SOLVED
Home

Can we create a custom Office 365 Admin Role

%3CLINGO-SUB%20id%3D%22lingo-sub-51902%22%20slang%3D%22en-US%22%3ECan%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51902%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20trying%20to%20provide%20someone%20access%20only%20to%20the%20service%20health%20dashboard%2C%20but%20the%20out%20of%20the%20box%20admin%20Roles%20does%20not%20seem%20to%20allow%20that%20without%20exposing%20other%20information%20(Billing%2C%20licenses...etc)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet-MsolRole%20does%20not%20seem%20to%20have%20the%20New-%20counter%20part%2C%20anyone%20knows%20if%20this%20can%20be%20done%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-51902%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%20Center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Administration%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-388776%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-388776%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F26168%22%20target%3D%22_blank%22%3E%40Marwan%20Al-Shami%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3Ca%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F26168%22%3E%40Marwan%20Al-Shami%3C%2Fa%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F60%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3E%40Juan%20Carlos%20Gonz%C3%A1lez%20Mart%C3%ADn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMarwan%2C%3C%2FP%3E%3CP%3EThough%20not%20directly%20related%20to%20your%20question%2C%20I%20have%20been%20able%20to%20create%20custom%20roles%20in%20Powershell%20using%20these%202%20Microsoft%20articles%20from%202015.%26nbsp%3B%20It%20may%20be%20possible%20to%20%22re-purpose%22%20the%20commands%20to%20accommodate%20your%20needs.%20Just%20be%20aware%20that%20extensive%20testing%20needs%20to%20be%20done%20due%20to%20users%20assigned%20to%20the%20new%20role%20having%20greater%20than%20the%20desired%20permissions.%3C%2FP%3E%3CP%3ENote.%20Some%20commands%20in%20the%20Contacts%20Delegation%20article%20do%20not%20work%20in%20the%20O365%20PS%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2015%2F05%2F27%2Fallow-users-to-manage-distribution-groups-without-creating-new-onesexchange-2013-redux%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2015%2F05%2F27%2Fallow-users-to-manage-distribution-groups-with...%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2013%2F08%2F07%2Fcreating-rbac-role-to-delegate-contact-management%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2013%2F08%2F07%2Fcreating-rbac-role-to-delegate-contact-managem...%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-307044%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-307044%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20also%20interested%20in%20the%20solution.%20Managing%20and%20granual%20premissions%20are%20basics.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EG.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303585%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303585%22%20slang%3D%22en-US%22%3E%3CP%3ENot%20even%20a%20whisper%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303477%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303477%22%20slang%3D%22en-US%22%3E%3CP%3EAll%2C%20has%20there%20been%20any%20reply%20from%20Microsoft%20on%20this%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-289695%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-289695%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20also%20been%20asking%20for%20this%20for%20quite%20some%20time%2C%20either%20by%20domain%20or%20by%20any%20other%20AAD%20attribute%20like%20Country%20or%20Department.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-204290%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-204290%22%20slang%3D%22en-US%22%3E%3CP%3EShould%20have%26nbsp%3B%20a%20method%20to%20assign%20every%20level%20of%20admin%20permission%20granularly.%26nbsp%3B%20For%20example%2C%20I%20would%20like%20to%20have%20our%20IT%20finance%20person%20able%20to%20assign%20Office%20365%20licenses%20to%20users%20which%20requires%20the%20%22User%20management%20administrator%22%20role%2C%20this%20however%20also%20allows%20her%20to%20add%2Fdelete%20accounts%20and%20add%2Fremove%20users%20from%20groups%2C%20definitely%20things%20I%20do%20not%20want%20her%20able%20to%20do!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-203499%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-203499%22%20slang%3D%22en-US%22%3EWe%20too%20are%20looking%20for%20the%20ability%20to%20create%20custom%20roles%20for%20reporting.%20While%20I%20want%20to%20provide%20some%20levels%20of%20access%2C%20the%20existing%20security%20roles%20provide%20far%20more%20(in%20some%20cases)%20than%20what%20I%20want%20to%20give.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-197160%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-197160%22%20slang%3D%22en-US%22%3E%3CP%3ECustom%20admin%20roles%20are%20critical.%20Is%20there%20a%20timeline%20on%20this%20as%20a%20feature%20release%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-194326%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-194326%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20the%20same%20issue%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20tenant%2C%20multiple%20domains.%20Need%20a%20way%20to%20split%20up%20Admin%20user%20permissions%2C%20so%20they%20are%20domain%20dependant.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-161153%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-161153%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYes%20we%20need%20customization%20for%20admin%20roles%20as%20well.%20it%20is%20very%20important%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51930%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51930%22%20slang%3D%22en-US%22%3ECorrect!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51923%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51923%22%20slang%3D%22en-US%22%3EThanks%20Juan%2C%3CBR%20%2F%3ESo%20as%20of%20now%2C%20custom%20roles%20are%20not%20a%20possibility%2C%20right%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51921%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51921%22%20slang%3D%22en-US%22%3EThe%20roles%20we%20currently%20have%20are%20fully%20described%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FAbout-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FAbout-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%3C%2FA%3E%20If%20those%20roles%20do%20not%20fit%20your%20requirements%2C%20then%20post%20in%20user%20voice%20your%20idea%20of%20this%20specific%20role%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51920%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51920%22%20slang%3D%22en-US%22%3E%3CP%3EUnfortunately%2C%20the%20Service%20administrator%20exposes%20much%20more%20than%20the%20Service%20health%20section%20(Billing%2C%20licenses%2C%20users%2C%20settings...etc)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20only%20need%20to%20provide%20access%20to%3A%3C%2FP%3E%3CP%3E1-%20Service%20Health%3C%2FP%3E%3CP%3E2-%20Message%20Center%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20nothing%20else.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51915%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51915%22%20slang%3D%22en-US%22%3EKamal%20is%20correct%2C%20Service%20Administrator%20role%20is%20intended%20to%20cover%20this%20scenario%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-51911%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20create%20a%20custom%20Office%20365%20Admin%20Role%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-51911%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20tick%20only%26nbsp%3B%3CSPAN%3EService%20administrator%2C%20that%20user%20should%20have%20access%20the%20rest.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ENavigate%20to%20%26nbsp%3B%26gt%3B%20Admin%20%26gt%3B%20users%20%26gt%3B%20Add%20user%20%26gt%3B%20Roles%20%26gt%3B%20Customised%20-%20from%20drop%20down%20select%26nbsp%3BService%20administrator.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ELet%20me%20know%20how%20you%20get%20on%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Marwan Al-Shami
New Contributor

We are trying to provide someone access only to the service health dashboard, but the out of the box admin Roles does not seem to allow that without exposing other information (Billing, licenses...etc)

 

Get-MsolRole does not seem to have the New- counter part, anyone knows if this can be done? 

16 Replies

Hi,

 

If you tick only Service administrator, that user should have access the rest.

 

Navigate to  > Admin > users > Add user > Roles > Customised - from drop down select Service administrator.

 

Let me know how you get on

Kamal is correct, Service Administrator role is intended to cover this scenario

Unfortunately, the Service administrator exposes much more than the Service health section (Billing, licenses, users, settings...etc)

 

We only need to provide access to:

1- Service Health

2- Message Center

 

And nothing else.

 

Thanks

The roles we currently have are fully described here: https://support.office.com/en-us/article/About-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b... If those roles do not fit your requirements, then post in user voice your idea of this specific role
Highlighted
Thanks Juan,
So as of now, custom roles are not a possibility, right?
Solution
Correct!

Hi there

 

Yes we need customization for admin roles as well. it is very important

We have the same issue

 

One tenant, multiple domains. Need a way to split up Admin user permissions, so they are domain dependant. 

Custom admin roles are critical. Is there a timeline on this as a feature release?

We too are looking for the ability to create custom roles for reporting. While I want to provide some levels of access, the existing security roles provide far more (in some cases) than what I want to give.

Should have  a method to assign every level of admin permission granularly.  For example, I would like to have our IT finance person able to assign Office 365 licenses to users which requires the "User management administrator" role, this however also allows her to add/delete accounts and add/remove users from groups, definitely things I do not want her able to do!

I've also been asking for this for quite some time, either by domain or by any other AAD attribute like Country or Department.

All, has there been any reply from Microsoft on this? 

Not even a whisper

Hello,

 

I am also interested in the solution. Managing and granual premissions are basics.

 

G.

@Marwan Al-Shami 

 

@Marwan Al-Shami

 

 

@Juan Carlos González Martín 

 

Marwan,

Though not directly related to your question, I have been able to create custom roles in Powershell using these 2 Microsoft articles from 2015.  It may be possible to "re-purpose" the commands to accommodate your needs. Just be aware that extensive testing needs to be done due to users assigned to the new role having greater than the desired permissions.

Note. Some commands in the Contacts Delegation article do not work in the O365 PS

 

https://blogs.technet.microsoft.com/rmilne/2015/05/27/allow-users-to-manage-distribution-groups-with...

 

https://blogs.technet.microsoft.com/rmilne/2013/08/07/creating-rbac-role-to-delegate-contact-managem...

 

 

Related Conversations
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
cntvertex in Discussions on
13 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
22 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
28 Replies
Edge insider Dev bypasses IE mode website list
HotCakeX in Enterprise on
4 Replies