About admin roles
Your subscription comes with a set of admin roles that you can assign to users in your organization. Each admin role maps to common business functions and gives people in your organization permissions to do specific tasks in the admin centers. For more information, see Assign admin roles
Things to consider...
Because admins have access to sensitive data and files, we recommend that you follow these guidelines to keep your organization's data more secure.
What's the least-permissive role?
The least permissive role means that you give a user only the access they need to do a task. Giving a user too many permissions can be a security risk.
For a list of the least permissive roles by task, see Least permissive role.
Need more details about what these roles can and cannot do?
In the Microsoft 365 admin center, go to Roles > Roles, and then select any role to open its detail pane. Select the Permissions tab to view the detailed list of what admins assigned that role have permission to do.
You can also view the brief descriptions later in this article: Roles available in the Microsoft 365 admin center.
If you don’t have access to the Microsoft 365 admin center, or if you’re looking for detailed information, including the cmdlets associated with a role, see Administrator role permissions in Azure Active Directory.
What about the Azure Active Directory roles?
The Azure portal has more roles than available in the Microsoft 365 admin center. If you have a large business, there might be roles in the Azure portal that meet your organizational needs.
For a list and description of all the Azure Active Directory roles, see Administrator role permissions in Azure Active Directory.
A user who is assigned an admin role will have the same level of access to cloud services that your organization has subscribed to, regardless of whether you assign the role in the Microsoft 365 admin center or the Azure portal, or by using the Azure AD module for Windows PowerShell.
Roles available in the Microsoft 365 admin center
The Microsoft 365 admin center lets you manage over 30 Azure AD roles. However, these roles are a subset of the roles available in the Azure portal.
You'll probably only need to assign the following roles in your organization.
All roles
Here's a list of all the roles available in the Microsoft 365 admin center.
No comments:
Post a Comment