← All Roles

Teams External Collaboration Administrator

Enabled
Versionv1
Date Added2026-06-21
Categorycollaboration
Assignment Modeallowed
Built-inYes
Template ID2fe872fb-daa8-4afc-8f6c-53c4565cfef4

Description

Manage external collaboration policies and settings for Teams, including configuring external domains and controlling which groups and users can interact with the organization.

Details

  • Manage Teams external collaboration settings that govern the organization's interactions with external users in chats, meetings, and calls.
  • Configure external domains, including creating, editing, and deleting domain entries that specify how users engage with external organizations.
  • Establish and manage allowlist and blocklist policies for external collaboration at both the user and group levels.
  • Control which external domains and users can collaborate with the organization for secure and compliant external collaboration.

Directory Actions4

  • microsoft.azure.supportTickets/allEntities/allTasks
  • microsoft.directory/authorizationPolicy/standard/read
  • microsoft.office365.webPortal/allEntities/standard/read
  • microsoft.teams/policies/externalAccessPolicy/allTasks

Graph API Permissions35

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • Bookings.Manage.All
  • Bookings.Read.All
  • Bookings.ReadWrite.All
  • BookingsAppointment.ReadWrite.All
  • Channel.Create
  • Channel.Delete.All
  • Channel.ReadBasic.All
  • ChannelMember.Read.All
  • ChannelMember.ReadWrite.All
  • ChannelMessage.Read.All
  • ChannelSettings.Read.All
  • ChannelSettings.ReadWrite.All
  • Directory.Read.All
  • Policy.Read.All
  • RoleManagement.Read.CloudPC
  • Schedule.Read.All
  • Schedule.ReadWrite.All
  • SchedulePermissions.ReadWrite.All
  • Team.Create
  • Team.ReadBasic.All
  • TeamMember.Read.All
  • TeamMember.ReadWrite.All
  • TeamsActivity.Read
  • TeamsActivity.Send
  • TeamsAppInstallation.ReadWriteAndConsentForTeam
  • TeamSettings.Read.All
  • TeamSettings.ReadWrite.All
  • TeamsPolicyUserAssign.ReadWrite.All
  • TeamsResourceAccount.Read.All
  • TeamsTab.Create
  • TeamsTab.Read.All
  • TeamsTab.ReadWrite.All
  • TeamsTelephoneNumber.Read.All
  • TeamsTelephoneNumber.ReadWrite.All
  • TeamsUserConfiguration.Read.All