Your company has a Microsoft Entra ID tenant. The tenant contains an Administrative Unit named Sales-AU and a dynamic security group named Sales-Dynamic-Group. Sales-Dynamic-Group is a member of Sales-AU.
You assign a user named Admin1 the Groups Administrator role scoped to Sales-AU.
Admin1 attempts to perform the following tasks:
1. Modify the membership of an assigned security group named Sales-Manual-Group that is a member of Sales-AU.
2. Modify the dynamic membership rule of Sales-Dynamic-Group.
Which tasks can Admin1 successfully perform?
- Only task 1Answer
- BOnly task 2
- CBoth task 1 and task 2
- DNeither task 1 nor task 2
Answer
Only task 1
The correct answer is the option stating that only task 1 can be performed. An administrator with the Groups Administrator role scoped to an Administrative Unit (AU) can manage the membership of standard assigned groups that are members of that AU. However, they cannot modify dynamic group rules. Modifying dynamic group rules requires directory-level (tenant-wide) Groups Administrator or Global Administrator privileges because dynamic rules are evaluated tenant-wide, and permitting an AU-scoped administrator to modify them would allow them to bypass the administrative boundary.
Step-by-Step Solution
Key Concept
Administrative Unit scope limits for group management and dynamic group rule modification constraints in Microsoft Entra ID