It does not include network connections from Microsoft into a customer network, sometimes called hybrid or inbound network connections | Teams service admins can also: - Manage meetings - Manage conference bridges - Manage all org-wide settings, including federation, teams upgrade, and teams client settings User admin Assign the User admin role to users who need to do the following for all users: - Add users and groups - Assign licenses - Manage most users properties - Create and manage user views - Update password expiration policies - Manage service requests - Monitor service health The user admin can also do the following actions for users who aren't admins and for users assigned the following roles: Directory reader, Guest inviter, Helpdesk admin, Message center reader, Reports reader: - Manage usernames - Delete and restore users - Reset passwords - Force users to sign out - Update FIDO device keys Delegated administration for Microsoft Partners If you're working with a Microsoft partner, you can assign them admin roles |
---|---|
This allows for customers who do not yet have automated updates to complete their processes before new connectivity is required | Related content article article article article |
Check out Administrator role permissions in Azure Active Directory.
24Endpoint data below lists requirements for connectivity from a user's machine to Office 365 | But the global admin has almost unlimited access to your org's settings and most of the data, so we also recommend that you don't have more than 4 global admins because that's a security threat |
---|---|
For example, if you want someone to reset employee passwords you shouldn't assign the unlimited global admin role, you should assign a limited admin role, like Password admin or Helpdesk admin | If you get a message in the admin center telling you that you don't have permissions to edit a setting or page, it's because you are assigned a role that doesn't have that permission |
The global reader admin can't edit any settings.