End user
A licensed Microsoft 365 user with no administrative role. Signed in to their own tenant.
What each kind of person can accomplish with CloudSergeant — and, for every operation, the Microsoft permission and role it actually needs.
Every action runs with the signed-in user's delegated Microsoft Graph, Exchange and SharePoint permissions. What someone can do is decided by their Microsoft Entra roles and workload permissions — there is no second set of rights to configure, review or audit, and no way to grant someone more inside CloudSergeant than they already have in Microsoft 365.
The only thing a CloudSergeant licence controls is whether the app may reach beyond your own tenant. Everything below follows from Microsoft's model, not ours.
A licensed Microsoft 365 user with no administrative role. Signed in to their own tenant.
Holds one or more Entra administrator roles in their own tenant. What they can do varies by role — the last column says which.
A partner with a Partner licence, working inside a customer's tenant through a GDAP relationship. Their own tenant's roles do not carry over.
| Operation | End user | Tenant administrator | Delegated partner admin | Needs |
|---|---|---|---|---|
| Entra | ||||
| Sign in, browse the directory lists | YesRead-only | Yes | Yes | Admin consent for the app in the tenant. A directory-reader role in the GDAP relationship. |
| Edit a user's profile | No | Yes | Yes | User.ReadWrite.All + User Administrator. |
| Create a user | No | Yes | Yes | User.ReadWrite.All + User Administrator. |
| Delete a user | No | Yes | Yes | User.ReadWrite.All + User Administrator. Privileged Authentication Administrator if the target holds an admin role. Never for a directory-synced account. |
| Reset a password | No | Yes | Yes | User.ReadWrite.All + Helpdesk, User, or Authentication Administrator. Privileged Authentication Administrator for an admin target. |
| Edit mobile / business phone | No | With the right role | With the right role | User-Phone.ReadWrite.All + Authentication Administrator. Not covered by User.ReadWrite.All. |
| Manage authentication methods, require MFA re-registration | No | With the right role | With the right role | UserAuthenticationMethod.ReadWrite.All (baseline) + Authentication Administrator. Never on your own account. |
| Change a profile picture | No | Yes | Yes | User.ReadWrite.All + User Administrator. |
| Reset an on-premises Immutable ID | No | Yes | Yes | User.ReadWrite.All + User Administrator, or Privileged Authentication Administrator. |
| Create or edit a group | No | Yes | Yes | Group.ReadWrite.All + Groups or User Administrator. |
| Change group membership or owners | No | Yes | Yes | GroupMember.ReadWrite.All + Groups or User Administrator. |
| Delete a group | No | Yes | Yes | Group.ReadWrite.All + Groups or User Administrator. Privileged Role Administrator for a role-assignable group. An Exchange role for distribution and mail-enabled security groups. |
| Edit a distribution group's mail settings | No | Exchange role | Exchange role | Exchange Administrator or Recipient Management. A directory role does not cover it. |
| Enable, disable or delete a device | No | Device role | If in the relationship | Directory.AccessAsUser.All (baseline) + Cloud Device or Intune Administrator. |
| Reveal a BitLocker recovery key | No | Device role | If in the relationship | BitLockerKey.Read.All + a device-administrator role. Always written to the activity log. |
| Mail contacts | No | Exchange role | Exchange role in the relationship | Exchange Administrator or Recipient Management. |
| Search across the tenant | YesDirectory sources only | Yes | Yes | Whatever each source needs. Sources you cannot read are reported and skipped; the rest still work. |
| Compare two users or two groups | YesRead-only | Yes | Yes | The same as browsing the directory lists. Compare only reads. |
| Exchange | ||||
| Grant yourself Full Access to a mailbox | No | Yes | Yes | Recipient Management, or Exchange Administrator. |
| Mailbox settings, addresses, forwarding, permissions | No | Exchange role | Exchange role in the relationship | Exchange Administrator or Recipient Management. |
| View restricted senders | NoThe page is an administrative tenant-wide view | Yes | Yes through GDAP | Exchange Online delegated access + Global Reader, Security Reader or View-Only Organization Management. |
| Unblock restricted senders | No | Yes | Yes through GDAPIf the security role is assigned | Exchange Online delegated access + Security Administrator, Global Administrator or Organization Management. |
| View quarantine for all users | NoThe page is an administrative tenant-wide view | Yes | Yes through GDAP | Exchange Online delegated access + Security Reader or Global Reader. |
| Release or permanently delete quarantined email | No | Yes | Yes through GDAPIf the Defender role is assigned | Exchange Online delegated access + Security Administrator or Global Administrator, or the corresponding Defender Email & collaboration role group. |
| Cleanup / Copy-Move / Export-Import on own mailbox | Yes | Yes | NoNo mailbox in the customer tenant | Mail.ReadWrite. No role — mailbox content is owner-only. |
| …on another mailbox with Full Access | YesIf granted the access | Yes | No | Mail.ReadWrite.Shared plus Full Access on that mailbox. |
| …by signing in a second account | Yes | Yes | Yes, this way onlySign in as a tenant user with access | An account that can already open the mailbox. No grant and no GDAP role needed. |
| OneDrive | ||||
| List the tenant's OneDrives | No | Reports role | If in the relationship | Reports.Read.All and ReportSettings.ReadWrite.All (baseline) + Reports Reader, SharePoint Administrator or Global Reader. Global Administrator is required to turn off concealed report names. |
| Read or empty a OneDrive recycle bin | No | Home tenant onlyPrimary sign-in | NoNot through GDAP or the second sign-in | SharePoint AllSites.FullControl + SharePoint Administrator, against the home-tenant personal-site endpoint. |
| Read or change OneDrive quota, sharing or lock settings | No | SharePoint role | If in the relationshipRequires a report URL or owner-verified standard URL | SharePoint AllSites.FullControl + SharePoint Administrator. Report storage may still appear when the live SharePoint fields cannot be resolved. |
| Manage OneDrive site collection administrators | No | SharePoint role | Add onlyThe existing list is unavailable | SharePoint AllSites.FullControl + SharePoint Administrator. |
| Share OneDrive files, including during user deletion | No | SharePoint role | NoThe file plane is unavailable | Files.ReadWrite.All (baseline) + SharePoint Administrator. |
| OneDrive Copy-Move / Export-Import / filtered Cleanup on a drive already accessible to the signed-in identity | YesOwn or explicitly accessible drive | Yes | Not with the GDAP identityThe file plane refuses it | Files.ReadWrite.All (baseline). No administrator role is needed when that identity can already open the drive. |
| …by signing in a second account | Yes | Yes | Yes, this way onlySign in as a customer-tenant user with file access | An account that can already open the drive. No GDAP role or application permission is added. |
| Tenant | ||||
| View licence subscriptions and who holds them | YesRead-only | Yes | Yes | Directory.Read.All. |
| Assign or remove licences | No | Yes | Yes | User.ReadWrite.All + Licence or User Administrator. |
| Assign or remove an admin role | No | Privileged role only | If in the relationship | RoleManagement.ReadWrite.Directory (baseline) + Privileged Role Administrator. |
| Partner | ||||
| Switch into a customer tenant | No | NoNeeds a Partner licence | Yes | A CloudSergeant Partner licence, plus a GDAP relationship with the customer. |
CloudSergeant does not hide the directory pages from people without an administrative role. Microsoft exposes no way to test in advance whether a write would succeed, so the app attempts the operation and explains any refusal — and the read permissions are consented for the whole organisation, not per person.
In practice that means an ordinary user who signs in can browse the user, group and device lists, and every attempt to change anything is refused by Microsoft. If that is not acceptable in your organisation, restrict who can obtain the app or use Conditional Access — do not rely on the interface to hide it.
Every other row in the table can be unlocked with the right Entra or Exchange role. Reading and deleting the contents of a mailbox cannot: it is available only to the mailbox's owner or to someone with Full Access. Not Exchange Administrator, not Global Administrator, not a GDAP relationship. This is Microsoft's model, and it is why a GDAP partner identity cannot run the mailbox tools; the explicit second sign-in must be a tenant user that already has owner or Full Access rights — the longer explanation is here.
Acting on an account that itself holds an admin role raises the bar to Privileged Authentication Administrator — for a password reset, authentication methods, an immutable ID reset, or a deletion. A 403 on one specific user while everyone else works is almost always this.
And Microsoft Entra refuses two role removals no matter what you hold: removing the last Global Administrator, and removing an assignment that is not a direct membership — a PIM-eligible assignment, or a role held through a role-assignable group. CloudSergeant only ever shows and changes direct, active assignments.
| Action | Who |
|---|---|
| Register the organisation, start the Beta Trial, manage the subscription | A Microsoft Entra Global Administrator of that organisation, and nobody else. |
| Use the app under the organisation's licence | Anyone signing in from the licensed tenant — the licence covers the organisation, not named people or devices. |
| See the licence state and re-check it | Anyone signed in, from the notice in the app. |