How to Grant Administrator Access to a User's OneDrive with PowerShell
Question details
The user needs to know the exact PowerShell commands to assign Site Collection Administrator access to a specific user's OneDrive account.

- Product
- Microsoft OneDrive
- Device & OS
- not provided
- Scenario
- An IT administrator is trying to manage permissions and gain access to a specific user's OneDrive account for compliance or management purposes.
- Observed behavior
- The user requires clarification on the correct PowerShell module, tenant URL format, and specific command syntax, as basic MSOnline commands do not grant OneDrive permissions.
Ensure you have the SharePoint Online Management Shell installed on your machine and possess Global Administrator or SharePoint Administrator privileges in your Microsoft 365 tenant.
Use SharePoint Online Management Shell to Grant Access
The most direct and reliable method to grant Site Collection Administrator rights to a user's OneDrive is via the official SharePoint Online PowerShell module.
OneDrive accounts are technically specialized SharePoint site collections. Therefore, managing their permissions requires using SharePoint Online (SPO) PowerShell commands rather than general Azure AD commands.
Open PowerShell as Administrator and run the command 'Connect-SPOService -Url https://yourtenant-admin.sharepoint.com'. Replace 'yourtenant' with your actual Microsoft 365 organization name, and sign in with your admin credentials.
Determine the exact URL of the target user's OneDrive. It typically follows the format 'https://yourtenant-my.sharepoint.com/personal/user_domain_com'.
Execute the command 'Set-SPOUser -Site https://yourtenant-my.sharepoint.com/personal/user_domain_com -LoginName admin@yourtenant.com -IsSiteCollectionAdmin $true'. Ensure you replace the URLs and the LoginName with the actual target URL and your administrator email.

Use PnP PowerShell Module
PnP PowerShell provides an alternative, often simplified syntax for managing Microsoft 365 permissions, including OneDrive sites.
Manage and Edit Your Documents Seamlessly with WPS Office
While IT administrators manage backend OneDrive access using PowerShell, end-users need a reliable, fast, and highly compatible office suite to handle their daily document tasks. WPS Office is a powerful, free alternative to Microsoft Office that supports viewing and editing files directly from various cloud storage platforms.
- 1. Download and Install WPS Office: Visit the official WPS website, download the free installer, and follow the on-screen instructions to set up the software.
- 2. Sign In to Your Cloud Storage: Open WPS Office, navigate to the 'Cloud' section, and log in to your preferred cloud storage service to access your documents.
- 3. Start Creating and Editing: Open any existing Microsoft Office file or start a new document, spreadsheet, or presentation using the intuitive tabbed workspace.

Frequently Asked Questions
Why am I getting an 'Access Denied' error when running Set-SPOUser?
This error typically occurs if your account lacks SharePoint Administrator or Global Administrator privileges in Microsoft 365, or if you connected to the standard SharePoint URL instead of the '-admin.sharepoint.com' administration URL during the Connect-SPOService step.
Can I use Get-MsolUser to grant OneDrive permissions?
No. MSOnline commands like Get-MsolUser are legacy Azure AD commands used strictly for querying or managing basic user identity information. They cannot manage permissions for SharePoint or OneDrive site collections.
How do I remove my administrator access from the user's OneDrive later?
You can remove your access by running the exact same Set-SPOUser command used to grant access, but change the parameter at the end to '-IsSiteCollectionAdmin $false'.
Is it possible to grant access to all users' OneDrives at once?
Yes, but it requires writing a PowerShell script that loops through all personal sites. You would use 'Get-SPOSite -IncludePersonalSite $true -Limit All -Filter "Url -like '-my.sharepoint.com/personal/'"' and then apply the 'Set-SPOUser' command to each site URL in the loop.




