Forum Discussion
Gabriela690
Jan 25, 2022Copper Contributor
Manage M365 Groups without access
For security concerns, I would like to find a way a user could manage M365 groups (add/remove users) without being owner/member of that group. I don't want this user to have acccess to the information (mostly financial) available within the group. Groups admin role is excluded.
Any idea if that would be possible?
1 Reply
- Users with certain admin permission can manage groups/teams without them being an owner, or without the need to grant the Groups admin role. The question however is which actions do you need to perform. If only adding/removing users, you can grant them the "Mail Recipients" Exchange Online role, or even create a custom role which only allows access to the corresponding Add-UnifiedGroupLinks/Remove-UnifiedGroupLinks cmdlets. If you do need to manage other aspects of a group however, this might not be an appropriate solution as other workloads don't offer such granular controls.