Updated: October 2026
Somebody on your team has more admin rights than their job needs. They probably got them on day one because it was quicker than working out what they needed. Role-based access control (RBAC) is how you fix that without reviewing every account by hand, and this guide shows how it works in Entra, Microsoft 365 and the tools your techs log into every day.
What Is RBAC?
RBAC, or role-based access control, is a way of granting access where permissions belong to roles and people get roles. A helpdesk tech gets the "password reset" role, not a list of 40 separate rights. When someone changes jobs, you swap their role and every permission follows.
That's the whole idea. You manage a short list of roles instead of a long list of people.
The model rests on three rules, the ones security exams like to ask about:
- Role assignment. A person can only use a permission if they hold a role.
- Role authorization. The role a person uses has to be one they've been approved for.
- Permission authorization. A person can only use permissions their active role allows.
In plain terms: no role, no access. And the role decides the access, not the person asking for it.
RBAC in the Tools You Already Run
The theory pages stop at "users, roles, permissions". In practice you meet RBAC in three places every week.
Microsoft Entra ID. Entra ships over 65 built-in roles, per Microsoft's own guidance, updated June 2026. There are roles for users and groups, and roles for Exchange, SharePoint and Intune. If none fits, you can build a custom role, and administrative units let you scope a role to one region or department. A regional helpdesk admin can reset passwords for their office and nobody else's.
Microsoft 365 admin roles. These are the same Entra roles, shown in the Microsoft 365 admin center. The trap is Global Administrator. It's the default for whoever set up the tenant, and it can change almost everything.
Your RMM and help desk. Technician roles decide who can run scripts, open remote sessions, see which clients and approve patches. A tier-1 tech who only needs remote control shouldn't be able to push a script to every endpoint.
For MSPs there's a fourth place: partner access to client tenants. Microsoft replaced the old delegated admin model, which handed partners Global Admin, with granular delegated admin privileges (GDAP). Partners now request specific roles for a set period. In this r/msp thread, a customer lists 13 admin roles their licensing supplier holds and asks which ones they need. The replies point to Microsoft's list of least-privileged roles by task.
Least Privilege Is the Point
RBAC is the mechanism. Least privilege is the goal: each person gets exactly the access their job needs, over the narrowest scope, for the shortest time.
Microsoft puts numbers on it. Its Entra best-practice guidance recommends fewer than five Global Administrators, fewer than ten privileged role assignments, and two cloud-only emergency access accounts kept for break-glass situations. Entra shows a warning card once you pass those thresholds, which makes it a quick check in any tenant.
The reason is simple. A compromised account can only do what its role allows. The Verizon 2025 DBIR found stolen or abused credentials were the first step in 22% of breaches. When the account an attacker lands on is a password-reset role, that's a bad day. When it's a Global Admin, it's the whole tenant.
Standing access is the other half. Privileged Identity Management (PIM) makes someone eligible for a role instead of holding it permanently. They activate it when needed, for a set time, and it drops off by itself.
This r/sysadmin thread is a good reminder of how often the opposite happens. A new hire gets full domain admin in their first week. One of the top replies asks whether anyone else is unsurprised he got domain admin right away, because it happens that often.
For the admin accounts themselves, our guide to privileged access management covers vaulting, session recording and the tools that do it.
RBAC vs ABAC, and When Roles Stop Scaling
RBAC has one well-known failure: role explosion. Every exception becomes a new role. "Helpdesk, but can also manage the Paris printers" turns into its own role, then another, until nobody knows what half the roles do.
Attribute-based access control (ABAC) answers a different question. Instead of "what's your role", it asks "what's true right now": your department, your device, your location, the data's sensitivity. It's more flexible and harder to audit.
You rarely have to pick one. Entra already layers them: roles decide what an admin can do, and Conditional Access checks device and location before the role works. Start with roles. Add attributes where the exceptions pile up.
How to Set Up RBAC for an IT Team
You don't need a project plan. You need an afternoon and the admin portals.
- List who holds what. Export every admin role assignment in Entra and your RMM. Everything else builds on this list.
- Define roles by job, not by person. Tier-1, tier-2, security, billing. If a role has one member, it's probably a person, not a job.
- Assign roles to groups. Add people to a group and give the group the role, so onboarding and offboarding are one change.
- Split daily and admin accounts. Email and browsing on one account, admin work on another.
- Make privileged roles eligible, not permanent. Use PIM, or your tool's equivalent, for anything that can change security settings.
- Review quarterly. Microsoft recommends recurring access reviews, because people move teams and quietly collect access.
- Keep two break-glass accounts. Cloud-only, excluded from normal sign-in rules, tested and locked away.
On endpoints, the same thinking applies to local admin rights. Our endpoint privilege management guide covers removing local admin without flooding the help desk.
This short explainer from Mike Chapple covers the model, and it's a good one to send a non-technical colleague.
Give AI Agents a Role Too
The newest accounts in your environment aren't people. AI agents that restart services, run scripts or reset passwords need a role like any tech, and the same rules apply: the narrowest scope that does the job, and a human approval for anything risky.
Ask two questions of any agent before it touches production. What can it change on its own? And where is the record of what it did? In OpenFrame, Flamingo's open, AI-native infrastructure layer for IT and security, nothing risky runs without a tech's approval, and every action is logged. Our IT automation guide covers the full set of guardrails.
Start With the Export
RBAC comes down to one habit: give access to roles, give roles to people, and check the list on a schedule. Microsoft's own thresholds are a good first target: fewer than five Global Admins, fewer than ten privileged assignments.
Pull the role export this week and count. For the next layer, read how RMM security protects the tool that can touch every endpoint you manage.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
