Back
Office 365

More control over data access with workload-specific admin roles

Share on Facebook Share on Twitter Share on Linkedin Share via OneNote Share via Email Print

Your people and your data are your organization’s greatest assets. With Office 365, we continuously strive to provide you with more control over how your data is managed and accessed.

At Ignite in May, we announced the ability to assign workload-specific service administrator roles to your organization’s IT administrators for Exchange Online, SharePoint Online and Skype for Business Online. We’re pleased to announce that this capability is rolling out starting today.

The ability to assign workload-specific admin roles provides your organization more control over how your Office 365 administrators access your data. An admin assigned to a workload-specific admin role would only have access to the relevant controls and settings associated with that workload. For example, the SharePoint Online administrator role provides that admin access to only SharePoint related controls and settings in the Office 365 Admin Center. The SharePoint Online admin can manage SharePoint site collections, configure SharePoint settings such as the organizations external sharing policy and access SharePoint Admin Center for additional SharePoint capabilities. However, the SharePoint Online admin will not have access to other Office 365 service controls and settings such as mailbox configuration, transport rules and other non-SharePoint related settings.

More-control-over-data-access-with-workload-specific-admin-roles-1

In addition, to better align the permissions to how your administrators are organized, there is more flexibility in assigning roles. If your Office IT administrators have multiple responsibilities and require permissions that are greater than what is offered in one administrator role, such as within SharePoint Online and Skype for Business Online responsibilities, then you can assign both those roles to that administrator. Your organization is no longer limited to only one admin role assignment per administrator.

To configure an admin role, the global administrator selects the user from the active user list, then selects edit user roles > Limited Admin Role to display the list of all the Office 365 admin roles. Simply select the applicable admin role(s) and you’re done.

More-control-over-data-access-with-workload-specific-admin-roles-2

With the new workload-specific admin roles and the ability to select multiple admin roles, your organization now has more options to set the right level of permissions to your Office 365 IT administrators. Ultimately, this means you now have more control over who has access to your organization’s data.

For more details on all the admin roles available in Office 365, please see, Assigning admin roles in Office 365.

Top