Groups Administrator
Description
Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.
Details
Members of this role can create and manage groups, create and manage group settings like naming and expiration policies, and view groups activity and audit reports. It is important to understand that assigning a user to this role gives them the ability to manage all the groups in the tenants across various workloads like Teams, SharePoint, and Yammer in addition to Outlook. Also, the user will be able to manage the various group settings across various admin portals like Microsoft Admin Center and the Azure Portal, as well as workload specific ones like Teams and SharePoint admin centers.
Directory Actions26
microsoft.azure.serviceHealth/allEntities/allTasksmicrosoft.azure.supportTickets/allEntities/allTasksmicrosoft.directory/bulkJobs.groups/basic/updatemicrosoft.directory/bulkJobs.groups/createmicrosoft.directory/bulkJobs.groups/standard/readmicrosoft.directory/deletedItems.groups/deletemicrosoft.directory/deletedItems.groups/restoremicrosoft.directory/groups/assignedLabels/updatemicrosoft.directory/groups/assignLicensemicrosoft.directory/groups/basic/updatemicrosoft.directory/groups/classification/updatemicrosoft.directory/groups/createmicrosoft.directory/groups/deletemicrosoft.directory/groups/dynamicMembershipRule/updatemicrosoft.directory/groups/groupType/updatemicrosoft.directory/groups/hiddenMembers/readmicrosoft.directory/groups/members/updatemicrosoft.directory/groups/onPremWriteBack/updatemicrosoft.directory/groups/owners/updatemicrosoft.directory/groups/reprocessLicenseAssignmentmicrosoft.directory/groups/restoremicrosoft.directory/groups/settings/updatemicrosoft.directory/groups/visibility/updatemicrosoft.office365.serviceHealth/allEntities/allTasksmicrosoft.office365.supportTickets/allEntities/allTasksmicrosoft.office365.webPortal/allEntities/standard/read
Graph API Permissions15
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
ChangeManagement.Read.AllDirectory.Read.AllGroup.Read.AllGroup.ReadWrite.AllGroupMember.Read.AllGroupMember.ReadWrite.AllGroupSettings.Read.AllGroupSettings.ReadWrite.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.Write