Skip to main content
Microsoft 365 uses Entra ID, Intune, Conditional Access, and Purview to secure identities, devices, and data. As you implement these controls, you must decide who can manage them. This article explains how Microsoft 365 organizes administrative permissions using role-based access control (RBAC), how to enable group-based role assignments, and how workload-specific admin centers (for example, Exchange) implement role groups. What is RBAC?
  • RBAC is a security model that grants permissions through roles rather than assigning permissions directly to individual users.
  • Administrators are placed into role groups; role groups contain one or more roles; and group members inherit the permissions defined by those roles.
A diagram titled "Assigning Admin Roles Using Role-Based Access Control" showing individual administrators, role groups, and role icons with arrows illustrating how roles are added to groups and applied to members. The right side lists brief definitions for Role, Role Group, and Assignment.
Role example
  • Think of a role as a named collection of permissions. One role might allow password resets; another might allow Teams configuration. Assigning a role to a role group lets you grant a bundle of permissions to all group members at once, which simplifies administration and supports least-privilege access.
Key RBAC concepts Where to manage roles
  • The Microsoft 365 admin center provides a tenant-wide view of many built-in roles (for example, Global Administrator) and role assignments.
  • Workload-specific admin centers (Exchange, Teams, SharePoint) provide role definitions and role groups scoped to those services.
Create and enable a security group for role-based assignments
  1. In the Microsoft 365 admin portal, go to Teams & groups → Active teams & groups.
  2. Choose the group type. Common types:
  3. When creating a security group, you can enable the option to allow Azure AD roles to be assigned to the group. This setting is required if you want to use the group for role-based assignments.
When you enable the option to assign Azure AD roles to a security group, that choice is permanent for the group. If you do not enable it at creation, the group cannot be used for role assignments later.
Example: Assign roles to a group
  • Create a security group named AB-900 role group and enable role assignment support.
  • In the Microsoft 365 admin center navigate to Roles → Role assignments.
  • Select a built-in role (for example, AI Administrator) to view role details, included permissions, and current assignments.
  • Choose Assign roles, add the AB-900 role group, and save. Repeat to add other roles such as Exchange Administrator.
  • Any user added to AB-900 role group now inherits all assigned roles.
Nesting groups and scope
  • You can often nest groups (add groups into groups) to reflect organizational structure. Support and membership evaluation for nested groups varies across admin centers and features—test nested membership behavior for specific roles and services before relying on it in production.
Exchange admin center: role groups and workflow
  • The Exchange admin center exposes Exchange-specific role groups tailored for mail and recipient management. When creating an Exchange role group you select a name, description, write scope, specific Exchange roles (for example, Address Lists, Mail Recipient Creation), and members.
A screenshot of the Microsoft Exchange admin center showing the "Add role group" workflow with a "Set up the basics" form. The page displays fields for the role group's Name, Description, and Write scope.
  • The Exchange role-group creation workflow guides you through: Basics → Permission → Admins → Review and finish.
Screenshot of the Exchange admin center showing the "Assign admins" page with a search box to add members to a role group. The left pane shows the setup steps (Basics, Permission, Admins, Review and finish) and there are Back/Next buttons at the bottom.
Tenant vs. workload roles
  • Roles available in the Microsoft 365 admin center are often tenant-level and span services, while workload admin centers expose roles scoped to service-specific responsibilities. For example, Exchange role groups are tightly focused on mail and recipient tasks; Microsoft 365 tenant roles may include broader privileges.
A screenshot of the Microsoft 365 admin center open to the "Role assignments" page, showing a list of built-in admin roles (with "Exchange Administrator" selected) and brief role descriptions. The left navigation menu and top search bar are also visible.
Best practices and key takeaways
  • Understand the difference between:
    • Role = collection of permissions
    • Role group = collection of roles for centralized assignment
    • Assignment = users/groups added to role groups
  • Use group-based role assignments to centralize management and enforce least privilege.
  • Always review the role definition and permission scope before assigning it.
  • Enable a security group for Azure AD role assignment at creation time if you plan to use it for RBAC.
  • Test nested group behavior for your target admin center and roles before broad adoption.
Use role groups to centralize administrative permissions and keep assignments consistent. Always review role permissions and scope before assigning them to any group.
Links and references

Watch Video