You manage three branch offices and an Azure subscription with an Azure Active Directory tenant. You must grant a local administrator in each office permission to manage users. Which feature should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: administrative units.
Why this is the answer
Administrative units (AUs) are the correct choice because they allow you to restrict administrative permissions to a specific subset of users and groups within your Azure AD tenant. This enables you to grant the local administrator in each office the ability to manage only the users relevant to their branch, without giving them tenant-wide permissions. Azure AD roles provide tenant-wide permissions, which would grant the local administrators access to manage users across all offices, violating the principle of least privilege. Access packages in Azure AD entitlement management are used for managing access to resources based on policies, not for delegating administrative control over user objects. Azure roles (RBAC) are for controlling access to Azure resources, not for managing users within Azure AD.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed