In Azure AD, how do we give rights to an admin just on a specific group of people? (Like a little enterprise in another bigger)

Maxime Tremblay 1 Reputation point
2022-02-11T14:51:19.35+00:00

Example : I want to give admin rights to someone, but only on the students of a school.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2022-02-11T20:20:37.387+00:00

    Hello @Maxime Tremblay ,

    I understand that you are looking to give admin rights to an admin to manage a specific group of users.

    The best solution for this in Azure AD is Administrative Units. Administrative Units provide a way to delegate administration using role-based access control to a subset of Azure AD users or groups. You can, for example, use administrative units to delegate the Helpdesk Administrator role to support regional specialists so they can manage users only in the region they support.

    The full list of supported administrative unit scenarios is documented in Administrative units in Azure Active Directory. You can also use My Staff, which is based on administrative units and enables you to delegate permissions to a figure of authority, such as a store manager or a team lead.

    Note that you do need an Azure AD Premium P1 or P2 license for each administrative unit administrator.

    Resources:
    Create or delete administrative units
    Manage your users with My Staff
    Delegate app registration permissions in Azure Active Directory

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.