Global Administrator in Microsoft 365 does not automatically give local administrator rights on a Windows PC. That is why the account can be a tenant admin in Microsoft 365 and still get “the requested operation requires elevation” on the device.
For this scenario, use this order of checks:
- Confirm whether the Windows account is a local administrator
Go to Start → type Control Panel → User Accounts → Change your account type.- If Administrator is selected, the account already has local admin rights.
- If it is not selected, the current Windows account is not a local administrator.
- Check whether the PC is joined to a domain or work environment
Open Control Panel → System and Security → System.
At the bottom:- Domain: means the PC is joined to a domain.
- Workgroup: means it is not domain-joined.
- If Office installation is the immediate issue
For Office install prompts or error 0-1005 / 0-2005:- Select Yes on the User Account Control prompt.
- Locate the downloaded Office installer .EXE, right-click it, and select Run as administrator.
- If needed, open Control Panel → Security and Maintenance → expand Security and make sure User Account Control is On.
- If the account is not an administrator
A Windows administrator account on that device is required to approve elevation or change the account type. If the Administrator option cannot be selected, the documented guidance is to contact the person who has administrator rights on the computer and have them either:- grant admin privileges, or
- enter their administrator username and password when prompted.
- If this is a work or school managed account setup
If the device was set up with a work account and there is no usable local administrator, the business or organization admin/help desk is the path Microsoft documents for account/admin recovery. For a sole-owner business, that means identifying whoever originally provisioned or manages the device setup, if anyone did. - If Teams or Microsoft 365 shows admin status but Windows still blocks changes
That is expected behavior. Cloud admin roles and local Windows elevation are separate.
A clean summary of the issue:
- Microsoft 365 Global Administrator = admin for cloud services.
- Windows local administrator = required for software installs and elevated changes on the PC.
- The error indicates the Windows device is not recognizing the signed-in account as having the required local elevation rights.