Your organization has a Microsoft Entra ID tenant that contains an administrative unit named Office-AU.
Office-AU contains the following resources:
- A user named Admin1
- An assigned security group named Group1
A user named User1 is created in the Microsoft Entra ID tenant but is NOT a member of Office-AU.
Admin1 is assigned the Groups Administrator role scoped to Office-AU.
Determine if the following statement is true or false: Admin1 can add User1 as a member of Group1.
Answer: Answer
Answer
True
The statement is true because the Groups Administrator role scoped to Office-AU grants Admin1 permission to modify the membership of Group1 since Group1 is within Office-AU. The users being added to the group do not need to be members of the same administrative unit.
Step-by-Step Solution
Key Concept
Groups Administrator role permissions scoped to an administrative unit in Microsoft Entra ID