Share via

Admin roles for Microsoft E3

Anonymous
2022-10-25T14:54:04+00:00

What are the best practices for administrating Microsoft E3 consoles like In-Tune and Universal Print (to name a few)?

Currently we use a separate admin user account with an admin designation in the user name. This account is admin on domain and in AzureAD (Global Administrator). However we do not wish to pay $36 or whatever it is for a Microsoft E3 licence monthly for both our regular user and our admin user.

So we don't want to run our daily regular users as admins either - big security risk.

Are there templates that you delgate certain E3 admin portals to regular IT users? Why doesn't the system allow a global admin user to administer on a portal that contains E3-exclusive features when there are many other E3 users under your umbrella?

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2022-10-25T17:40:38+00:00

    Hello kjstechO365,

    Good day!

    Thank you for posting to Microsoft Community. We are happy to help you.

    We usually advise the customer to have two admin to manage the admin role, so they don't need to assign admin role to normal users.

    Why doesn't the system allow a global admin user to administer on a portal that contains E3-exclusive features when there are many other E3 users under your umbrella? Do you mean administrator user. this is what the admin user can do: Assign the User admin role to users who need to do the following for all users:

    • Add users and groups
    • Assign licenses
    • Manage most users properties
    • Create and manage user views
    • Update password expiration policies
    • Manage service requests
    • Monitor service health

    The user admin can also do the following actions for users who aren't admins and for users assigned the following roles: Directory reader, Guest inviter, Helpdesk admin, Message center reader, Reports reader:

    • Manage usernames
    • Delete and restore users
    • Reset passwords
    • Force users to sign out
    • Update (FIDO) device keys

    For your reference about the different admin: About admin roles in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn

    Appreciate your patience and understanding and thank you for your time and cooperation.

    Sincerely,

    Eben Ezer Tres | Microsoft Community Moderator

    Was this answer helpful?

    0 comments No comments