Administrative Units

Tags
Azure Active Directory
Created Time
Jul 2, 2022 11:43 AM

Objective

Create an administrative unit for Sales in Vancouver offices
User “Ford Harvey” will be the helpdesk administrator only for the sales group users in Vancouver

Process

We will create an administrative unit for “Sales - Vancouver”
notion image
Select the Role Helpdesk Administrator and select Ford Harvey from the users
notion image
notion image
To add members dynamically into the group we can click on properties and change membership type to dynamic similar to how we create groups
notion image
We set the dynamic query similar to how we set up the group dynamic membership
Documentation: Dynamic Assignment
notion image
đź’ˇ
In an administrative unit, adding a group into the administrative unit does not allow the administrator of that AU to perform administrative tasks to members within that group. This is why members must be added in separately.

Conclusion

The administrative unit for “Sales - Vancouver” has been created
Members are automatically added to the group based on the dynamic membership rule
notion image
If we go to roles and administrators we can see that Ford Harvey is assigned as the Helpdesk administrator for this AU
notion image
Logging on as Ford Harvey we can perform a password reset on members in the AU.
We can reset the password for “Meta Sporer” which can be seen above to be a member of the AU.
notion image
However, if we try to change the password of “Martin Crooks” who isn’t in the Sales - Vancouver group, but in the “Sales - Surrey” group, we’ll see that the option is greyed out.
notion image