Pierwsze kroki lub instrukcje dotyczące rozpoczęcia korzystania z witryny pytań i odpowiedzi Microsoft Q&A
Limiting “User Administrator” Role to an Administrative Unit in Entra ID
Hello, in my organization using Entra ID, we have P1 licenses. We’ve structured our environment into several Administrative Units, each with its own assigned administrator. Currently, these administrators can only reset passwords, as they have the "Password Administrator" role.
I would like to extend their permissions so they can also create new user accounts within their assigned Administrative Unit — but without having access to the entire tenant. The issue arises when I assign them the "User Administrator" role and limit the scope to a specific Administrative Unit — the administrator still sees all users in the organization, not just those assigned to their unit.
Is there a way to limit both visibility and account creation permissions strictly to the scope of the assigned Administrative Unit, similar to how it works with password resets?