← All Roles

Exchange Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration
Assignment Modeallowed
Built-inYes
Template ID29232cdf-9323-42fd-ade2-1d097af3e4de

Description

Can manage all aspects of the Exchange product.

Details

Users with this role have global permissions within Microsoft Exchange Online, when the service is present.

Directory Actions25

  • microsoft.azure.serviceHealth/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.backup/exchangeProtectionPolicies/allProperties/allTasks
  • microsoft.backup/exchangeRestoreSessions/allProperties/allTasks
  • microsoft.backup/restorePoints/userMailboxes/allProperties/allTasks
  • microsoft.backup/userMailboxProtectionUnits/allProperties/allTasks
  • microsoft.backup/userMailboxRestoreArtifacts/allProperties/allTasks
  • microsoft.directory/contacts/allProperties/read
  • microsoft.directory/contacts/memberOf/read
  • microsoft.directory/contacts/standard/read
  • microsoft.directory/groups/hiddenMembers/read
  • microsoft.directory/groups.unified/assignedLabels/update
  • microsoft.directory/groups.unified/basic/update
  • microsoft.directory/groups.unified/create
  • microsoft.directory/groups.unified/delete
  • microsoft.directory/groups.unified/members/update
  • microsoft.directory/groups.unified/owners/update
  • microsoft.directory/groups.unified/restore
  • microsoft.directory/onPremisesSynchronization/standard/read
  • microsoft.office365.exchange/allEntities/basic/allTasks
  • microsoft.office365.network/performance/allProperties/read
  • microsoft.office365.serviceHealth/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.office365.usageReports/allEntities/allProperties/read
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions37

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • BackupRestore-Monitor.Read.All
  • BackupRestore-Restore.Read.All
  • Calendars.Read
  • Calendars.ReadWrite
  • ChangeManagement.Read.All
  • Contacts.Read
  • Contacts.ReadWrite
  • Directory.Read.All
  • EntraBackup.Read.All
  • EntraBackup.ReadWrite.Preview
  • EntraBackup.ReadWrite.Recovery
  • ExchangeMessageTrace.Read.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • GroupSettings.Read.All
  • Mail.Read
  • Mail.ReadWrite
  • MailboxSettings.Read
  • MailboxSettings.ReadWrite
  • NetworkAccess-Reports.Read.All
  • OnPremDirectorySynchronization.Read.All
  • OrgContact.Read.All
  • Place.Read.All
  • Place.ReadWrite.All
  • Reports.Read.All
  • ReportSettings.Read.All
  • RoleManagement.Read.Exchange
  • RoleManagement.ReadWrite.Exchange
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write