Forum Discussion
Adding Admin permissions to every SPO and Teams sites that gets created?
Dean,
That looks interesting. Thanks for the link.
Do you know if it would work the same for Teams creation? I know that each new team creates a new group, but I wasn't sure if that flow would work the same for creating a new team and linking it to the new group.
Thanks.
Ted
When you create a new Team, you have the choice of connecting to an existing Group or getting a new Group. If you have limited who can create new Groups, that effectively limits who can create new Teams also.
- May 21, 2018
I really wouldn't want my admins to have standing access to every Team, Group or Site. They should either ask an owner to invite them, or if that's not possible grant themselves access using their admin rights, then after they've finished they should leave the team. Imagine how dangerous their Delve would be with access to everything all the time!
If you really must you can automate this by applying a site design to the default teamsite template, then in the design trigger a flow to make your changes.
- Dean_GrossMay 21, 2018Silver Contributor
I agree with you, this is another great example of just because it can be done, does not mean that it should be done.
A much more secure approach is to use Azure AD Privileged Identity Management to provide just in time admin functionality that is auditable and time limited. https://docs.microsoft.com/en-us/azure/active-directory/active-directory-privileged-identity-management-configure- Ted McLaughlinMay 23, 2018Brass Contributor
After reading through the whole page on PIM I still can't see how that would enable me to get into some Teams Site. How does PIM do anything that Global Admin doesn't?
What's aggravating about this is that my Admin account is domain admin, farm admin, (for 8 production SP farms including our ecommerce farm), global backup admin, (meaning I really can see everything), exchange admin, has full control on our Payroll, Board of Directors sites, plus our Mergers & Acquisition's sites, (where all the seriously confidential stuff is stored). But I can't help Suzy at the factory the next state over because Bill was the one who stood up the team she is on, and he is out of the office today and no one else can give me access.
Grrrrrr.. Is this progress?
Ted