---
title: "Manage Admins without Microsoft Global Admin Credentials"
slug: "enterprise-manage-users-without-global-admin"
updated: 2025-08-26T05:56:01Z
published: 2025-08-26T05:56:01Z
canonical: "kb.connecttoteams.com/enterprise-manage-users-without-global-admin"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.connecttoteams.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage Admins without Microsoft Global Admin Credentials

This article explains how to configure any Teams user in your O365 organization without Global Admin role to become an Enterprise Admin in ConnecttoTeams Enterprise Portal.

This could be used in cases wherein you want non-admin employees, such as your IT personnel or operations staff, to manage your operations in the Enterprise Portal.

## Introduction

Enterprises strongly prefer to reserve their Microsoft Global Admin role for use only when necessary. Some certifications (i.e. SOC2) require a very strict control on who has access at the highest level in IT Systems.

**Microsoft Global Admin role is REQUIRED to complete the** [**Enterprise Registration**](/v1/docs/getting-started-as-an-enterprise) **and** [**Direct Routing setup**](/v1/docs/set-up-direct-routing) **as well as the optional Teams Application setup.**

All day-to-day tasks - adding, configuring and deleting End Users - can be performed with delegated Microsoft credentials.

> [!NOTE]
> The Microsoft User with this delegated authority must have Teams Administrator role.

In some Microsoft Enterprises, delegation is a conditional setting that needs to be configured in Azure Active Directory in a process where the Global Admin grants a conditional consent to a delegated admin to a certain task. While time-consuming and inconvenient, this is undoubtedly an effective security measure.

Here is a table of the capabilities of each level of Microsoft roles:

| Portal Tasks | Global Administrator | Teams Administrator |
| --- | --- | --- |
| [Initial Registration](/v1/docs/getting-started-as-an-enterprise) | YES | NO |
| [Setup Direct Routing](/v1/docs/set-up-direct-routing) | YES | NO |
| [Setup / Manage PBX](/v1/docs/pbx-user-guides) | YES | YES |
| Setup / Manage PBX End User Portal | YES | YES |
| Setup / Manage [PBX Feature Codes](/v1/docs/feature-codes-and-cards) | YES | YES |
| Setup / Manage Users | YES | YES |
| Add / Delete Teams Applications | YES | NO |

## **Steps to Provide Delegated Authority**

1. Navigate to [Team Admin Center](https://admin.teams.microsoft.com/) >>**Active Users**.

![](https://cdn.us.document360.io/312e5ae5-e3c1-465d-8e37-f253a7ba8eee/Images/Documentation/image(181).png)
2. Select the subject user (not the Global Admin) and then select **Manage Roles**. ![](https://cdn.us.document360.io/312e5ae5-e3c1-465d-8e37-f253a7ba8eee/Images/Documentation/image(182).png)
3. Select **Admin center access** as seen in the picture below. ![](https://cdn.us.document360.io/312e5ae5-e3c1-465d-8e37-f253a7ba8eee/Images/Documentation/image(183).png)
4. Select **Teams Administrator** and click **Save changes**. ![](https://cdn.us.document360.io/312e5ae5-e3c1-465d-8e37-f253a7ba8eee/Images/Documentation/{1E5E1C76-37DA-4AFA-A1D1-550318651428}.png)

The Microsoft User details will show the **Teams Administrator** in the **Role** as shown below.![](https://cdn.us.document360.io/312e5ae5-e3c1-465d-8e37-f253a7ba8eee/Images/Documentation/{1897E381-B475-4E9C-8F45-6D7694F6E5E9}.png)

When changes are saved, the Microsoft User with these credentials will then be able to access the ConnecttoTeams Enterprise Portal and be able to manage end users as well as the tasks listed in the table above.
