Skip to content

Commit f49c1aa

Browse files
committed
Update intro text
1 parent 13cf7e6 commit f49c1aa

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

articles/active-directory/roles/admin-units-assign-roles.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,11 @@ ms.collection: M365-identity-device-management
1818

1919
# Assign Azure AD roles with administrative unit scope
2020

21-
In Azure Active Directory (Azure AD), for more granular administrative control, you can assign an Azure AD role with a scope that's limited to one or more administrative units.
21+
In Azure Active Directory (Azure AD), for more granular administrative control, you can assign an Azure AD role with a scope that's limited to one or more administrative units. When an Azure AD role is assigned at the scope of an administrative unit, role permissions apply only when managing members of the administrative unit itself, and do not apply to tenant-wide settings or configurations.
22+
23+
For example, an administrator who is assigned the Groups Administrator role at the scope of an administrative unit can manage groups that are members of the administrative unit, but they cannot manage other groups in the tenant. They also cannot manage tenant-level settings related to groups, such as expiration or group naming policies.
24+
25+
This article describes how to assign Azure AD roles with administrative unit scope.
2226

2327
## Prerequisites
2428

0 commit comments

Comments
 (0)