You are configuring permissions in a Microsoft Entra ID tenant. You plan to assign the Helpdesk Administrator role to a user named AdminA. You must ensure that AdminA can only perform helpdesk operations, such as password resets, for users located in the Munich branch office. Which Microsoft Entra ID resource or configuration should you implement to restrict the scope of this role?
- Aan Azure resource group
- Ba management group
- an administrative unitCevap
- Da dynamic user group
Cevap
an administrative unit
Administrative units are designed specifically to delegate Microsoft Entra ID administrative roles with a restricted scope, such as limiting a helpdesk administrator to managing users in a specific branch office.
Adım Adım Çözüm
Anahtar Kavram
Administrative units in Microsoft Entra ID allow organizations to subdivide a directory into logical chunks and delegate administrative roles with permissions restricted to only those chunks.