Groups Administrator
Attack path
Groups Administrator can change the membership of standard security and Microsoft 365 groups. If an ordinary group has been assigned an Azure RBAC role, used as a Conditional Access exclusion, or trusted by a sensitive application, an attacker could add a controlled identity and inherit that access. Role-assignable groups are protected, but groups carrying Azure or application permissions are not necessarily marked that way, so poor group design can turn this role into a route to subscription ownership, protected data or weaker sign-in controls.
Description
Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.
Details
Members of this role can create and manage groups, create and manage group settings like naming and expiration policies, and view groups activity and audit reports. It is important to understand that assigning a user to this role gives them the ability to manage all the groups in the tenants across various workloads like Teams, SharePoint, and Yammer in addition to Outlook. Also, the user will be able to manage the various group settings across various admin portals like Microsoft Admin Center and the Azure Portal, as well as workload specific ones like Teams and SharePoint admin centers.
Directory Actions26
| Action | Condition |
|---|---|
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.directory/bulkJobs.groups/basic/update | null |
microsoft.directory/bulkJobs.groups/create | null |
microsoft.directory/bulkJobs.groups/standard/read | null |
microsoft.directory/deletedItems.groups/delete | null |
microsoft.directory/deletedItems.groups/restore | null |
microsoft.directory/groups/assignedLabels/update | null |
microsoft.directory/groups/assignLicense | null |
microsoft.directory/groups/basic/update | null |
microsoft.directory/groups/classification/update | null |
microsoft.directory/groups/create | null |
microsoft.directory/groups/delete | null |
microsoft.directory/groups/dynamicMembershipRule/update | null |
microsoft.directory/groups/groupType/update | null |
microsoft.directory/groups/hiddenMembers/read | null |
microsoft.directory/groups/members/update | null |
microsoft.directory/groups/onPremWriteBack/update | null |
microsoft.directory/groups/owners/update | null |
microsoft.directory/groups/reprocessLicenseAssignment | null |
microsoft.directory/groups/restore | null |
microsoft.directory/groups/settings/update | null |
microsoft.directory/groups/visibility/update | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions15
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
ChangeManagement.Read.AllDirectory.Read.AllGroup.Read.AllGroup.ReadWrite.AllGroupMember.Read.AllGroupMember.ReadWrite.AllGroupSettings.Read.AllGroupSettings.ReadWrite.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.Write