question

MaximeTremblay-9125 avatar image
0 Votes"
MaximeTremblay-9125 asked MarileeTurscak-MSFT answered

In Azure AD, how do we give rights to an admin just on a specific group of people? (Like a little enterprise in another bigger)

Example : I want to give admin rights to someone, but only on the students of a school.

Thank you.

azure-ad-group-management
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered

Hello @MaximeTremblay-9125,

I understand that you are looking to give admin rights to an admin to manage a specific group of users.

The best solution for this in Azure AD is Administrative Units. Administrative Units provide a way to delegate administration using role-based access control to a subset of Azure AD users or groups. You can, for example, use administrative units to delegate the Helpdesk Administrator role to support regional specialists so they can manage users only in the region they support.

The full list of supported administrative unit scenarios is documented in Administrative units in Azure Active Directory. You can also use My Staff, which is based on administrative units and enables you to delegate permissions to a figure of authority, such as a store manager or a team lead.

Note that you do need an Azure AD Premium P1 or P2 license for each administrative unit administrator.

Resources:
Create or delete administrative units
Manage your users with My Staff
Delegate app registration permissions in Azure Active Directory

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.