PIM roles: can you create a custom role that combines the Exchange Administrator and Exchange Recipient Administrator

Xiomara Gonzalez 40 Reputation points
2023-08-22T09:25:55.5933333+00:00

Hi All,

I tried creating a custom role that would combine some permissions of the Exchange Recipient administrator role and the Exchange Administrator role.

When I created the custom role I cloned the Exchange Administrator role and tried adding some permissions from the Exchange Recipient administrator role and I was not able to find any. I then started the custom role from scratch and was not able to find the permissions I wanted from the Exchange Recipient administrator role.

Can someone please confirm if this is possible and how I could do this?

Thank you in advance!

Microsoft Entra
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 149.3K Reputation points MVP
    2023-08-22T10:53:05.6966667+00:00

    The Exchange Admin can do everything the Recipient Manager can do so there would be no reason to combine them.

    You can't create custom roles for Exchange from Azure however, it an Exchange thing

    https://learn.microsoft.com/en-us/exchange/permissions-exo/permissions-exo


  2. Andy David - MVP 149.3K Reputation points MVP
    2023-08-22T11:07:13.3666667+00:00

    Ok, the existing Exchange roles are the only ones available. If you want to to create a custom role, you have to create an Exchange specific role, not an Azure one.

    One thing I have not tested with an Exchange role is creating a custom role in Exchange and adding to a PIM enabled group like this. I know it works for Purview:

    https://nikkichapple.com/how-to-apply-just-in-time-access-to-security-compliance-roles/


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.