Azure AD Administrative Units Overview

Поделиться
HTML-код
  • Опубликовано: 6 фев 2025
  • A walkthrough of the new Azure AD Administrative Unit capability to provide granular scoped role assignment of Azure AD users and groups along with a demo.

Комментарии • 66

  • @richardwaldron1684
    @richardwaldron1684 3 года назад +31

    I've seen other videos on AUs and no one else has mentioned that limitation on adding groups i.e. you can't manage the users within the groups, only the groups. It's your attention to detail in all you videos (very important detail if you want pass exams and be an effective Azure admin) that makes them so good. I would have a harder time understanding Azure if it wasn't for your training library. Thank you!

    • @jonathanwitherspoon32
      @jonathanwitherspoon32 2 года назад +1

      #facts The group thing is what really helped me because I was lost with how that worked

  • @MohamedGamal-zd3td
    @MohamedGamal-zd3td 3 года назад +10

    Every time I'm stuck with a topic, you are my first resort to get a simplified explanation of this topic. many thanks, John :)

    • @NTFAQGuy
      @NTFAQGuy  3 года назад +1

      Great to hear, thank you!

  • @patrickslayden5239
    @patrickslayden5239 3 года назад +2

    This was one of the Best explanations on AU's that I have seen. Thank you so much.

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      You're very welcome!

  • @jonathanwitherspoon32
    @jonathanwitherspoon32 2 года назад +6

    Bro! I just finished an online course on Udemy last night that I have access to through my alumni resources. After the course was over it had some practice test which, I took one and passed it, but still lacked confidence in several areas. Administrative Units was one of them. You just explained this so completely and with such precision that if you charged for this content you would have been paid immediately. I was able to take great notes in my OneNote and feel like I really understand Administrative Units now. I will now be moving to more of your videos for other areas, and I am excited to know that anything you have said can be backed up really easily with a quick search of Microsoft documentation. Not going to lie your channel has been fantastic. My exam is scheduled for June 4th at 3:30. I am trying to get as much as I can in. Thank you so much for your dedication and knowledge pass down.

  • @bharatkamate
    @bharatkamate Год назад

    I have seen other videos where they do ask for like and all.
    You are the one who really want people to come and learn here.
    i don't know how to say but you are the gem for learners.
    thank you so much for your efforts toward the Azure so that we can learn from pure technical perspective.
    Hats off you Brother.

  • @TheSebolcat
    @TheSebolcat 2 года назад +1

    Thanks John for clearly explaining the AU functions. I was confused about the group but now I'm more confident to set it up correctly for our users.

  • @MuhammadFarhan-tg3pd
    @MuhammadFarhan-tg3pd 4 года назад +2

    Excellent explanation from John on AAD Admin Units, Very helpful stuff on my current project limiting the role of Automation account to specific role at reduced scope 😊

  • @aldosansan2335
    @aldosansan2335 Год назад

    Was confusing at first, but after a couple of tries, I got it, you cannot manage users in groups if they are not in the AU you have the priviledges to!
    I know is an old vid, but great content as usual John! Ty!

  • @pahadifamily5428
    @pahadifamily5428 2 года назад +1

    Amazing content as always.... Short crisp .. to the point... perfect.

  • @michield6812
    @michield6812 Год назад +1

    Short but sweet this video! I just noticed that AU can now be Dynamic User type (Preview)

  • @sylviawylie9218
    @sylviawylie9218 8 месяцев назад

    Generic comment to show my appreciation. Keep winning John!

  • @armandosse
    @armandosse 7 месяцев назад

    Fantastic explanation, thank you.

  • @oliverl.1143
    @oliverl.1143 2 года назад

    As always, great explanation. Thank you.

  • @seattledan
    @seattledan 4 года назад +1

    Another great video John! Thank you.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Glad you enjoyed it

  • @Stateoftheheart
    @Stateoftheheart Год назад

    Thanks John, so helpful as always!

  • @loo6837
    @loo6837 Год назад +1

    Your videos helped me lot, Thank you very much.

  • @kaushik4486
    @kaushik4486 3 года назад

    Good one.. This clears a lot of basic concepts

  • @gosconsultingoy7672
    @gosconsultingoy7672 4 года назад +2

    Cool, helped a ton, but man alive this dude is jacked!

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      lol, its the camera. it adds 10 lbs :-D

  • @bernardpolydor3906
    @bernardpolydor3906 8 месяцев назад

    very good explanations

  • @kenrq63
    @kenrq63 4 года назад

    Another good video John, thank you. Biggest takeaway from this is plan your operational structure ;-)

  • @MrHasie
    @MrHasie 3 года назад

    Thank you for the clarification regarding groups. Uhh, why can it not reset!?!?!

  • @JayantSharma2202
    @JayantSharma2202 3 года назад

    Awesome explanation

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      Glad you think so!

  • @revenueengine-financelesso8149
    @revenueengine-financelesso8149 4 года назад

    Very helpful. I like the digital whiteboard setup. Will consider. Cheers.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Glad it was helpful!

  • @echthys
    @echthys 2 года назад

    This was very helpful thank you :)

  • @bhargavimanchikalapudi8111
    @bhargavimanchikalapudi8111 3 года назад

    Thanks its Good one , How to add a permissions so that one particular person can add a set of groups to people

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      Glad you liked it

  • @haidaraltaiar
    @haidaraltaiar 2 года назад

    Thank you boss you made it so clear God bless you :)

  • @bobbymoore868
    @bobbymoore868 4 года назад

    It appears that you have to give any admins 'directory read-access to the whole tenant in addition to container permissions. The expected functionality I was hoping for was to only be able to view the users in the container I manage - I am doing something wrong, or is this expected?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      not sure following. normally users would have directory read for their local tenant. It's guests we tend to remove the directory read.

  • @GiovanniOrlandoi7
    @GiovanniOrlandoi7 3 года назад

    Very helpful. Thanks!

  • @Depstha
    @Depstha 4 года назад

    Nicely explained. !!

  • @jatinnandwani6678
    @jatinnandwani6678 3 года назад

    Thank you

  • @CoopmanGreg
    @CoopmanGreg 3 года назад

    How do you attach these Admin Groups to the different departments you talked about without setting those departments up as Management Groups? Thanks

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      Management groups are azure arm constructs and nothing to do with azure ad admin units. You create admin units with the people in for that department then grant admins to that specific admin unit.

    • @CoopmanGreg
      @CoopmanGreg 3 года назад

      @@NTFAQGuy Thank you

  • @James-sc1lz
    @James-sc1lz 3 года назад

    Another great video John. Admin Units sound like the same thing as using using a dynamic group and filtering user accounts by region and then applying RBAC to that AD group. Is this correct? In other words, can I achieve the same thing just doing it a different way? As you state wIth the flat AAD structure I guess this is needed because you can't simply apply permissions or policies to OUs like you can on-prem.

    • @NTFAQGuy
      @NTFAQGuy  3 года назад +1

      no. RBAC on a group is just managing the group, not things inside.

    • @James-sc1lz
      @James-sc1lz 3 года назад

      @@NTFAQGuy Thank you.

  • @omarnajjar4188
    @omarnajjar4188 4 года назад

    Hi John, love the content you provide! Is there a similar functionality for managing Hybrid joined devices/AAD only devices?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      most device type management would be more Intune than AAD and Intune does have grouping capabilities.

  • @mazdanaqvy3754
    @mazdanaqvy3754 Месяц назад

    Thanks

  • @matrixman20101
    @matrixman20101 4 года назад

    Thank you , but May I ask what's new this feature added comparing to RBAC or customized policy ?, I'd like kindly ask you if you can explain more topics like encryption "BYOK, HYOK" and how we can use HYOK on Azure ? , also monitoring on Azure i.e VMs log analytics and log analytics workspace and how we can integrate it with service desk systems for alerts . Thank you in advance .

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +3

      So that's the point. This is complete separate from RBAC on Azure resources. This is specific to Azure AD user and group management delegation. You cannot use these for RBAC of Azure resources. Azure RBAC is based around ARM roles assigned to users and groups at a scope like subscription or resource group. These AUs are to grant Azure AD roles to users at a reduce scope, i.e. the AU.

  • @gpalskis
    @gpalskis 4 года назад

    I remember one MSFT man talked about this feature back in 2017. I wonder when it will go GA from Preview :)

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      Yeahhhhhh :-) Very soon :-D

    • @spudpuppy2000
      @spudpuppy2000 4 года назад

      @@NTFAQGuy It just did.

  • @inter7322
    @inter7322 4 года назад

    So since this is just in preview what is the current standard for handling azure ad like this?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Basically today unless you use an external governance solution you really can’t limit scope of roles. This is needed!

  • @Folio1Communications
    @Folio1Communications 4 года назад

    Hay John, would you add Azure management groups into the mix?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +2

      So management groups are around management of azure resources and nothing really to do with azure ad. I’ll be covering them in detail in the governance lesson of my azure masterclass will be posting over next couple of weeks. Basically they let you create a hierarchy which subscriptions live in and you can apply policy, budget and rbac.

  • @AleksandarIvanov69
    @AleksandarIvanov69 2 года назад

    For the algorithm! 😁

  • @jatinnandwani6678
    @jatinnandwani6678 3 года назад

    Imagine there are 360 likes on this video at the moment..