Microsoft 365 Admin Roles Overview
Microsoft 365
admin roles
permissions
admin center
security
By Kerry · Updated 03/05/26 07:09 AM
Microsoft 365 uses role-based access control to limit what admins can do. Rather than making everyone a Global Administrator, assign the least-privileged role needed for each function.
Common roles: Global Administrator (full access — limit to 2–4 people), User Administrator (create/manage users and groups), Exchange Administrator (manage mailboxes and mail flow), Teams Administrator (manage Teams settings), Billing Administrator (manage subscriptions and billing), Security Administrator (manage security policies and alerts).
To assign roles, go to admin.microsoft.com > Users > Active users, click a user, then select Manage roles from their profile. Choose the appropriate role and save. For higher-risk actions, consider using Privileged Identity Management (PIM) in Azure AD so that admin roles are only activated on-demand with approval and time limits.