Containers in Microsoft Entra ID that limit the reach of directory administrators to particular users, groups or devices. They are neither Azure Policy scopes nor cost groupings.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500SC-900SC-401
Each book explains Administrative units in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
Related terms
- Privileged Role Administrator
Entra role whose holders can consent for the whole organisation to any permission, Graph application permissions included. It also looks after PIM, administrative units, role-assignable groups and the assignment of Entra roles.
- Restricted administrator
An admin in a Purview role group whose scope is limited to assigned administrative units, managing policies just for those. They can't view historical data like alerts or Activity explorer, nor existing policies.
- Unrestricted administrator
An admin in a Purview role group without assigned administrative units. Their policies can cover the entire directory, and every policy and all data is visible to them.