אירוע
9 באפר׳, 15 - 10 באפר׳, 12
קוד העתיד עם בינה מלאכותית והתחברות לעמיתים ומומחים של Java ב- JDConf 2025.
הירשם כעתהדפדפן הזה אינו נתמך עוד.
שדרג ל- Microsoft Edge כדי לנצל את התכונות, עדכוני האבטחה והתמיכה הטכנית העדכניים ביותר.
חשוב
Restricted management administrative units are currently in PREVIEW. See the Product Terms for legal terms that apply to features that are in beta, preview, or otherwise not yet released into general availability.
Restricted management administrative units allow you to protect specific objects in your tenant from modification by anyone other than a specific set of administrators that you designate. This allows you to meet security or compliance requirements without having to remove tenant-level role assignments from your administrators.
Here are some reasons why you might use restricted management administrative units to help manage access in your tenant.
הערה
Placing objects in restricted management administrative units severely restricts who can make changes to the objects. This restriction can cause existing workflows to break.
Here are the objects that can be members of restricted management administrative units.
Microsoft Entra object type | Administrative unit | Administrative unit with restricted management setting enabled |
---|---|---|
Users | Yes | Yes |
Devices | Yes | Yes |
Groups (Security) | Yes | Yes |
Groups (Microsoft 365) | Yes | No |
Groups (Mail enabled security) | Yes | No |
Groups (Distribution) | Yes | No |
For administrators not explicitly assigned at the restricted management administrative unit scope, operations that directly modify the Microsoft Entra properties of objects in restricted management administrative units are blocked, whereas operations on related objects in Microsoft 365 services aren't affected.
Operation type | Blocked | Allowed |
---|---|---|
Read standard properties like user principal name, user photo | ✅ | |
Modify any Microsoft Entra properties of the user, group, or device | ❌ | |
Delete the user, group, or device | ❌ | |
Update password for a user | ❌ | |
Modify owners or members of the group in the restricted management administrative unit | ❌ | |
Add users, groups, or devices in a restricted management administrative unit to groups in Microsoft Entra ID | ✅ | |
Modify email and mailbox settings in Exchange for the user in the restricted management administrative unit | ✅ | |
Apply policies to a device in a restricted management administrative unit using Intune | ✅ | |
Add or remove a group as a site owner in SharePoint | ✅ |
Only administrators with an explicit assignment at the scope of a restricted management administrative unit can change the Microsoft Entra properties of objects in the restricted management administrative unit.
User role | Blocked | Allowed |
---|---|---|
Global Administrator | ❌ | |
Tenant-scoped administrators (including Global Administrator) | ❌ | |
Administrators assigned at the scope of restricted management administrative unit | ✅ | |
Administrators assigned at the scope of another restricted management administrative unit of which the object is a member | ✅ | |
Administrators assigned at the scope of another regular administrative unit of which the object is a member | ❌ | |
Groups Administrator, User Administrator, and other role assigned at the scope of a resource | ❌ | |
Owners of groups or devices added to restricted management administrative units | ❌ |
Here are some of the limits and constraints for restricted management administrative units.
Applications can't modify objects in restricted management administrative units by default. To grant an application access to manage objects in a restricted management administrative unit, you must assign a Microsoft Entra role to the application at the scope of the restricted management administrative unit. If you assign Microsoft Graph application permissions to the application, those permissions won't apply because it's restricted.
Restricted management administrative units require a Microsoft Entra ID P1 license for each administrative unit administrator, and Microsoft Entra ID Free licenses for administrative unit members. To find the right license for your requirements, see Comparing generally available features of the Free and Premium editions.
אירוע
9 באפר׳, 15 - 10 באפר׳, 12
קוד העתיד עם בינה מלאכותית והתחברות לעמיתים ומומחים של Java ב- JDConf 2025.
הירשם כעתהדרכה
מודול
ניהול זהויות Microsoft Entra - Training
מודול זה מאפשר לך לטפל במשימות של Microsoft Entra ID, כולל RBAC, ניהול משתמשים/קבוצות, רכיבי cmdlet של PowerShell וסינכרון אובייקטים של AD DS. לאחר השלמת מודול זה, תוכל להשתמש במזהה Microsoft Entra ולנהל אותו ביעילות.
אישור
Microsoft Certified: Identity and Access Administrator Associate - Certifications
להדגים את התכונות של Microsoft Entra ID כדי לבצע מודרניזציה של פתרונות זהות, ליישם פתרונות היברידיים וליישם פיקוח על זהות.