online services.”

Michael B. Smith

unread,
Sep 11, 2023, 4:05:41 PM9/11/23
to ntsys...@googlegroups.com

That’s exactly like writing “if you are lazy and don’t want to chase down specific required permissions, assign domain admin to users who need global access to most AD and on-prem services”.

 

There are other ways.  😊

 

That’s why I asked if you had a specific activities you had not been able to delegate.

 

Thanks.

Randy Hollenbeck

unread,
Sep 11, 2023, 4:10:42 PM9/11/23
to ntsys...@googlegroups.com
Not using Global Admin to administer M365.  They will not be able to make site wide (global) changes

Roles needed:

Authentication Administrator
Exchange Administrator
License Administrator
SharePoint Administrator
Teams Administrator
User Administrator

Need user and license to add licenses
Need Authentication Administrator to turn on and off MFA (will not be able to turn on/off any admin including themseleves)

If you want to configure MFA for non-admin users, only use Authentication Administrator role and if you want to configure MFA for all users including admin users, use Privileged Authentication Administrator role.

To give additional access that are not listed, https://go.microsoft.com/fwlink/p/?linkid=2097861 

1. In the admin center, go to Roles -> Role assignments.  Choose the Azure AD, Exchange, Intune or Billing tab to view the admin roles available for your organization.

After adding verify by looking at the user and permissions by the Roles



Charles F Sullivan

unread,
Sep 11, 2023, 4:53:13 PM9/11/23
to ntsys...@googlegroups.com
Randy, I think that's exactly what I was looking for. We won't be using Teams, SharePoint or Exchange, so I should be able to put those aside. Much appreciated!

Michael, I agree with your point. That's why I didn't want to just assume there wasn't a better way.

Reply all
Reply to author
Forward
0 new messages