Soru

Zorluk: KolayAdministrative Units and License Management

You are configuring permissions in a Microsoft Entra ID tenant. You plan to assign the Helpdesk Administrator role to a user named AdminA. You must ensure that AdminA can only perform helpdesk operations, such as password resets, for users located in the Munich branch office. Which Microsoft Entra ID resource or configuration should you implement to restrict the scope of this role?

  1. A
    an Azure resource group
  2. B
    a management group
  3. an administrative unitCevap
  4. D
    a dynamic user group

Cevap

an administrative unit
Administrative units are designed specifically to delegate Microsoft Entra ID administrative roles with a restricted scope, such as limiting a helpdesk administrator to managing users in a specific branch office.

Adım Adım Çözüm

1
Create an administrative unit in the Microsoft Entra ID tenant.
A logical container is established within the directory for delegation.
This container will define the scope for the delegated role.
2
Add the users located in the Munich branch office to the newly created administrative unit.
The target scope is populated with the correct user accounts.
Only members of the administrative unit will be affected by the delegated administrator.
3
Assign the Helpdesk Administrator role to AdminA at the administrative unit scope.
AdminA is granted Helpdesk Administrator permissions restricted only to users within that unit.
Role assignments at the administrative unit scope limit the admin's rights to only the members of that unit.

Anahtar Kavram

Administrative units in Microsoft Entra ID allow organizations to subdivide a directory into logical chunks and delegate administrative roles with permissions restricted to only those chunks.
Bu soruyu puanla