Home > App Management > Manage App Profiles for Microsoft Tenants > How to Assign the Exchange Administrator Role to an App? > Overview
Export to PDFIf you create app profiles for the following apps and you want to manage Exchange mailboxes and settings / Security and distribution group objects / Microsoft 365 Defender settings, you need to go to the Microsoft Entra admin center (or Microsoft Azure portal) to assign the Exchange Administrator role to the apps.
| App profile type (in AOS) | App profile type (in AOS) | App name (in Microsoft Entra ID) |
|---|---|---|
| Classic mode | Microsoft 365 (All permissions) | AvePoint Online Services Administration for Microsoft365 |
| Modern mode | Cloud Backup for Microsoft 365 (All permissions) | AvePoint Cloud Backup for Microsoft365 (All Permissions) |
| Modern mode | Cloud Backup for Microsoft 365 (Exchange permissions) | AvePoint Cloud Backup for Microsoft365 (Exchange Permissions) |
| Modern mode | EnPower for Microsoft 365 | AvePoint EnPower for Microsoft365 |
| Modern mode | EnPower for Teams Calling | AvePoint EnPower Teams Calling |
| Modern mode | Policies for Microsoft 365 | AvePoint Policies for Microsoft365 |
| Modern mode | Cloud Governance for Exchange | AvePoint Cloud Governance Exchange App |
| Modern mode | Fly | AvePoint Fly |
| Modern mode | Opus | AvePoint Opus |
| Modern mode | Cloud Management Services for Microsoft 365 (This app requires the Exchange Administrator role only when your organization uses the Classic DocAve Backup service or uses the Cloud Archiving service together with the AvePoint Opus service for Exchange management.) | AvePoint Cloud Management Service for Microsoft365 |
| Custom mode | Custom Azure apps of the following services: Cloud Backup for Microsoft 365, Cloud Management, Cloud Governance, Fly, EnPower, Opus, and Policies for Microsoft 365 | [custom app name]You can also get its application ID in the app profile detail page. |
Note the following:
To use Cloud Backup for Microsoft 365, EnPower, or Policies for Microsoft 365, the Exchange Administrator role must be assigned to the related app.
To use Cloud Governance, if you do not want to assign the Exchange Administrator role to the related app, you can also assign custom Exchange Online role groups to the app. For details on assigning custom Exchange Online role groups, refer to the Assign Custom Exchange Online Role Groups to the Application section.
To use Fly, if you do not want to assign the Exchange Administrator role to this app, you can also assign custom roles to the app. For more information, refer to the Fly User Guide.
To use Cloud Management or Opus, if you do not want to assign the Exchange Administrator role to this app, you can also assign other supported Microsoft Entra roles to the app. For more information, refer to this Microsoft article: Assign Microsoft Entra roles to the application.
To scan Microsoft 365 Group / Microsoft Team / Viva Engage Community objects with the Group / Team / Viva Engage community property > Custom attribute rule, the Exchange Administrator role must be assigned to the related apps in your environment.
To assign the Exchange Administrator role to the app, refer to the following steps:
Log in to the Microsoft Entra admin center (or Microsoft Azure portal), and go to Microsoft Entra ID.
Click Roles & admins (or Roles and administrators) in the left pane.
On the Roles and administrators page, search the Exchange Administrator role, and then click Exchange Administrator.

On the Assignments page that opens, click Add assignments.
On the Add assignments page, click the button to select a member.

You can enter an app name (or application ID) in the search box to search for the app to which you want to assign the role.
The Application ID information is displayed on the App profile details page in AvePoint Online Services > Management > App management.

Select the app and click Select to assign the role. Note that the assigned role will take effect in about 30 minutes.