Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium

A global administrator needs to delegate the ability to manage Exchange Online recipient properties (e.g., mailboxes, distribution lists) to a junior administrator, but without granting them full control over all Exchange Online settings or other Microsoft 365 services. Which built-in Azure AD role provides the LEAST privilege required for this task?

  1. AGlobal Administrator
  2. BUser Administrator
  3. CExchange Administrator
  4. DHelpdesk Administrator
Show answer & explanation

Correct answer: C. Exchange Administrator

The Exchange Administrator role is specifically designed to manage recipients, compliance, and other Exchange Online features. It provides the necessary permissions for managing mailboxes and distribution lists without granting broader administrative rights across the entire Microsoft 365 tenant, adhering to the principle of least privilege.

Why the other options are wrong

  • A. Global Administrator grants full control over all Microsoft 365 services and is excessive for this task.
  • B. User Administrator can manage users' properties and licenses but does not have the specific permissions to manage Exchange recipient properties like mailboxes and distribution lists.
  • D. Helpdesk Administrator can reset passwords and manage service requests but lacks the specific permissions for Exchange recipient management.

Principle of Least Privilege

A security best practice dictating that users and services should only be granted the minimum permissions necessary to perform their required tasks.

  • Reduces the attack surface and potential damage from compromised accounts.
  • Requires careful selection of roles and permissions.
  • Often involves using built-in roles or creating custom roles.

Memory trick: Think of roles as different keys, each opening specific doors in your Microsoft 365 castle.

More Deploy and manage a Microsoft 365 tenant questions