Fix SharePoint Site Collection Administrator Access Errors
Question details
A Global Administrator receives access denied errors when attempting to use PowerShell cmdlets like Get-SPOUser and Get-SPOGroup.

- Product
- SharePoint Online
- Device & OS
- not provided
- Scenario
- Running SharePoint Online PowerShell cmdlets to view or manage site users and groups.
- Observed behavior
- The system returns an access error despite the user executing the commands with a Global Administrator account.
Ensure you have the latest version of the SharePoint Online Management Shell installed and that you have your Global Administrator credentials ready.
Connect to the Correct Admin Endpoint and Assign Permissions
Verify your connection to the SharePoint administration URL and explicitly grant Site Collection Administrator rights to your admin account.
Although Global Administrators have broad access across Microsoft 365, explicit Site Collection Administrator permissions are sometimes required to successfully execute site-level cmdlets like Get-SPOUser and Get-SPOGroup.
Open PowerShell as an administrator and run the command 'Connect-SPOService -Url https://[yourtenant]-admin.sharepoint.com'. Log in with your Global Administrator credentials.
Execute the command 'Set-SPOUser -Site https://[yourtenant].sharepoint.com/sites/[sitename] -LoginName youradmin@domain.com -IsSiteCollectionAdmin $true' to explicitly grant your account administrator rights to the specific site.
Run the 'Get-SPOUser' or 'Get-SPOGroup' cmdlet again for the target site to confirm the access error has been resolved.

Escalate via Microsoft 365 Support Ticket
If explicit permission assignment does not resolve the access errors, open a support ticket with Microsoft for backend investigation.
Boost Document Productivity with WPS Office
While managing SharePoint sites requires specific Microsoft 365 administration tools, everyday document collaboration doesn't have to be complicated. WPS Office provides a lightweight, highly compatible alternative for creating, editing, and sharing documents across your organization without complex permission setups.
- 1. Download and Install: Visit the official WPS Office website to download the free installation package for your operating system.
- 2. Open Office Files: Launch WPS Office and directly open your existing .docx, .xlsx, or .pptx files with zero formatting loss.
- 3. Edit and Collaborate: Use the familiar, intuitive ribbon interface to edit documents and easily share them with your team.

Frequently Asked Questions
Why does a Global Administrator get access denied in SharePoint?
While Global Admins have tenant-wide administrative privileges, individual SharePoint site collections often require explicit Site Collection Administrator permissions to manage users and groups via site-level PowerShell cmdlets.
What is the correct endpoint URL for Connect-SPOService?
You must connect to your organization's SharePoint administration URL. It is typically formatted as https://[your-tenant-name]-admin.sharepoint.com.
How can I assign Site Collection Administrator rights using PowerShell?
You can assign these rights by using the Set-SPOUser cmdlet combined with the -IsSiteCollectionAdmin $true parameter targeting your specific admin account email and the site URL.




