← All Roles

Groups Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration,identity
Assignment Modeallowed
Built-inYes
Template IDfdd7a751-b60b-444a-984c-02652fe8fa1c

Description

Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.

Details

Members of this role can create and manage groups, create and manage group settings like naming and expiration policies, and view groups activity and audit reports. It is important to understand that assigning a user to this role gives them the ability to manage all the groups in the tenants across various workloads like Teams, SharePoint, and Yammer in addition to Outlook. Also, the user will be able to manage the various group settings across various admin portals like Microsoft Admin Center and the Azure Portal, as well as workload specific ones like Teams and SharePoint admin centers.

Directory Actions26

  • microsoft.azure.serviceHealth/allEntities/allTasks
  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.directory/bulkJobs.groups/basic/update
  • microsoft.directory/bulkJobs.groups/create
  • microsoft.directory/bulkJobs.groups/standard/read
  • microsoft.directory/deletedItems.groups/delete
  • microsoft.directory/deletedItems.groups/restore
  • microsoft.directory/groups/assignedLabels/update
  • microsoft.directory/groups/assignLicense
  • microsoft.directory/groups/basic/update
  • microsoft.directory/groups/classification/update
  • microsoft.directory/groups/create
  • microsoft.directory/groups/delete
  • microsoft.directory/groups/dynamicMembershipRule/update
  • microsoft.directory/groups/groupType/update
  • microsoft.directory/groups/hiddenMembers/read
  • microsoft.directory/groups/members/update
  • microsoft.directory/groups/onPremWriteBack/update
  • microsoft.directory/groups/owners/update
  • microsoft.directory/groups/reprocessLicenseAssignment
  • microsoft.directory/groups/restore
  • microsoft.directory/groups/settings/update
  • microsoft.directory/groups/visibility/update
  • microsoft.office365.serviceHealth/allEntities/allTasks
  • microsoft.office365.supportTickets/allEntities/allTasks
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions15

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • ChangeManagement.Read.All
  • Directory.Read.All
  • Group.Read.All
  • Group.ReadWrite.All
  • GroupMember.Read.All
  • GroupMember.ReadWrite.All
  • GroupSettings.Read.All
  • GroupSettings.ReadWrite.All
  • ServiceActivity-Exchange.Read.All
  • ServiceActivity-Microsoft365Web.Read.All
  • ServiceActivity-OneDrive.Read.All
  • ServiceActivity-Teams.Read.All
  • ServiceHealth.Read.All
  • ServiceMessage.Read.All
  • ServiceMessageViewpoint.Write