In this article
  • An introduction to administrative units
  • Manage administrative units
  • How inheritance works for groups in administrative units
  • Administrative units and Privileged Identity Management
  • My Staff portal
  • Limitations of administrative units
  • FAQs

A Complete Guide to Azure AD Administrative Units

28 Oct 2021
|
20 min read
|
Anju George
twitterlinkedin
Blog Articles

Article at a glance

Azure AD Administrative Units (AUs) allow organizations to delegate admin roles with limited scope, reducing the need for global admin access and supporting the principle of least privilege. However, AUs have limitations:

  • AUs can only contain users and groups, not devices. They require Azure AD Premium licenses, and not all administrative roles are available for AUs.

Read more

An introduction to Azure AD administrative units

Why do you need administrative units?

Azure AD without administrative units

Azure AD with administrative units

Manage administrative units in Azure Active Directory

Licensing requirements

Create an administrative unit

create an administrative unit
add azure administrative unit
add administrative unit
add administrative unit

Add users to an administrative unit

add users to azure administrative unit

bulk add users to an administrative unit

Add groups to an administrative unit

add groups to an azure administrative unit

add a group to administrative units

Assign admin roles for an administrative unit

assign admin role for an administrative unit
assign admin roles for azure administrative units

How inheritance works for groups in administrative units

scope of azure administrative unit

azure administrative unit with two users

group inside administrative unit
users inside the group

administrative-unit scoped role

error message

Administrative units and Privileged Identity Management

Key features of Privileged Identity Management 

Assign scoped roles in Privileged Identity Management

assign AU scoped roles in PIM

select assignment type

Administrative units and My Staff portal

How to enable My Staff in Azure Active Directory

manage user feature settings in azure active directory
enable my staff portal

How My Staff works

user administrator for administrative unit

my staff portal
members of an azure administrative unit

How to reset a user password 

reset user password in my staff portal

audit logs

Limitations of administrative units

Frequently asked questions on Azure AD administrative units

In this article
  • An introduction to administrative units
  • Manage administrative units
  • How inheritance works for groups in administrative units
  • Administrative units and Privileged Identity Management
  • My Staff portal
  • Limitations of administrative units
  • FAQs
twitterlinkedin