简体   繁体   中英

Azure AD - Block group managing for some admins

Is there possible to block administrators from managing one group in Azure AD tenant?

Description, what i expect: I have a one group called "test.group" and for organisation purposes, only two administrators can managed that group (with global admin role). The rest of admins (without global admin role) cannot managed membership or even edit that group. Is it possible? (powershell or GUI?)

I tried Administrative Units but it's pointless to do it only for one group. Unless, there is possible to remove directory roles only for AU scope.

Azure AD roles with permissions microsoft.directory/groups/* will apply to all groups: Global Administrators or Group Administrators will be able to manage any group. You cannot remove, disable or deny such permissions on a per user or per group basis.

Users without microsoft.directory/groups/* permissions won't be able to manage any groups unless they are made owners of the groups. This is achievable out of the box for any member (non guest) user that creates a group. They will be added as the first owner.

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM