Microsoft 365 Container Level Permissions

    ModuleAccessible reportAvailable actionDescription
    ExchangeMailboxesCreate mailboxesCreate user mailboxes.
    *Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
    ExchangeMailboxesDelete mailboxesDelete user mailboxes.
    ExchangeMailboxesSearch for mailbox forwardingSearch for mailboxes that are automatically forwarding emails to specific internal recipients
    ExchangeMailboxesManage mailboxesManage user mailboxes, including to edit information for basics, update settings, and archive user mailboxes.
    ExchangeMailboxesLitigation holdManage the litigation hold settings of mailboxes.
    ExchangeMailboxesManage mailbox delegationManage user mailbox delegation settings, including the contacts folder delegation, calendar delegation, and mailbox delegation settings.
    ExchangeMailboxesCopy permissionCopy permission of a mailbox to another one.
    ExchangeMailboxesCheck if mailbox existsCheck if the mailbox still exists.
    ExchangeMailboxesExport reportsExport user mailboxes into reports.
    ExchangeMailboxesManage organization units for on-premises mailboxesMove hybrid mailboxes from one organization unit to another.
    ExchangeMailboxesApply renewal profileApply renewal profile created in Cloud Governance to shared mailboxes.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesApply contact election profileApply contact election profile created in Cloud Governance to shared mailboxes.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesRestart renewalRestart the renewal process of shared mailboxes.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesAuto-complete renewalComplete the renewal process of shared mailboxes.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesAssign renewal tasksUpdate the assignees of a shared mailbox’s renewal.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesSpecify contactsSpecify contacts for shared mailboxes.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesEdit metadataEdit the Cloud Governance metadata applied to the shared mailboxes.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesRemove from Cloud Governance.Remove registered mailboxes from Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailboxesTrigger workflowsTrigger the manually triggered workflows to manage or report the selected user mailboxes.
    ExchangeResourcesCreate resource mailboxesCreate resource mailboxes.
    *Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
    ExchangeResourcesDelete resource mailboxesDelete resource mailboxes
    ExchangeResourcesManage resource mailboxesManage resource mailboxes, including to edit information for the basics, resource address, and configure booking options.
    ExchangeResourcesManage resource mailbox delegationManage resource mailboxes delegation, including both resource and calendar delegation.
    ExchangeResourcesExport reportsExport resource mailboxes into reports.
    ExchangeResourcesSpecify contactsSpecify contacts for resource mailboxes.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeResourcesEdit metadataEdit the Cloud Governance metadata applied to the resource mailboxes.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeResourcesRemove from Cloud Governance.Remove registered resource mailboxes from Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    ExchangeMailbox activityExport reportsView and export mailbox activity reports.
    ExchangeMail usersManage mail usersIncluding mail users and guest mail users.
    *Note: guest mail users can only be managed in Users module.
    ExchangeMail usersDelete mail usersIncluding mail users and guest mail users.
    *Note: guest mail users can only be deleted in the Users module.
    ExchangeMail usersExport reportsExport mail users into reports.
    TeamsTeamsCreate TeamsCreate Teams.
    Note the following: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.If selected, you can also configure whether only users in this group's manageable tenants or user containers can be added to Groups during Group creation
    TeamsTeamsDelete TeamsDelete Teams.
    TeamsTeamsManage TeamsManage Teams, including basics, channels, and settings.
    TeamsTeamsManage membershipsManage memberships, including Team memberships, channel memberships, and policies.
    TeamsTeamsDownload permission reportDownload Teams’ permission report.*Note: This is only available when you have a subscription for AvePoint Insights.
    TeamsTeamsExport reportsExport Teams into reports.
    TeamsTeamsTrigger workflowsTrigger the manually triggered workflows to manage or report the selected Teams.
    TeamsTeamsAppy renewal profileApply renewal profile created in Cloud Governance to Teams.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsRestart renewalRestart the renewal process of Teams.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsAuto-complete renewalComplete the renewal process of Teams.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsRemove from Cloud Governance.Remove registered Teams from Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsEdit metadataRemove Teams’ Cloud Governance metadata.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsSpecify contactsSpecify primary and secondary contacts for Teams.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsAssign renewal tasksUpdate the assignee of Teams’ renewal task.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeamsApply contact election profileApply contact election profile to Teams.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    TeamsTeams auditsExport reportsView and export Teams audit reports.
    TeamsTeams activity reportExport reportsView and export Teams activity reports.
    TeamsChannel reportCreate channelsCreate new channels.
    TeamsChannel reportDelete channelsDelete channels from Teams.
    TeamsChannel reportManage channelsUpdate channel information.
    TeamsChannel reportManage membershipView and update channel membership.
    TeamsChannel reportExport reportExport channel report into Excel files.
    TeamsDevice reportExport reportsView and export Teams device reports.
    TeamsUser reportEdit policiesAccess Teams user report and edit user policies.
    TeamsPSTN and SMS report-Access PSTN and SMS report.
    TeamsSensitivity reportApply sensitivity labelsApply sensitivity labels to Teams’ objects.
    TeamsSensitivity reportRemove permissionsRemove user permissions for Teams’ objects.
    GroupsGroupsCreate GroupsCreate Groups, including Microsoft 365 Groups, distribution groups, security groups, and mail-enabled security groups.
    Note the following: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.If selected, you can also configure whether only users in this group's manageable tenants or user containers can be added to Groups during Group creation
    GroupsGroupsManage GroupsManage Group properties.
    GroupsGroupsManage membershipsManage Group memberships.
    GroupsGroupsDelete GroupsDelete Groups.
    GroupsGroupsExport reportsExport Groups into reports.
    GroupsGroupsTrigger workflowsTrigger the manually triggered workflows to manage or report the selected Groups.
    GroupsGroupsApply renewal profileApply renewal profile created in Cloud Governance to groups.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsApply contact election profileApply contact election profile created in Cloud Governance to groups.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsRestart renewalRestart the renewal process of groups.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsAuto-complete renewalComplete the renewal process of groups.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsAssign renewal tasksUpdate the assignees of a group renewal.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsSpecify contactsSpecify contacts for groups.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsEdit metadataEdit the Cloud Governance metadata applied to the groups.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroupsRemove from Cloud GovernanceRemove registered Groups from Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    GroupsGroups activity reportExport reportsView and export Group activity reports.
    UsersUsersCreate usersCreate Microsoft 365 users.
    *Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
    UsersUsersCreate users/Invite users > Assign licenses and appsAssign licenses and apps when creating or inviting users.
    UsersUsersCreate users/Invite users > Create users in all containers/Invite users to all containersCreate or invite users to containers that is not in the permission group’s manageable scope.
    UsersUsersInvite usersInvite external users to your as guests in your organization.
    *Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
    UsersUsersCreate on-premises usersCreate on-premises users in your local Active Directory.
    UsersUsersManage organizational units for on-premises usersManage the organization units of your on-premises users.
    UsersUsersEdit user detailsEdit users’ detail information.
    UsersUsersManage admin rolesManage the administration roles of users.
    UsersUsersManage user licensesAssign or remove user licenses.
    UsersUsersManage security settingsManage settings, including password settings, user sessions, sign-in settings, and MFA settings.
    UsersUsersDelete usersDelete users.
    UsersUsersExport reportsExport users into reports.
    UsersUsersTrigger workflowsTrigger the manually triggered workflows to manage or report the selected users.
    UsersUsersRemove from Cloud GovernanceRemove registered users from Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    UsersSign-in reportConfigure MFA settingsConfigure the MFA settings for users in the Sign-in report.
    UsersSign-in reportReset MFA settingsReset the MFA settings for users in the Sign-in report, including restoring the user’s authentication status, resetting the user’s authentication methods, and deleting the app passwords generated by this user.
    UsersSign-in reportRevoke sessionsRevoke all sessions for the user and require the user to re-sign in on all devices in the Sign-in report.
    UsersSign-in reportReset passwordManually or automatically reset the password for users in the Sign-in report.
    UsersSign-in reportBlock sign-inBlock users from signing in.
    UsersSign-in reportExport reportsView and export sign-in reports.
    UsersUser activity reportExport reportsView and export user activity reports.
    UsersMicrosoft 365 Apps activity reportExport reportsExport Microsoft 365 Apps activity report.
    UsersUser activation reportExport reportsExport user activation reports.
    SharePointSharePoint sitesCreate sitesCreate SharePoint online sites.
    Note the following: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.If selected, you can also configure whether only users in this group's manageable tenants or user containers can be added to Groups during Group creation
    SharePointSharePoint sitesManage sites > BasicsEdit site basic information.
    SharePointSharePoint sitesManage sites > HubManage sites’ hub settings.
    SharePointSharePoint sitesManage sites > Connect to new Microsoft 365 GroupConnect sites to Microsoft 365 Group.
    SharePointSharePoint sitesArchive/ReactivateArchive sites or reactive archived sites.
    SharePointSharePoint sitesArchive/ReactivateArchive sites or reactive archived sites.
    SharePointSharePoint sitesManage permissionsManage site permissions, including site admins, site owners, site members, and site visitors.
    SharePointSharePoint sitesManage settingsManage site settings, including the sharing, sensitivity, storage settings, and site status.
    SharePointSharePoint sitesDelete sitesDelete sites.
    SharePointSharePoint sitesExport reportsExport SharePoint Online sites into reports.
    SharePointSharePoint sitesTrigger workflowsTrigger the manually triggered workflows to manage or report the selected sites.
    SharePointSharePoint sitesApply renewal profileApply renewal profile created in Cloud Governance to SharePoint sites.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesApply contact election profileApply contact election profile created in Cloud Governance to SharePoint sites.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesRestart renewalRestart the renewal process of SharePoint sites.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesAuto-complete renewalComplete the renewal process of SharePoint sites.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesAssign renewal tasksUpdate the assignees of SharePoint sites’ renewal.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesSpecify contactsSpecify contacts for SharePoint sites.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesEdit metadataEdit Cloud Governance metadata of the sites.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointSharePoint sitesRemove from Cloud GovernanceRemove registered SharePoint sites from Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    SharePointGroup team sitesCreate sitesCreate SharePoint Online Group team sites.
    *Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
    SharePointGroup team sitesManage sites > BasicsEdit sites’ basic information.
    SharePointGroup team sitesManage sites > HubUpdate sites’ hub settings.
    SharePointGroup team sitesArchive/ReactivateArchive sites or reactive archived sites.
    SharePointGroup team sitesManage permissionsManage Group team site permissions, including primary admin, additional admins, site owners, site members, and site visitors.
    SharePointGroup team sitesManage settingsManage Group team site settings, including the sharing, sensitivity, storage settings, and site status.
    SharePointGroup team sitesDelete sitesDelete Group team sites.
    SharePointGroup team sitesExport reportsExport Group team sites into reports.
    SharePointGroup team sitesTrigger workflowsTrigger the manually triggered workflows to manage or report the selected sites.
    OneDriveOneDriveManage administratorsManage OneDrive administrators.
    OneDriveOneDriveManage external sharingManage external sharing settings for OneDrive.
    OneDriveOneDriveManage storage limitManage storage limit for OneDrive.
    OneDriveOneDriveExport reportsExport OneDrive into reports.
    OneDriveOneDriveUpdate OneDrive statusLock or unlock the OneDrive.
    OneDriveOneDriveTrigger workflowsTrigger the manually triggered workflows to manage or report the selected OneDrive.
    OneDriveOneDriveApply renewal profileApply renewal profile created in Cloud Governance to OneDrive.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    OneDriveOneDriveRestart renewalRestart the renewal process of OneDrive.
    *Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    OneDriveOneDriveEnable/Disable assessmentEnable or disable OneDrive assessment in AvePoint Insights and Cloud Governance.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    OneDriveOneDriveAuto-complete renewalComplete the renewal process of OneDrive.*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
    Teams dashboardsTeams user adoption-Access the default Teams user adoption dashboard, and manage gadgets for the Active users, 1:1 calls and meetings, Audio and video time (min), Chats, Active users in departments, Chats in departments, Audio and video time in departments (min), 1:1 calls and meetings in departments charts.
    Teams dashboardsTeams activity-Access the default Teams activity dashboard, and manage gadgets for the Teams without owners, Inactive Teams, Top 10 Teams by members, Top 10 Teams by channels, Top 10 Teams by activity, Public vs Private Teams, Empty Teams, Teams with external users charts.
    Teams dashboardsTeams users-Access the default Teams users dashboard, and manage gadgets for the Active users, Inactive users, Active vs Inactive users charts.
    LoopLoopManage settingsManage basic workspace settings including sensitivity label assignment.
    LoopLoopManage permissionsManage workspace permissions.
    LoopLoopDeleteDelete workspaces.
    LoopLoopExport reportsExport workspace properties into reports.
    SharePoint dashboardsTotal storage used-View and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
    SharePoint dashboardsTotal files-View and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
    SharePoint dashboardsTop 10 inactive sites-View and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
    SharePoint dashboardsTop 10 sites by storage-View and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
    SharePoint dashboardsTop 10 sites by activity-View and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
    OneDrive dashboardsTotal storage used-View and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
    OneDrive dashboardsTotal files-View and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
    OneDrive dashboardsStorage used by blocked users-View and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
    OneDrive dashboardsFiles of blocked users-View and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
    OneDrive dashboardsTop 10 users by storage-View and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
    Compliance dashboardsExchange compliance-Access the default Exchange compliance dashboard, and manage gadgets for the Litigation hold enabled mailboxes, Mailboxes forwarding to external domains, Mailboxes forwarding to specific domains, Litigation hold enabled mailboxes in departments, Mailboxes forwarding to external domains in departments, Mailboxes forwarding to specific domains in departments charts.
    Compliance dashboardsAdministration compliance-Access the default Administration compliance dashboard, and manage gadgets for the Users with administrative roles, Global administrators, OneDrive with multiple administrators, Administrative role assignments, Users with administrative roles in departments, OneDrive with multiple administrators in departments charts.
    Compliance dashboardsUser access compliance-Access the default User access compliance dashboard, and manage gadgets for the Users without strong password, Password changed/reset users, Sign-in failed users, Users with multiple IP addresses, Strong password required, Users without strong password in departments, Password never expires, Password never expired users in departments, MFA status, MFA disabled users in departments, Password changed/reset users in departments, Sign-in failed users in departments, Sign-in failed users with multiple IP addresses in departments, Failed sign-ins in departments charts.
    Compliance dashboardsCollaboration compliance-Access the default Collaboration compliance dashboard, and manage gadgets for the External links, External users, Sensitive items, External links trend, External users trend, Sensitive items trend charts.
    Compliance dashboardsTop 10 compliance risks-Access the default Top 10 compliance risks dashboard, and manage gadgets for the Top 10 countries with failed sign-ins, Top 10 departments with failed sign-ins, Top 10 sign-in failed users, Top 10 OneDrive with multiple administrators charts.