logo
search
Security Policy Errors

How to Assign Exchange Administrator Roles to Groups Without Mailboxes

Maira MehtabMaira Mehtab Sep 28, 2026 868 views

Question details

The administrator needs to assign granular Exchange role permissions to specific groups of dedicated administrator accounts that do not possess active mailboxes.

Product
Exchange Online / Microsoft 365
Device & OS
not provided
Scenario
Attempting to grant granular Exchange permissions to a group of dedicated admin accounts instead of assigning them the full Exchange Administrator role.
Observed behavior
The Exchange admin center interface only accepts mail-enabled security groups or shared mailboxes for role assignments, rejecting standard non-mailbox groups.
Before you start

Ensure you have Global Administrator or Privileged Role Administrator permissions in your Microsoft 365 tenant to create role-assignable groups.

Solution 1Recommended

Create a Role-Assignable Group in Microsoft Entra ID

Use Microsoft Entra ID to create a specific security group designed for role assignments, bypassing the Exchange admin center's mail-enabled requirement.

Microsoft Entra ID allows the creation of role-assignable groups. This property can only be set during group creation and enables you to assign administrative roles to the group without needing associated mailboxes.

1
Access Microsoft Entra ID

Log in to the Microsoft Entra admin center using an account with Privileged Role Administrator permissions.

2
Create a new group

Navigate to 'Identity' > 'Groups' > 'All groups' and click on 'New group'.

3
Enable role assignment

Set the Group type to 'Security'. Under the 'Microsoft Entra roles can be assigned to the group' setting, toggle the switch to 'Yes'.

4
Add members and assign roles

Add your non-mailbox administrator accounts as members of this group. Once the group is created, navigate to 'Roles and administrators', select the required granular Exchange roles, and assign them to the newly created group.

Licensing Requirement: Creating role-assignable groups in Microsoft Entra ID requires a Microsoft Entra ID P1 or P2 premium license.
Free Microsoft Office alternative

Looking for a Lightweight Office Suite? Try WPS Office

While advanced Exchange server management requires Microsoft 365 administrative tools, for your everyday document, spreadsheet, and presentation tasks, WPS Office provides a powerful, free, and lightweight alternative. Enjoy a familiar tabbed interface and robust features without the heavy subscription costs.

  1. 1. Visit the website: Go to the official WPS Office website to access the free installer.
  2. 2. Download the software: Click the 'Free Download' button to download the lightweight setup file to your computer.
  3. 3. Install and launch: Run the installer, follow the simple on-screen instructions, and launch WPS Office to start managing your documents.
Seamlessly open, edit, and save Microsoft Word, Excel, and PowerPoint file formatsFree and lightweight alternative to Microsoft Office for everyday productivityFamiliar tabbed user interface ensuring a smooth and easy migrationBuilt-in PDF editing tools for comprehensive and efficient document management
microsoft office alternative - wps office

Frequently Asked Questions

Why does the Exchange admin center reject my standard security group?

By default, the legacy and standard interfaces in the Exchange admin center are designed to require mail-enabled security groups or shared mailboxes for role assignments. Standard security groups without mailboxes are not recognized as valid targets in this specific interface.

Can I enable role-assignment for an existing group?

No, the 'Microsoft Entra roles can be assigned to the group' property can only be configured at the time the group is created. You cannot convert an existing standard group into a role-assignable group.

Do I need special licenses to use role-assignable groups?

Yes, creating role-assignable groups in Microsoft Entra ID generally requires a Microsoft Entra ID P1 or P2 premium license, depending on your organization's setup and the specific administrative features you are utilizing.