SharePoint Advanced Management Administrator
Enabled
Description
Manage all aspects of SharePoint Advanced Management.
Details
Assign the SharePoint Advanced Management Administrator role to users who need to do the following tasks:
- Perform all actions available to SharePoint Administrators, including global management of SharePoint Online, support ticket handling, and service health monitoring
- View names, paths, and URLs of files, folders, libraries, documents, and lists within SharePoint sites, without accessing file or item content
- Remove permissions from files, folders, libraries, documents, and lists within SharePoint sites
Directory Actions28
| Action | Condition |
|---|---|
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.backup/oneDriveForBusinessProtectionPolicies/allProperties/allTasks | null |
microsoft.backup/oneDriveForBusinessRestoreSessions/allProperties/allTasks | null |
microsoft.backup/restorePoints/sites/allProperties/allTasks | null |
microsoft.backup/restorePoints/userDrives/allProperties/allTasks | null |
microsoft.backup/sharePointProtectionPolicies/allProperties/allTasks | null |
microsoft.backup/sharePointRestoreSessions/allProperties/allTasks | null |
microsoft.backup/siteProtectionUnits/allProperties/allTasks | null |
microsoft.backup/siteRestoreArtifacts/allProperties/allTasks | null |
microsoft.backup/userDriveProtectionUnits/allProperties/allTasks | null |
microsoft.backup/userDriveRestoreArtifacts/allProperties/allTasks | null |
microsoft.directory/groups/hiddenMembers/read | null |
microsoft.directory/groups.unified/assignedLabels/update | null |
microsoft.directory/groups.unified/basic/update | null |
microsoft.directory/groups.unified/create | null |
microsoft.directory/groups.unified/delete | null |
microsoft.directory/groups.unified/members/update | null |
microsoft.directory/groups.unified/owners/update | null |
microsoft.directory/groups.unified/restore | null |
microsoft.office365.migrations/allEntities/allProperties/allTasks | null |
microsoft.office365.network/performance/allProperties/read | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.sharePointAdvancedManagement/allEntities/allProperties/allTasks | null |
microsoft.office365.sharePoint/allEntities/allTasks | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.usageReports/allEntities/allProperties/read | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions33
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
BackupRestore-Monitor.Read.AllBackupRestore-Restore.Read.AllChangeManagement.Read.AllDirectory.Read.AllEntraBackup.Read.AllEntraBackup.ReadWrite.PreviewEntraBackup.ReadWrite.RecoveryFiles.Read.AllFiles.ReadWrite.AllGroup.Read.AllGroup.ReadWrite.AllGroupMember.Read.AllGroupMember.ReadWrite.AllGroupSettings.Read.AllNetworkAccess-Reports.Read.AllReports.Read.AllReportSettings.Read.AllServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.WriteSharePointCrossTenantMigration.Manage.AllSharePointTenantSettings.Read.AllSharePointTenantSettings.ReadWrite.AllSites.FullControl.AllSites.Manage.AllSites.Read.AllSites.ReadWrite.AllTermStore.Read.AllTermStore.ReadWrite.All