Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A client has an Azure AD tenant and wants to delegate administrative tasks for managing user accounts (e.g., resetting passwords, blocking users) to help desk personnel, but only for users within specific departments. They want to avoid granting these help desk personnel broad administrative roles like 'User Administrator' across the entire tenant. Which Azure AD feature allows for this granular delegation?
- AAdministrative Units
- BAzure Role-Based Access Control (RBAC)
- CAzure AD Identity Governance
- DAzure AD Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: A. Administrative Units
Administrative Units (AUs) in Azure AD allow you to group users and apply administrative roles to a subset of your organization. This enables granular delegation, so help desk personnel can be assigned a role like 'Password Administrator' but only within the scope of a specific Administrative Unit, preventing them from managing users outside that department.
Why the other options are wrong
- B. Azure RBAC applies to Azure resources (subscriptions, resource groups, resources), not directly to granular delegation of Azure AD user management tasks within the directory.
- C. Identity Governance includes features like Entitlement Management, Access Reviews, and PIM, but Administrative Units are the specific feature for scoping directory administrative roles.
- D. PIM manages just-in-time access for privileged roles, it doesn't create granular scopes for administrative delegation of standard user management tasks.
Azure AD Administrative Units (AUs)
Containers for users and groups that allow for more granular delegation of administrative roles in Azure AD.
- Scopes administrative roles to a subset of users/groups.
- Prevents broad administrative access.
- Supports roles like User Admin, Password Admin, Group Admin.
Memory trick: Admin Units: Administer Unique Sections.