Azure AD – New administration roles to delegate administration tasks and reduce the need to grant global administrator

As you know, Azure Active Directory provides a large list of administration roles to allow delegating administration tasks and reduce the need to grant the more powerful global administrator role.

Well, 2 new roles are now available:

  • Authentication policy administrator to delegate the permissions to manage the authentication methods enabled on Azure AD and associated tasks (multi factor authentication and password policy)
  • Domain name administrator to delegate domain names management (add, read, remove or update the domain(s) associated with your Azure AD tenant)

image_thumb-426-1370443  image_thumb-427-5912018

Azure AD – New administration role available to delegate administration of Microsoft Cloud App Security (MCAS)

As you know, Azure AD comes with administration roles to allow you delegate administration tasks with the least privilege.

Read More

Azure AD / Office 365 – 3 new administration roles available

In the way to limit the need and use of the global administrator role, 3 new administration roles have been made available:

Read More

Azure AD – New administration roles for managing domain name and authentication methods

Good news, you don’t need to be a global administrator to manage Multi Factor Authentication (MFA) or authentication methods.

Read More