Seperate O365 Global Admin from Azure Global Admin
We have need to separate admin roles between O365 - we have administrators for Office 365 who are not Active Directory administrators. These roles need to be separated.

6 comments
-
Michael Siciliano commented
This is definitely needed
-
David Greene commented
For Global Admin
-
Roger Borrello commented
Office 365 administration is very similar to desktop administration, where we are configuring application behaviors. To keep that the same as the infrastructure administration is just a bad experience for administers trying to establish least privilege roles.
-
Dustin B. commented
This is very much needed. Especially for high regulated industries that have requirements for role separation.
-
Richard Gardner commented
100% agree. We have two towers in our organization. One who are the enterprise admins (in old AD speak) and the Exchange Admins (in old Exchange speak). In the cloud there should be matching split of responsibilities and capabilities (permissions and rights).
There should be Azure Global Admins, and there should be O365 Admins, totally separate. If your org is small and one person, or only one group does all those functions, then add them to each separately.
-
Rob commented
I meant to say - We have need to separate admin roles between O365 and Azure. Can't have O365 Global Admin have Admin rights in Azure AD, etc.