Soru

Zorluk: OrtaUsers and Groups in Microsoft Entra ID

Your organization has a Microsoft Entra ID tenant that contains an administrative unit named Office-AU.

Office-AU contains the following resources:
- A user named Admin1
- An assigned security group named Group1

A user named User1 is created in the Microsoft Entra ID tenant but is NOT a member of Office-AU.

Admin1 is assigned the Groups Administrator role scoped to Office-AU.

Determine if the following statement is true or false: Admin1 can add User1 as a member of Group1.

Cevap: Cevap

Cevap

True
The statement is true because the Groups Administrator role scoped to Office-AU grants Admin1 permission to modify the membership of Group1 since Group1 is within Office-AU. The users being added to the group do not need to be members of the same administrative unit.

Adım Adım Çözüm

1
Identify the role and scope of the administrator.
Admin1 has the Groups Administrator role scoped to Office-AU.
This determines that Admin1 can manage groups that are members of Office-AU.
2
Determine if the target group is within the administrator's scope.
Group1 is a member of Office-AU.
Since Group1 is in Office-AU, Admin1 has permission to manage its membership.
3
Determine if the user being added must be within the same administrative unit.
No, Microsoft Entra ID allows administrative unit-scoped administrators to add any user from the tenant to a group in their scope.
The write operation is performed on the group's membership attribute, not on the user object itself. Therefore, the user does not need to be within the administrative unit.

Anahtar Kavram

Groups Administrator role permissions scoped to an administrative unit in Microsoft Entra ID
Bu soruyu puanla