Skip to content

Commit b188e54

Browse files
committed
and now save it
1 parent b075872 commit b188e54

File tree

1 file changed

+6
-2
lines changed

1 file changed

+6
-2
lines changed

articles/active-directory/users-groups-roles/directory-administrative-units.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ In this preview release, you can manage administrative units using the Azure por
4848

4949
Administrative units can be used to logically group Azure AD resources. For example, for an organization whose IT department is scattered globally, it might make sense to create administrative units that define those geographical boundaries. In another scenario where a multi-national organization has different "sub-organizations", that are semi-autonomous in operations, each sub-organization may be represented by an administrative unit.
5050

51-
The criteria on which administrative units are created will be guided by the unique requirements of an organization. Administrative Units are a common way to define structure across M365 services. Therefore, a key point to consider is to ensure that how and when your administrative units are created makes sense across M365 services. You can get maximum value out of administrative units when you can associate common resources across M365 under an administrative unit.
51+
The criteria on which administrative units are created will be guided by the unique requirements of an organization. Administrative Units are a common way to define structure across M365 services. We recommend that you prepare your administrative units with their use across M365 services in mind. You can get maximum value out of administrative units when you can associate common resources across M365 under an administrative unit.
5252

5353
You can expect the creation of administrative units in the organization to go through the following stages:
5454

@@ -89,7 +89,11 @@ Permissions | MS Graph/PowerShell | Azure AD portal | Microsoft 365 admin ce
8989
administrative unit-scoped management of group properties and members | Supported | Supported | Not supported
9090
administrative unit-scoped management of group licensing | Supported | Supported | Not supported
9191

92-
Administrative units apply scope only to management permissions. They do not prevent members or administrators from using their [default user permissions](../fundamentals/users-default-permissions.md) to browse other users, groups, or resources outside of the administrative unit. In the Office 365 portal, users outside of an administrative unit-scoped admin's administrative units are filtered out, but you can browse other users in the Azure AD portal, PowerShell, and other Microsoft services.
92+
> [!NOTE]
93+
>
94+
> Administrators with an admin unit scope can't manage dynamic group membership rules.
95+
96+
Administrative units apply scope only to management permissions. They don't prevent members or administrators from using their [default user permissions](../fundamentals/users-default-permissions.md) to browse other users, groups, or resources outside of the administrative unit. In the Office 365 portal, users outside of an administrative unit-scoped admin's administrative units are filtered out, but you can browse other users in the Azure AD portal, PowerShell, and other Microsoft services.
9397

9498
## Next steps
9599

0 commit comments

Comments
 (0)