← All Roles

Groups Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration,identity
Assignment Modeallowed
Built-inYes
Template IDfdd7a751-b60b-444a-984c-02652fe8fa1c

Attack path

Groups Administrator can change the membership of standard security and Microsoft 365 groups. If an ordinary group has been assigned an Azure RBAC role, used as a Conditional Access exclusion, or trusted by a sensitive application, an attacker could add a controlled identity and inherit that access. Role-assignable groups are protected, but groups carrying Azure or application permissions are not necessarily marked that way, so poor group design can turn this role into a route to subscription ownership, protected data or weaker sign-in controls.

Description

Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.

Details

Members of this role can create and manage groups, create and manage group settings like naming and expiration policies, and view groups activity and audit reports. It is important to understand that assigning a user to this role gives them the ability to manage all the groups in the tenants across various workloads like Teams, SharePoint, and Yammer in addition to Outlook. Also, the user will be able to manage the various group settings across various admin portals like Microsoft Admin Center and the Azure Portal, as well as workload specific ones like Teams and SharePoint admin centers.

Directory Actions26

ActionCondition
microsoft.azure.serviceHealth/allEntities/allTasksnull
microsoft.azure.supportTickets/allEntities/allTasksnull
microsoft.directory/bulkJobs.groups/basic/updatenull
microsoft.directory/bulkJobs.groups/createnull
microsoft.directory/bulkJobs.groups/standard/readnull
microsoft.directory/deletedItems.groups/deletenull
microsoft.directory/deletedItems.groups/restorenull
microsoft.directory/groups/assignedLabels/updatenull
microsoft.directory/groups/assignLicensenull
microsoft.directory/groups/basic/updatenull
microsoft.directory/groups/classification/updatenull
microsoft.directory/groups/createnull
microsoft.directory/groups/deletenull
microsoft.directory/groups/dynamicMembershipRule/updatenull
microsoft.directory/groups/groupType/updatenull
microsoft.directory/groups/hiddenMembers/readnull
microsoft.directory/groups/members/updatenull
microsoft.directory/groups/onPremWriteBack/updatenull
microsoft.directory/groups/owners/updatenull
microsoft.directory/groups/reprocessLicenseAssignmentnull
microsoft.directory/groups/restorenull
microsoft.directory/groups/settings/updatenull
microsoft.directory/groups/visibility/updatenull
microsoft.office365.serviceHealth/allEntities/allTasksnull
microsoft.office365.supportTickets/allEntities/allTasksnull
microsoft.office365.webPortal/allEntities/standard/readnull

Graph API Permissions15

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • ChangeManagement.Read.All
  • Directory.Read.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • GroupSettings.Read.All
  • GroupSettings.ReadWrite.All
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write