Who can do what

What each kind of person can accomplish with CloudSergeant — and, for every operation, the Microsoft permission and role it actually needs.

CloudSergeant has no permission model of its own

Every action runs with the signed-in user's delegated Microsoft Graph, Exchange and SharePoint permissions. What someone can do is decided by their Microsoft Entra roles and workload permissions — there is no second set of rights to configure, review or audit, and no way to grant someone more inside CloudSergeant than they already have in Microsoft 365.

The only thing a CloudSergeant licence controls is whether the app may reach beyond your own tenant. Everything below follows from Microsoft's model, not ours.

The three personas

End user

A licensed Microsoft 365 user with no administrative role. Signed in to their own tenant.

Tenant administrator

Holds one or more Entra administrator roles in their own tenant. What they can do varies by role — the last column says which.

Delegated partner administrator

A partner with a Partner licence, working inside a customer's tenant through a GDAP relationship. Their own tenant's roles do not carry over.

Capability matrix

Every row is an operation the app performs. "Needs" lists the Microsoft permission and the directory, Exchange or SharePoint role required; Global Administrator always covers it.
Operation End user Tenant administrator Delegated partner admin Needs
Entra
Sign in, browse the directory lists YesRead-only Yes Yes Admin consent for the app in the tenant. A directory-reader role in the GDAP relationship.
Edit a user's profile No Yes Yes User.ReadWrite.All + User Administrator.
Create a user No Yes Yes User.ReadWrite.All + User Administrator.
Delete a user No Yes Yes User.ReadWrite.All + User Administrator. Privileged Authentication Administrator if the target holds an admin role. Never for a directory-synced account.
Reset a password No Yes Yes User.ReadWrite.All + Helpdesk, User, or Authentication Administrator. Privileged Authentication Administrator for an admin target.
Edit mobile / business phone No With the right role With the right role User-Phone.ReadWrite.All + Authentication Administrator. Not covered by User.ReadWrite.All.
Manage authentication methods, require MFA re-registration No With the right role With the right role UserAuthenticationMethod.ReadWrite.All (baseline) + Authentication Administrator. Never on your own account.
Change a profile picture No Yes Yes User.ReadWrite.All + User Administrator.
Reset an on-premises Immutable ID No Yes Yes User.ReadWrite.All + User Administrator, or Privileged Authentication Administrator.
Create or edit a group No Yes Yes Group.ReadWrite.All + Groups or User Administrator.
Change group membership or owners No Yes Yes GroupMember.ReadWrite.All + Groups or User Administrator.
Delete a group No Yes Yes Group.ReadWrite.All + Groups or User Administrator. Privileged Role Administrator for a role-assignable group. An Exchange role for distribution and mail-enabled security groups.
Edit a distribution group's mail settings No Exchange role Exchange role Exchange Administrator or Recipient Management. A directory role does not cover it.
Enable, disable or delete a device No Device role If in the relationship Directory.AccessAsUser.All (baseline) + Cloud Device or Intune Administrator.
Reveal a BitLocker recovery key No Device role If in the relationship BitLockerKey.Read.All + a device-administrator role. Always written to the activity log.
Mail contacts No Exchange role Exchange role in the relationship Exchange Administrator or Recipient Management.
Search across the tenant YesDirectory sources only Yes Yes Whatever each source needs. Sources you cannot read are reported and skipped; the rest still work.
Compare two users or two groups YesRead-only Yes Yes The same as browsing the directory lists. Compare only reads.
Exchange
Grant yourself Full Access to a mailbox No Yes Yes Recipient Management, or Exchange Administrator.
Mailbox settings, addresses, forwarding, permissions No Exchange role Exchange role in the relationship Exchange Administrator or Recipient Management.
View restricted senders NoThe page is an administrative tenant-wide view Yes Yes through GDAP Exchange Online delegated access + Global Reader, Security Reader or View-Only Organization Management.
Unblock restricted senders No Yes Yes through GDAPIf the security role is assigned Exchange Online delegated access + Security Administrator, Global Administrator or Organization Management.
View quarantine for all users NoThe page is an administrative tenant-wide view Yes Yes through GDAP Exchange Online delegated access + Security Reader or Global Reader.
Release or permanently delete quarantined email No Yes Yes through GDAPIf the Defender role is assigned Exchange Online delegated access + Security Administrator or Global Administrator, or the corresponding Defender Email & collaboration role group.
Cleanup / Copy-Move / Export-Import on own mailbox Yes Yes NoNo mailbox in the customer tenant Mail.ReadWrite. No role — mailbox content is owner-only.
…on another mailbox with Full Access YesIf granted the access Yes No Mail.ReadWrite.Shared plus Full Access on that mailbox.
…by signing in a second account Yes Yes Yes, this way onlySign in as a tenant user with access An account that can already open the mailbox. No grant and no GDAP role needed.
OneDrive
List the tenant's OneDrives No Reports role If in the relationship Reports.Read.All and ReportSettings.ReadWrite.All (baseline) + Reports Reader, SharePoint Administrator or Global Reader. Global Administrator is required to turn off concealed report names.
Read or empty a OneDrive recycle bin No Home tenant onlyPrimary sign-in NoNot through GDAP or the second sign-in SharePoint AllSites.FullControl + SharePoint Administrator, against the home-tenant personal-site endpoint.
Read or change OneDrive quota, sharing or lock settings No SharePoint role If in the relationshipRequires a report URL or owner-verified standard URL SharePoint AllSites.FullControl + SharePoint Administrator. Report storage may still appear when the live SharePoint fields cannot be resolved.
Manage OneDrive site collection administrators No SharePoint role Add onlyThe existing list is unavailable SharePoint AllSites.FullControl + SharePoint Administrator.
Share OneDrive files, including during user deletion No SharePoint role NoThe file plane is unavailable Files.ReadWrite.All (baseline) + SharePoint Administrator.
OneDrive Copy-Move / Export-Import / filtered Cleanup on a drive already accessible to the signed-in identity YesOwn or explicitly accessible drive Yes Not with the GDAP identityThe file plane refuses it Files.ReadWrite.All (baseline). No administrator role is needed when that identity can already open the drive.
…by signing in a second account Yes Yes Yes, this way onlySign in as a customer-tenant user with file access An account that can already open the drive. No GDAP role or application permission is added.
Tenant
View licence subscriptions and who holds them YesRead-only Yes Yes Directory.Read.All.
Assign or remove licences No Yes Yes User.ReadWrite.All + Licence or User Administrator.
Assign or remove an admin role No Privileged role only If in the relationship RoleManagement.ReadWrite.Directory (baseline) + Privileged Role Administrator.
Partner
Switch into a customer tenant No NoNeeds a Partner licence Yes A CloudSergeant Partner licence, plus a GDAP relationship with the customer.

Three things the table cannot show

An end user is not blocked from looking

CloudSergeant does not hide the directory pages from people without an administrative role. Microsoft exposes no way to test in advance whether a write would succeed, so the app attempts the operation and explains any refusal — and the read permissions are consented for the whole organisation, not per person.

In practice that means an ordinary user who signs in can browse the user, group and device lists, and every attempt to change anything is refused by Microsoft. If that is not acceptable in your organisation, restrict who can obtain the app or use Conditional Access — do not rely on the interface to hide it.

Mailbox content is the one thing no role grants

Every other row in the table can be unlocked with the right Entra or Exchange role. Reading and deleting the contents of a mailbox cannot: it is available only to the mailbox's owner or to someone with Full Access. Not Exchange Administrator, not Global Administrator, not a GDAP relationship. This is Microsoft's model, and it is why a GDAP partner identity cannot run the mailbox tools; the explicit second sign-in must be a tenant user that already has owner or Full Access rights — the longer explanation is here.

Two escalations, and two refusals that are not about permissions

Acting on an account that itself holds an admin role raises the bar to Privileged Authentication Administrator — for a password reset, authentication methods, an immutable ID reset, or a deletion. A 403 on one specific user while everyone else works is almost always this.

And Microsoft Entra refuses two role removals no matter what you hold: removing the last Global Administrator, and removing an assignment that is not a direct membership — a PIM-eligible assignment, or a role held through a role-assignable group. CloudSergeant only ever shows and changes direct, active assignments.

And the licence itself

Who can administer the CloudSergeant subscription.
ActionWho
Register the organisation, start the Beta Trial, manage the subscription A Microsoft Entra Global Administrator of that organisation, and nobody else.
Use the app under the organisation's licence Anyone signing in from the licensed tenant — the licence covers the organisation, not named people or devices.
See the licence state and re-check it Anyone signed in, from the notice in the app.

More on permissions and troubleshooting