Limiting “User Administrator” Role to an Administrative Unit in Entra ID

Kacper Kołaczkowski 0 Punkty reputacji
2025-04-07T12:53:36.5766667+00:00

Hello, in my organization using Entra ID, we have P1 licenses. We’ve structured our environment into several Administrative Units, each with its own assigned administrator. Currently, these administrators can only reset passwords, as they have the "Password Administrator" role.

I would like to extend their permissions so they can also create new user accounts within their assigned Administrative Unit — but without having access to the entire tenant. The issue arises when I assign them the "User Administrator" role and limit the scope to a specific Administrative Unit — the administrator still sees all users in the organization, not just those assigned to their unit.

Is there a way to limit both visibility and account creation permissions strictly to the scope of the assigned Administrative Unit, similar to how it works with password resets?

Centrum społecznościowe | Omówienie witryny z pytaniami i odpowiedziami Q&A | Wprowadzenie do pytań i odpowiedzi Q&A
Komentarze: 0 Brak komentarzy

Twoja odpowiedź

Odpowiedzi mogą być oznaczone jako „Zaakceptowane” przez autora pytań i „Proponowane” przez moderatorów, co pomaga użytkownikom poznać odpowiedź rozwiązującą problem autora.