it:ad:azure:security:role:administration:service_administrator:home

IT:AD:Azure:Security:Role:Administration:Service Administrator (SA)

There is only one Service Administrator (SA).

Can do all that an Account Administrator (AA) can – bar see the billing information.

Can in turn set up to 200 Service Co-Administrators (CAs).

Service Co-Administrator (CAs)s have the same permissions as the Service Administrator (SA) (ie, can create Services) – bar adding/removing Service Co-Administrators (CAs).

The reason for the split between Service Administrator (SA) and Service Co-Administrators (CAs) is an artificial way of defining which Admin can revoke service creation rights from others – and not have it done to him/her…

SubscriptionAccount Administrator : AccountService Administrator : AccountCo-administrators : Account[]Account1-*

Remembering that the Azure AD Service is not the same Service as AD itself is…not obvious.

Whereas the the creator of an Azure AD (which is generally the IT:AD:Azure:Security:Role:Administration:Account Administrator (AA)) is automatically made a Azure AD Global Administrator, others won't be – unless manually added and provisioned with an Azure AD administration role (they won't even see an AD to manage in their Portal)2).


  • /home/skysigal/public_html/data/pages/it/ad/azure/security/role/administration/service_administrator/home.txt
  • Last modified: 2023/11/04 03:02
  • by 127.0.0.1