← All Roles

Exchange Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration
Assignment Modeallowed
Built-inYes
Template ID29232cdf-9323-42fd-ade2-1d097af3e4de

Attack path

An Exchange Administrator controls mailboxes, transport settings and much of Exchange Online. An attacker could create inbox or mail-flow rules that copy password-reset messages, enrolment links and other sensitive correspondence to a mailbox they control, using the captured information to compromise additional identities. They could also search or export business data and abuse access to Microsoft 365 group resources where permitted. This role does not directly grant full Entra control, but email's role in account recovery makes it a strong route to lateral movement.

Description

Can manage all aspects of the Exchange product.

Details

Users with this role have global permissions within Microsoft Exchange Online, when the service is present.

Directory Actions25

ActionCondition
microsoft.azure.serviceHealth/allEntities/allTasksnull
microsoft.azure.supportTickets/allEntities/allTasksnull
microsoft.backup/exchangeProtectionPolicies/allProperties/allTasksnull
microsoft.backup/exchangeRestoreSessions/allProperties/allTasksnull
microsoft.backup/restorePoints/userMailboxes/allProperties/allTasksnull
microsoft.backup/userMailboxProtectionUnits/allProperties/allTasksnull
microsoft.backup/userMailboxRestoreArtifacts/allProperties/allTasksnull
microsoft.directory/contacts/allProperties/readnull
microsoft.directory/contacts/memberOf/readnull
microsoft.directory/contacts/standard/readnull
microsoft.directory/groups/hiddenMembers/readnull
microsoft.directory/groups.unified/assignedLabels/updatenull
microsoft.directory/groups.unified/basic/updatenull
microsoft.directory/groups.unified/createnull
microsoft.directory/groups.unified/deletenull
microsoft.directory/groups.unified/members/updatenull
microsoft.directory/groups.unified/owners/updatenull
microsoft.directory/groups.unified/restorenull
microsoft.directory/onPremisesSynchronization/standard/readnull
microsoft.office365.exchange/allEntities/basic/allTasksnull
microsoft.office365.network/performance/allProperties/readnull
microsoft.office365.serviceHealth/allEntities/allTasksnull
microsoft.office365.supportTickets/allEntities/allTasksnull
microsoft.office365.usageReports/allEntities/allProperties/readnull
microsoft.office365.webPortal/allEntities/standard/readnull

Graph API Permissions37

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • BackupRestore-Monitor.Read.All
  • BackupRestore-Restore.Read.All
  • Calendars.Read
  • Calendars.ReadWrite
  • ChangeManagement.Read.All
  • Contacts.Read
  • Contacts.ReadWrite
  • Directory.Read.All
  • EntraBackup.Read.All
  • EntraBackup.ReadWrite.Preview
  • EntraBackup.ReadWrite.Recovery
  • ExchangeMessageTrace.Read.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • GroupSettings.Read.All
  • Mail.Read
  • Mail.ReadWrite
  • MailboxSettings.Read
  • MailboxSettings.ReadWrite
  • NetworkAccess-Reports.Read.All
  • OnPremDirectorySynchronization.Read.All
  • OrgContact.Read.All
  • Place.Read.All
  • Place.ReadWrite.All
  • Reports.Read.All
  • ReportSettings.Read.All
  • RoleManagement.Read.Exchange
  • RoleManagement.ReadWrite.Exchange
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write