Can visibility of Entra AD Users and Groups be restricted from Admins

ComputerHabit 1,051 Reputation points
2024-01-04T17:00:13.9466667+00:00

I am attempting to restrict access to admins of Administrative Units to only see in Users and Devices what they have access to.

I have restricted default user access to Azure Portal.
User's image

The account I'm testing with does not have a Global role assigned.

The account does have a custom permission assigned, it is scoped to an Administrative Unit.
The only permission in the role is Read\Delete Device.
User's image

I login with the account assigned to this role. I can still see all Groups and all Users. I can pretty much see everything with the account.

Is there a way to restrict visibility of all the objects not in the AU scope?

I've searched a lot but no luck.

Thanks

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Answer accepted by question author
  1. Vasil Michev 124.9K Reputation points MVP Volunteer Moderator
    2024-01-04T17:43:27.7+00:00

    Technically speaking, you cannot restrict "view" access, even regular accounts get to see all objects within the organization by default. Now, depending on the implementation across the various admin endpoints, you can expect different results. For example, if you login to the Microsoft 365 admin center as user with only an AU-scoped admin role assignment, you will be presented with a trimmed UI, and will only be able to see the users/groups under the AU scope. Logging in to the Azure AD/Entra ID portal with the same user will still display all objects (regardless of the setting you toggled), as technically this is a user with an admin role. He will still only be able to make changes against objects within the scope of the AU, but visibility cannot be restricted.

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.