Your company wants to delegate user administration tasks, such as resetting passwords, for users in the marketing department only. The delegated administrator must not have administrative privileges over users in other departments.
Which two of the following actions should you perform? (Select TWO.)
- Create an administrative unit and add the marketing department users to it.Cevap
- Assign the User Administrator role to the delegated administrator scoped to the administrative unit.Cevap
- CCreate an Azure resource group and assign the User Access Administrator role to the delegated administrator at the resource group scope.
- DAssign the Contributor role to the delegated administrator at the Azure subscription scope.
Cevap
To delegate user management for a specific subset of users without granting tenant-wide permissions, you must create an administrative unit containing those users and then assign the User Administrator role to the delegated administrator scoped to that administrative unit.
To limit the scope of administrative permissions over a subset of users, you must use Microsoft Entra ID Administrative Units. Creating an administrative unit containing the target users and assigning the User Administrator role scoped specifically to that administrative unit ensures that the delegated administrator can manage only the marketing users and has no administrative rights over other users in the tenant.
Adım Adım Çözüm
Anahtar Kavram
Delegating Microsoft Entra ID administration using Administrative Units
Tahmini Süre:45s