What is the difference between an administrator, account owner and ordinary user?¶
The account owner holds the service relationship, an administrator manages a defined part of the environment, and an ordinary user works within assigned permissions. One person may occupy more than one role, but each role supports a different proposition and can change over time.
One deleted file, three different relationships¶
Northstar pays for a Microsoft 365 tenant. Priya holds a Microsoft Entra administrative role over a group of users. Dave has ordinary access to a SharePoint project folder. At 14:18, the provider records deletion of budget-draft.xlsx by Dave's user object.
Northstar's subscription establishes the customer relationship. Priya's role establishes a class of administrative capability. Dave's permission explains why his account could reach the file. The 14:18 event is the evidence that begins to answer which account route acted.
A role describes a relationship or capability. An event records activity. Keep both on the relevant timeline.
Read each role at the right level¶
| Role | What it can establish | Representative record | Useful next comparison |
|---|---|---|---|
| Account owner or customer | Which person or organisation contracted for the environment | Subscription, tenant and billing identifiers; start/end dates | Contract, payment and tenant-administration records |
| Administrator | Which identity could perform defined management actions | Role name, scope, assignment period and role-change event | Audit event, support ticket and administrator session |
| Ordinary user | Which identity could use a resource within assigned permissions | User/object ID, group membership, sharing grant and permission period | Resource event, session and device record |
| Event actor | Which account or application context the system associated with one action | Operation, actor, target, result, timestamp and correlation/request ID | Authentication, session, application and local-device evidence |
The same person may move between rows. Dave might own a personal OneDrive subscription, administer a volunteer group's workspace and use Northstar's tenant as an ordinary employee. Record the provider, tenant, exact role and relevant period rather than describing Dave simply as “the owner” or “an admin”.
Capability is useful evidence - but it is not an event¶
A historical role assignment can exclude impossible routes and identify plausible ones. If Priya's role ended before the deletion, that matters. If her role allowed user management but not SharePoint content deletion, that matters too. If a role change occurred minutes before the file event, the two records form a focused line of enquiry.
The administrator explainer examines role, capability and action in more depth. For an ordinary user, the equivalent discipline is to distinguish permission from use: access to the folder explains possibility, while the provider event and cloud session address activity.
Current provider examples - checked 2 September 2026
Microsoft Entra role-based access control assigns roles at defined scopes, including a tenant, application or administrative unit. Microsoft also says its audit logs can track changes to role assignments and directory objects over time.
Google Workspace similarly makes an administrator's controls depend on assigned privileges; its current privilege definitions separate user-management operations such as creating, suspending, renaming and resetting users.
Product roles and scopes change. Preserve the exact role definition that applied during the event, not a present-day paraphrase.
State the conclusion as four propositions¶
Northstar owned the tenant. Priya held a recorded scoped administrative role. Dave's user object had access to the folder. The provider associated the 14:18 deletion with Dave's account context. The session, device and surrounding records are needed to establish who controlled that context and why the deletion occurred.
The point to remember
Ownership, administrative capability, ordinary permission and recorded activity are separate propositions. Fix each to the relevant time, then follow the event into the session and device evidence.