Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A global organization uses Azure AD for its workforce identities. They have several departments, each with its own IT administrators responsible for managing user accounts and groups within their department. The central IT team wants to delegate these administrative tasks without granting global administrator privileges or custom roles that span the entire directory. They need a solution that allows departmental IT admins to manage users and groups only within their specific department's scope. Which Azure AD feature should be used?
- ACustom Azure AD roles
- BAzure Management Groups
- CAzure AD Privileged Identity Management (PIM)
- DAzure AD Administrative Units (AUs)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Administrative Units (AUs)
Azure AD Administrative Units (AUs) allow for granular delegation of administrative rights over subsets of users and groups. This directly enables departmental IT admins to manage only their specific department's resources without broader permissions.
Why the other options are wrong
- A. While custom roles can be created, without Administrative Units, these roles would apply tenant-wide, or require complex filtering that is less efficient than AUs for departmental delegation.
- B. Azure Management Groups are used to manage access, policies, and compliance for Azure subscriptions, not for delegating user/group management within Azure AD.
- C. PIM is for managing just-in-time access for privileged roles, not for defining the scope of administrative delegation for departmental IT admins.
Azure AD Administrative Units (AUs)
Administrative Units in Azure AD allow for the creation of logical containers for users and groups, enabling the delegation of administrative permissions to a defined scope. This allows administrators to manage only a specific subset of the directory, aligning with the principle of least privilege.
- Delegates administrative control over subsets of users and groups.
- Helps implement least privilege for distributed administration.
- Can be assigned to roles like User Administrator, Group Administrator.
- Requires Azure AD Premium P1 license.
Memory trick: Admin Units: Divide and Delegate.