Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A global enterprise has a highly distributed IT team. They need to delegate administrative control over specific user groups and their associated applications to regional administrators, without granting them tenant-wide administrative privileges. For example, the European team should only manage European users and applications. Which Azure AD feature is best suited for this requirement?
- AAzure AD Privileged Identity Management (PIM)
- BAzure RBAC for resource groups
- CAzure AD Administrative Units (AUs)
- DAzure AD Custom Roles
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Administrative Units (AUs)
Administrative Units (AUs) allow for granular delegation of administrative rights over a specific subset of users, groups, or devices. This is ideal for scenarios where regional administrators need to manage only their specific entities without tenant-wide permissions.
Why the other options are wrong
- A. Azure AD Privileged Identity Management (PIM) focuses on just-in-time access and approval workflows for privileged roles, not for delegating scope-limited administrative control over directory objects.
- B. Azure RBAC for resource groups is for managing access to Azure resources (like VMs, storage accounts) within subscriptions, not for managing Azure AD user or group objects.
- D. Azure AD Custom Roles define specific permissions, but they don't inherently scope those permissions to a subset of users or groups within the directory.
Azure AD Administrative Units (AUs)
Azure AD containers that allow you to logically group users, groups, or devices and then delegate administrative permissions over only those objects.
- Enables granular delegation of directory administration.
- Prevents granting tenant-wide admin rights.
- Useful for large organizations with distributed IT teams.
Memory trick: Administrative Units are like creating mini-departments within your big company directory.