‎ApplicationImpersonation permission on new admin role group

Ryan Link 25 Reputation points
2023-02-18T06:08:57.5266667+00:00

I am attempting to create a new role group with ApplicationImpersonation permissions per https://answers.microsoft.com/en-us/msoffice/forum/all/exchange-impersonation-error-unable-to-open-user/834c4ea9-6cb5-4df4-9011-433ba501f6d2.

When I do so in https://admin.exchange.microsoft.com/#/adminRoles I click Add role group, then name it CloudMigratorImpersonation with default write scope.

Next I add ApplicationImpersonation and Mailbox Import Export permissions, and attempt to assign myself (global admin) to the new role group.

When I click Add Role Group, I get:

Error executing request. You don't have access to create, change, or remove the "professionalartists.onmicrosoft.com\ApplicationImpersonation-CloudMigratorImpersonation" management role assignment. You must be assigned a delegating role assignment to the management role or its parent in the hierarchy without a scope restriction.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,068 questions
Microsoft Exchange Online
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
825 questions
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,562 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 107.3K Reputation points MVP
    2023-02-18T09:09:26.23+00:00

    Seems like someone has played with the default role group assignments in your tenant. On the same page, open the Organization management role and under Permissions, make sure the checkbox next to Role management is ticked. While you're there, wouldn't hurt to also add your own user as member of the role.

    3 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.