3.1.2. Administrative Units
💡 First Principle: Roles answer what power; administrative units answer over whom. An AU is a container of users, groups, and devices that turns a tenant-wide role into a department-, region-, or school-sized one — delegation without forking tenants.
Mechanics that matter: an AU holds members (users, groups, devices); a scoped role assignment grants a role at that AU (e.g., Helpdesk Administrator of the "France" AU resets only French users' passwords). Membership can be assigned (manual) or dynamic (rule-based on attributes like department or country — P1 licensing for members). Note carefully what scoping means for groups: adding a group to an AU scopes management of the group object itself (its owners can be managed, its properties edited by AU-scoped Groups Admins) — it does not sweep the group's members into the AU.
Restricted management administrative units flip the direction of protection: objects placed in one can be modified only by admins explicitly scoped to that AU — tenant-wide role holders (even Global Administrator, for most operations) are locked out. The use case is protecting VIP accounts (executives, security team) from a compromised broad-scope helpdesk role: put the CEO in a restricted AU, and only the designated executive-support admins can reset that password.
When AUs appear in stems, the tells are geography/department delegation ("only manage users in the Paris office"), school districts (their original design center), and the phrase "without granting permissions to other users." When restricted AUs appear, the tell is protecting a sensitive subset from existing admins.
⚠️ Exam Trap: AU membership by itself grants nothing to anyone. The AU is inert until a role is assigned at its scope — and conversely, an AU-scoped User Administrator cannot touch users outside the AU, including creating users tenant-wide (creation lands in the AU only for AU-scoped role behaviors that support it).
Reflection Question: Why does putting the executives' group into a normal AU fail to protect the executives themselves, and what two changes make the protection real?