Forum Discussion
Mike_Feihle
Jan 01, 2022Copper Contributor
Limiting access based on domain
I have 1 tenant with 12 domains. I would like to give 1 email account on each domain access to change users under their domain, but only to their domain. Possible?
VasilMichev
MVP
There are plenty of articles detailing how it works out there, I even did some webinars on AUs back in the day. And you can always play with it with a free trial (demo) tenant, as getting your hands dirty is the best way to learn stuff.
If add/remove/change users and password is all you need here, there is already support for that within the M365 Admin center via AUs already. Still, don't get your hopes too high, as AUs have some limitations. Here's an (outdated) article on how it worked back in the old admin center: https://blog.quadrotech-it.com/blog/working-with-administrative-units-in-the-office-365-admin-center/
If add/remove/change users and password is all you need here, there is already support for that within the M365 Admin center via AUs already. Still, don't get your hopes too high, as AUs have some limitations. Here's an (outdated) article on how it worked back in the old admin center: https://blog.quadrotech-it.com/blog/working-with-administrative-units-in-the-office-365-admin-center/
Mike_Feihle
Jan 03, 2022Copper Contributor
I am more than happy to play with a user account on our live tenant, but I am seriously new to this, and I find the documentation on anything related to this is missing or outdated.
- Mike_FeihleJan 03, 2022Copper ContributorWell, I tried creating an AU, added a group of members specific to the domain of users I want to manage, and it still shows every user.
Without detailed instructions, and decent documents, I find working with Azure or Exchange to be all trial and error. You would think the people that designed these systems would at least document how it works.- VasilMichevJan 03, 2022MVPKeep in mind that if you already have an admin role assigned, you will not be subject to the AU restrictions, so best test with a fresh account. Look at the top right corner of the screen, when on the Users > Active users page in the M365 admin center. If the user is assigned to one or more "scoped" roles, you will see the "Select administrative unit" ("No unit selected") dropdown there. With the default selection, you will see all the objects. Switch to the AU-based scope you've created to see the limited list of users/objects.
- Mike_FeihleJan 03, 2022Copper Contributor
Thanks, I see that. But at what step do I add it to a specific domain. I want THIS user to only administer the emails of their own domain. We will have 12 domains added to the 1 tenant.