You are a Global Administrator for a Microsoft Entra ID tenant.
You need to delegate the management of a group of users in the Sales department to a local administrator named Admin1. Admin1 has no directory-wide roles. Admin1 must be able to update user profiles and manage group memberships for the Sales department.
Additionally, you need to implement group-based licensing for the Sales department users using a Microsoft 365 license. The configuration must prevent any license assignment errors due to missing user properties.
Which sequence of actions should you perform to meet these requirements?
- 1Create the Administrative Unit and add the Sales department users to it.
- 2Assign the User Administrator and Groups Administrator roles to Admin1, scoped to the Administrative Unit.
- 3Have Admin1 configure the Usage Location property for the Sales department users.
- 4Have Admin1 create a security group and add the Sales department users to it.
- 5As a Global Administrator, assign the Microsoft 365 licenses to the security group.
Answer
First, create the Administrative Unit and add the Sales department users to it. Second, assign the User Administrator and Groups Administrator roles to Admin1 scoped to the Administrative Unit. Third, have Admin1 configure the Usage Location property for the Sales department users. Fourth, have Admin1 create a security group and add the Sales department users to it. Finally, as a Global Administrator, assign the Microsoft 365 licenses to the security group.
The correct sequence begins by creating the Administrative Unit and adding the target users to it, which establishes the administrative boundary. Next, the User Administrator and Groups Administrator roles are assigned to the local administrator scoped to the Administrative Unit, giving them the necessary permissions to manage the users and groups. The local administrator then configures the Usage Location for the users to satisfy the license prerequisite. Afterward, the local administrator creates the security group and adds the users. Finally, the Global Administrator assigns the licenses to the security group because license assignment requires tenant-wide permissions that cannot be scoped to an Administrative Unit.
Step-by-Step Solution
Key Concept
Delegating administration via Microsoft Entra ID Administrative Units and configuring group-based licensing prerequisites.
Estimated Time:2m 0s