Azure AD Custor Role to Only Restory Groups

Mario A. Hernandez 171 Reputation points
2021-08-06T17:29:40.67+00:00

Hello, I need a little help. I am trying to create a custom role in Azure AD to allow restoration of groups and that's it. There is a Group Administrator built in role with that option but it gives too much power. When I create a new custom role from scratch, it does not give me the options to restore a group. I can only see options to create, delete, modify but not restore. Any ideas?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2021-08-11T20:08:33.253+00:00

    @Mario A. Hernandez
    Thank you for your post!

    Based off our Restore a deleted Microsoft 365 group in Azure Active Directory documentation, the only options to restore a deleted group would be through the Azure Portal, AzureAD Admin Center, or PowerShell. From my testing, it doesn't look like the role permission of microsoft.directory/groups/restore is available to be assigned to custom roles. If you'd like this permission to be added to the permissions list, I'd recommend leveraging our User Voice forum so our engineering team can look into implementing this.

    122320-image.png

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. FJcmdk4488 56 Reputation points
    2021-08-10T23:32:10.797+00:00

    Can you provide some more detail on what you are trying to do with this role? Do you need to restore a group that this role does not own?

    I believe you must have one of the following roles to restore and permanently delete users.

    Global administrator

    Partner Tier1 Support

    Partner Tier2 Support

    User administrator

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.