Home > Glossary > Microsoft 365 Administrator > Microsoft Entra ID Administrative Units

📖 What is Microsoft Entra ID Administrative Units?

Microsoft Entra ID Administrative Units are logical containers used to delegate administrative permissions over a specific subset of users, groups, or devices. This allows an organization to implement a decentralized management model where admins can manage their own department or region without having tenant-wide access.

🥋 Sensei Says:

"Focus on the 'scope' of administration; this is the primary answer when the exam asks how to restrict an administrator's power to a specific group of users."

📚 Certification: Microsoft 365 Administrator (MS-102)

🔑 What are the Key Concepts of Microsoft Entra ID Administrative Units?

  • Scope of Authority: Restricts administrative roles to a specific subset of objects, preventing administrators from making changes to the entire tenant directory.
  • Object Membership: Supports the inclusion of users, groups, and devices, enabling granular management based on regional, departmental, or organizational boundaries.
  • Role Assignment: Permissions are granted at the AU level, ensuring the assigned administrator can only perform actions on objects within that specific container.
  • Dynamic Membership: Allows for the automatic addition of users to an AU based on specific attribute rules, reducing manual overhead for large organizations.
  • Least Privilege Implementation: Facilitates a decentralized management model that adheres to security best practices by limiting the blast radius of administrative accounts.

🎯 How does Microsoft Entra ID Administrative Units appear on the MS-102 Exam?

A scenario might describe a global company needing regional IT leads to manage password resets and user updates only for their specific geographic region. You will be asked to identify Administrative Units as the solution to restrict this administrative scope.

You may be asked to design a solution where department heads can manage their own team's group memberships and user profiles. The correct answer involves creating an Administrative Unit for that department and assigning the appropriate role.

Expect questions about automating the organization of users into management boundaries. The scenario will likely involve using dynamic membership rules to populate Administrative Units based on user attributes like 'Country' or 'Department'.

❓ Frequently Asked Questions

How do Administrative Units differ from Azure RBAC roles?

Azure RBAC manages access to Azure resources like Virtual Machines or Storage Accounts. Administrative Units specifically manage access to Entra ID directory objects, such as users and groups, within a restricted scope.


Can a user be assigned a role at both the tenant level and the AU level?

Yes, but the tenant-level role takes precedence. If a user is a Global Administrator at the tenant level, they have full access regardless of any restrictive Administrative Unit boundaries.

Related Terms from Microsoft 365 Administrator

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Microsoft Entra ID Administrative Units? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium