The problem most SMBs are actually trying to solve
Microsoft 365 admin tasks fall into two buckets: workflow knowledge (who's being hired, what department, which licenses they need) and technical execution (the actual admin-center clicks to make it happen).
In most SMBs, HR has the workflow knowledge and IT has the technical permissions. The gap between them is the ticket queue. HR opens a ticket: "New hire Sarah starting Monday, needs Sales tools." IT picks it up two days later. Sarah's laptop is already on her desk; her email isn't.
The delegation question is: how do you give HR the technical execution without giving them Global Admin (or accidentally giving them access to things they shouldn't touch, like Conditional Access or billing)?
Six real answers below, in roughly the order they make sense for an SMB with 20-500 employees. K-12 IT teams have a similar problem with slightly different constraints — dedicated section near the end.
Quick comparison
| Feature | Approach | Cost | UI built for HR? | Per-delegate audit | Setup time |
|---|---|---|---|---|---|
User Administrator role | User Admin role | Free | No | Unified log (queryable) | 1 min |
Helpdesk Administrator role | Helpdesk Admin role | Free | No | Unified log (queryable) | 1 min |
Custom RBAC + Admin Units | Custom RBAC | Free | No | Unified log (queryable) | 30+ min to define |
UserDesk for M365 | UserDesk | $79/mo Starter | Yes | Built-in per delegate | ~2 min |
JumpCloud M365 module | JumpCloud | $9/user/mo (full platform) | Identity-platform UI | Built-in | Hours (full IDM setup) |
Manual ticket workflow | Tickets only | Free (your time) | N/A (HR doesn't act directly) | Ticket trail | None |
Table verified
The six approaches in detail
Ranked by suitability for the typical 20-500 employee SMB. Right answer depends on your specific delegate, your tolerance for admin-center exposure, and your budget.
UserDesk for M365
Purpose-built for this specific delegation case. The only tool on this list that was designed to be handed to HR.
- Best for
- SMBs whose HR or office manager regularly handles new hires, password resets, license changes, group/distribution-list membership — and you want them doing it without ever seeing the Admin Center.
- Cost
- $79/mo Starter (up to 50 M365 users + 3 portal admins). $149/mo Pro (unlimited). 14-day free trial, no card.
What it is: a focused web portal with three role tiers (Admin / Member / Viewer). HR gets Member, sees a clean users list with scoped actions: reset password, create user from template, manage licenses, add/remove from Teams/distribution lists, disable account. The Admin Center isn't exposed at all — there's no path from UserDesk into Conditional Access, billing, DNS, etc.
Strengths for HR delegation specifically:
- UI designed for non-IT users — no training needed
- Mobile-first (HR doing a password reset from a phone is common)
- Onboarding templates pre-fill licenses, groups, dept, title per role ("Sales Rep" → done)
- Per-delegate audit log — "what did Megan in HR do this week?" is one filter
- Hard scope — there's no way for HR to accidentally affect tenant settings
- 2-minute setup via Microsoft OAuth consent
Where it falls short:
- Costs $79/mo — not free
- No CSV bulk operations (use Admin Center for migrations)
- No deep reporting (use AdminDroid alongside if you need it)
- SaaS-only (no on-prem option)
When to pick this: when your delegate is genuinely non-IT and you want a tool they'll use without ongoing IT support. The 14-day trial is the honest test — put it in front of your HR person; if they can't use it without a 10-minute walk-through, we've failed at our stated job.
Approach details verified
M365 User Administrator role assignment
Microsoft's built-in answer. Free, supported, and wrong for non-IT delegates.
- Best for
- Orgs where the delegate is IT-fluent (helpdesk, IT-adjacent ops staff) and is comfortable with the Microsoft 365 Admin Center UI.
- Cost
- Free (included with M365).
What it is: assign the User Administrator role to HR via Microsoft Entra → Roles & administrators. They get permissions to create/delete users, reset passwords, assign licenses, manage group membership. Microsoft's officially supported delegation answer.
Strengths:
- Free, no third-party dependencies
- Microsoft-supported, well-documented
- Permission set is correct for HR work
- 1-minute setup
Where it falls short for non-IT HR:
- Gives them full access to the M365 Admin Center UI — overwhelming for HR
- Settings → Org settings, Service health, Billing all visible (mostly read-only but visible)
- No per-delegate audit view; you query the unified log
- No onboarding templates — manual fill per new hire
- Mobile experience is functional, not designed
When to pick this: when your delegate is IT-adjacent (helpdesk technician, IT-savvy ops manager) and the Admin Center isn't a UX problem for them. Read the dedicated User Administrator role vs UserDesk comparison for the deep dive.
Approach details verified
M365 Helpdesk Administrator role assignment
Narrower than User Admin. The right native role if password resets are the only workflow.
- Best for
- Orgs where HR's only M365 task is password resets — no new hires, no license changes, nothing else.
- Cost
- Free (included with M365).
What it is: Helpdesk Administrator role — limited to password resets + invalidating refresh tokens for non-admin users. Narrower scope than User Administrator.
Strengths:
- Free
- Lower blast radius than User Administrator — narrower permissions
- 1-minute setup
Where it falls short:
- Same UI surface problem — full Admin Center exposed
- Can't create users; can't manage licenses; can't manage group membership
- If HR also handles onboarding, you outgrow this role immediately
When to pick this: as a narrow stopgap when you only need password reset delegation and want to keep scope minimal. Outgrows itself the moment you add any other workflow.
Approach details verified
Custom RBAC role + Administrative Units
The Microsoft-native answer when User Admin is too broad. Powerful, free, and a real configuration effort.
- Best for
- IT teams comfortable with Microsoft Entra who want to scope HR's permissions exactly (e.g. limit to specific department, specific actions).
- Cost
- Free. Requires Microsoft Entra ID P1 license for some features (often included in M365 Business Premium and above).
What it is: Microsoft Entra supports custom role definitions with granular permission picking, combined with Administrative Units that scope the role to specific users/groups (similar to AD OUs). You can build "HR password-reset role" scoped to "Sales department users only."
Strengths:
- Free (P1 license required for Admin Units; often already in your plan)
- Genuinely granular — pick exact permissions, scope to exact users
- Microsoft-supported
- Composes with other native roles
Where it falls short:
- Real configuration time — defining roles + AUs is 30+ minutes
- Maintenance burden — when org structure changes, AUs need updating
- UI surface still exposed — delegate lands in Admin Center, just with more things greyed out
- Per-delegate audit still requires unified log queries
When to pick this: when you need permission scoping more granular than the built-in roles offer, the delegate is comfortable with the Admin Center UI, and budget won't cover $79/mo. Otherwise the configuration burden usually isn't worth it.
Approach details verified
JumpCloud (M365 module)
Right answer if you're already shopping for a full identity platform. Wrong answer if M365 delegation is the only thing you're solving.
- Best for
- Orgs that want a full identity directory (replacing or augmenting Active Directory) with M365 user provisioning included as one feature among many.
- Cost
- JumpCloud Platform pricing per-user, ~$9/user/mo for the most common bundle. M365 features included in the full platform.
What it is: an identity platform (often positioned as "cloud Active Directory") that includes M365 user provisioning, SSO, MFA, device management. HR could delegate via JumpCloud's admin UI.
Strengths:
- Full identity platform — solves multiple problems at once
- Cross-platform device support (Windows, macOS, Linux)
- One identity directory across many SaaS tools
- Reasonable per-user pricing if you're using the full platform
Where it falls short for HR-delegation specifically:
- You're buying full IDM — paying for M365 mgmt as a slice
- If you're happy with Entra ID as your directory, JumpCloud is overkill
- UI is identity-platform-style, not built specifically for non-IT delegates
- Setup is hours, not minutes
When to pick this: when you're shopping for a full identity platform anyway. Don't buy JumpCloud solely for M365 delegation; that's a $9/user/mo answer to a problem UserDesk solves for $79/mo flat per tenant.
Approach details verified
Manual ticket workflow (no tool, HR opens tickets)
The default state. Cheapest in dollars, expensive in IT time and HR frustration.
- Best for
- Very small orgs where M365 admin tasks are rare enough that 'open a ticket' actually works.
- Cost
- Free (your time + HR's wait + tickets per week).
What it is: the default. HR opens a ticket; IT works it; HR follows up when it's done. The work still happens — just with extra latency and IT-context-switch cost.
Strengths:
- Free in dollars
- Zero setup
- IT keeps full control + visibility
Where it falls short:
- IT becomes the bottleneck for every routine HR request
- New hires sit at empty desks waiting for accounts
- Password resets take hours instead of seconds
- Real cost: ~1-3 hours/week of IT time at $80-120/hr loaded
- HR/leadership frustration compounds; eventually triggers a Global Admin handoff that's worse
When to pick this: only if M365 admin tasks are genuinely rare (small org, low churn). At even a few requests per week, every other approach on this list pays for itself in IT time saved.
Approach details verified
Verdict for the typical SMB
For a 20-500 employee SMB whose HR person handles routine M365 work, the honest ranking is:
- UserDesk — purpose-built for this exact case. The UX gap between "HR uses the Admin Center with User Administrator role" and "HR uses UserDesk" is the entire reason we built it. $79/mo, 14-day trial.
- Custom RBAC role + Admin Units — if budget is genuinely zero and you have the time to configure it properly. Trade money for setup hours.
- User Administrator role (or Helpdesk Admin if narrower) — if HR is IT-fluent enough that the Admin Center isn't a UX problem.
- Manual ticket workflow — if M365 admin tasks are genuinely rare. Once they're weekly or more frequent, this option is the most expensive of the six in real terms.
JumpCloud doesn't belong on this list if M365 delegation is your only problem — it's the right answer to a different, broader question.
For K-12 IT teams
What changes when the delegate is a school secretary or principal
K-12 districts have the same delegation problem with different specifics. Building-level secretaries handle a huge volume of staff and student M365 work — onboarding new teachers in August, password resets for students at every grade level, distribution lists per class. Your IT team is typically one to three people for the whole district.
What's different vs the SMB case:
- Student data sensitivity. FERPA and (for students under 13) COPPA add real consequences to mis- delegation. The narrower the delegate's scope, the better.
- Seasonal scale. August onboarding waves are 10-100x your normal volume. Tools that scale to bulk operations matter more here than in most SMBs.
- Building-level delegation. You often want secretary at School A managing only School A's users — not Schools B-G. Administrative Units in Microsoft Entra are the native answer for this scoping; most third-party tools support some form too.
- State reporting + audit retention. Many states require admin action audit logs retained for multiple years. Whatever tool you pick, confirm its audit export + retention model.
- Budget reality. District budgets are quarter-by-quarter and often require purchase orders. Free + native is the default; SaaS tools under ~$200/mo can usually be expensed; anything more goes through procurement.
K-12-specific guidance on the six approaches:
- UserDesk + Admin Units (or per-tenant scoping): works if your district uses one M365 tenant for all schools (most do). Each building's secretary gets portal access scoped to their building's users via the Member role + group scoping. Single-tenant pricing ($79/mo) makes it expensible for the district.
- Custom RBAC + Administrative Units: the free path. Real configuration effort but probably worth it at the district level — set up once, applies across many delegates. Has the same UI exposure problem as plain User Admin.
- SaaS HR platforms (Rippling, BambooHR with M365 module): attractive in K-12 because they cover HR onboarding + M365 + payroll in one tool. Pricier than focused tools but the bundle math can work for districts.
UserDesk works in K-12 EDU tenants the same way it works in commercial M365 — Microsoft OAuth only, no student data ever leaves your tenant, audit log per delegate. If you want to talk through a K-12 specific rollout (FERPA implications, building-level scoping, summer onboarding wave), the founder's Calendly is here.
Implementation guide: rolling out HR delegation at a 50-person company
Whichever approach you pick, the rollout pattern is roughly the same. Here's what works:
- Pick the workflow to delegate first. Don't start with "everything HR could possibly do." Start with password resets (highest volume, lowest risk). Add new-hire creation after 2-4 weeks of password-reset delegation working smoothly.
- Pick the delegate person specifically. Not "HR" in the abstract — name the person. Their comfort with technology determines which tool is viable. Watch them attempt one task before committing.
- Onboarding templates first. If you're using a tool with templates (UserDesk, ManageEngine), define them BEFORE handing the tool to HR. New hire friction comes from missing licenses + groups, not from the user-creation step itself.
- Audit log review cadence. Set a 15-min weekly review for the first month. Most concerns evaporate after you watch a few weeks of activity and see the work is bounded + correct.
- Document the escalation path. HR will hit edge cases (locked admin account, account they can't see, weird license state). Make sure they know exactly when to escalate to IT vs try to handle it themselves.
Frequently asked questions
Q01Why not just use a custom RBAC role with Administrative Units?
It's a legitimate free option that scopes permissions properly. The catch: it doesn't change the UI surface. The delegate still lands in the Microsoft 365 Admin Center showing all the panels they can see but can't fully act on. If your HR person is IT-fluent enough that the broader admin center isn't a UX problem, custom RBAC + Admin Units is genuinely the cheapest right answer. If your HR person needs a UI that's clearly designed for them, you need a focused tool.
Q02What if HR makes a mistake and disables the wrong account?
Two layers of protection on UserDesk specifically: (1) the action set is small and bounded — the delegate can disable a user but can't delete the mailbox or change tenant settings, so misclicks have small blast radius; (2) every action is logged with timestamp + actor in the per-delegate audit log, so a wrong disable is a 30-second re-enable once you spot it. Native roles + Admin Center have the same audit data but it's buried in the unified audit log rather than surfaced for review.
Q03Can HR reset passwords for users in admin roles?
By default, no — Microsoft updated the User Administrator and Helpdesk Administrator roles in 2024 to prevent password resets for users holding protected admin roles (Global Admin, Privileged Role Admin, etc.). This is a good security default. UserDesk respects the same restriction — even an Admin-tier UserDesk user can't reset a Global Admin password via the portal.
Q04Does this work for K-12 with FERPA / student data concerns?
UserDesk uses Microsoft OAuth only — student data never leaves your M365 EDU tenant. Our database stores billing metadata + audit logs (action: "reset password for student@district.edu", actor: "secretary@district.edu", timestamp). We never see student PII, grades, IEPs, or any educational record. For most district FERPA reviews, this maps cleanly to "no third party processes student records." See the dedicated K-12 section above for the longer take.
Q05What if HR refuses to use a new tool?
Common pushback. Two things usually work: (1) demo it with the HR person in the room before committing — UserDesk's 14-day trial is the honest way; if they aren't comfortable in 5 minutes we're doing it wrong; (2) start with one workflow (password resets) before adding more. HR resists "learning a system"; they don't resist "this one button does the password reset thing you've been waiting on tickets for." Once that habit forms, adding new-hire creation is incremental.
Q06What about Okta Workflows or Workato for HR-triggered M365 provisioning?
Different category. Orchestration platforms automate workflows that IT builds — they don't put a portal in front of HR. HR triggers the workflow via a form or HRIS event; the platform does the M365 work in the background. Great for high-automation orgs (especially if you already use Okta for SSO); less direct than "HR logs into a portal and clicks reset." Many orgs use both.
Q07How is per-delegate audit different from the unified audit log?
The unified audit log captures everything (all activity across the tenant, all users, all services). It's powerful but firehose-y. To answer "what did Sarah in HR do this week," you'd open Microsoft Purview, set date range, filter by Sarah's UPN, filter by activity type, run the query, possibly export to CSV. UserDesk's per-delegate view shows only the actions taken through the portal, defaults to per-delegate filter, and is one click from the Audit page. Same underlying data philosophy, different ergonomics.
Try it
Free 14-day trial — no card
Connect your Microsoft 365 tenant in 2 minutes. Hand the portal to HR or your team leads. Cancel any time.
Free checklist
M365 Delegation Checklist
What to delegate, what to keep, and how to set it up without breaking your tenant.