Azure AD Administrative Units Overview

Поділитися
Вставка
  • Опубліковано 9 вер 2024
  • A walkthrough of the new Azure AD Administrative Unit capability to provide granular scoped role assignment of Azure AD users and groups along with a demo.

КОМЕНТАРІ • 65

  • @richardwaldron1684
    @richardwaldron1684 2 роки тому +28

    I've seen other videos on AUs and no one else has mentioned that limitation on adding groups i.e. you can't manage the users within the groups, only the groups. It's your attention to detail in all you videos (very important detail if you want pass exams and be an effective Azure admin) that makes them so good. I would have a harder time understanding Azure if it wasn't for your training library. Thank you!

    • @jonathanwitherspoon32
      @jonathanwitherspoon32 2 роки тому +1

      #facts The group thing is what really helped me because I was lost with how that worked

  • @MohamedGamal-zd3td
    @MohamedGamal-zd3td 3 роки тому +10

    Every time I'm stuck with a topic, you are my first resort to get a simplified explanation of this topic. many thanks, John :)

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      Great to hear, thank you!

  • @michield6812
    @michield6812 Рік тому +1

    Short but sweet this video! I just noticed that AU can now be Dynamic User type (Preview)

  • @jonathanwitherspoon32
    @jonathanwitherspoon32 2 роки тому +5

    Bro! I just finished an online course on Udemy last night that I have access to through my alumni resources. After the course was over it had some practice test which, I took one and passed it, but still lacked confidence in several areas. Administrative Units was one of them. You just explained this so completely and with such precision that if you charged for this content you would have been paid immediately. I was able to take great notes in my OneNote and feel like I really understand Administrative Units now. I will now be moving to more of your videos for other areas, and I am excited to know that anything you have said can be backed up really easily with a quick search of Microsoft documentation. Not going to lie your channel has been fantastic. My exam is scheduled for June 4th at 3:30. I am trying to get as much as I can in. Thank you so much for your dedication and knowledge pass down.

  • @TheSebolcat
    @TheSebolcat 2 роки тому +1

    Thanks John for clearly explaining the AU functions. I was confused about the group but now I'm more confident to set it up correctly for our users.

  • @patrickslayden5239
    @patrickslayden5239 2 роки тому +1

    This was one of the Best explanations on AU's that I have seen. Thank you so much.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      You're very welcome!

  • @pahadifamily5428
    @pahadifamily5428 2 роки тому +1

    Amazing content as always.... Short crisp .. to the point... perfect.

  • @sylviawylie9218
    @sylviawylie9218 3 місяці тому

    Generic comment to show my appreciation. Keep winning John!

  • @gosconsultingoy7672
    @gosconsultingoy7672 3 роки тому +2

    Cool, helped a ton, but man alive this dude is jacked!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      lol, its the camera. it adds 10 lbs :-D

  • @bharatkamate
    @bharatkamate Рік тому

    I have seen other videos where they do ask for like and all.
    You are the one who really want people to come and learn here.
    i don't know how to say but you are the gem for learners.
    thank you so much for your efforts toward the Azure so that we can learn from pure technical perspective.
    Hats off you Brother.

  • @MuhammadFarhan-tg3pd
    @MuhammadFarhan-tg3pd 4 роки тому +2

    Excellent explanation from John on AAD Admin Units, Very helpful stuff on my current project limiting the role of Automation account to specific role at reduced scope 😊

  • @armandosse
    @armandosse 2 місяці тому

    Fantastic explanation, thank you.

  • @aldosansan2335
    @aldosansan2335 Рік тому

    Was confusing at first, but after a couple of tries, I got it, you cannot manage users in groups if they are not in the AU you have the priviledges to!
    I know is an old vid, but great content as usual John! Ty!

  • @seattledan
    @seattledan 3 роки тому +1

    Another great video John! Thank you.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad you enjoyed it

  • @loo6837
    @loo6837 Рік тому +1

    Your videos helped me lot, Thank you very much.

  • @oliverl.1143
    @oliverl.1143 2 роки тому

    As always, great explanation. Thank you.

  • @bernardpolydor3906
    @bernardpolydor3906 3 місяці тому

    very good explanations

  • @Stateoftheheart
    @Stateoftheheart Рік тому

    Thanks John, so helpful as always!

  • @kaushik4486
    @kaushik4486 2 роки тому

    Good one.. This clears a lot of basic concepts

  • @revenueengine-financelesso8149
    @revenueengine-financelesso8149 3 роки тому

    Very helpful. I like the digital whiteboard setup. Will consider. Cheers.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad it was helpful!

  • @GiovanniOrlandoi7
    @GiovanniOrlandoi7 2 роки тому

    Very helpful. Thanks!

  • @kenrq63
    @kenrq63 4 роки тому

    Another good video John, thank you. Biggest takeaway from this is plan your operational structure ;-)

  • @RockVult
    @RockVult 2 роки тому

    This was very helpful thank you :)

  • @haidaraltaiar
    @haidaraltaiar 2 роки тому

    Thank you boss you made it so clear God bless you :)

  • @JayantSharma2202
    @JayantSharma2202 3 роки тому

    Awesome explanation

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad you think so!

  • @jatinnandwani6678
    @jatinnandwani6678 2 роки тому

    Thank you

  • @Depstha
    @Depstha 3 роки тому

    Nicely explained. !!

  • @MrHasie
    @MrHasie 3 роки тому

    Thank you for the clarification regarding groups. Uhh, why can it not reset!?!?!

  • @omarnajjar4188
    @omarnajjar4188 3 роки тому

    Hi John, love the content you provide! Is there a similar functionality for managing Hybrid joined devices/AAD only devices?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      most device type management would be more Intune than AAD and Intune does have grouping capabilities.

  • @bhargavimanchikalapudi8111
    @bhargavimanchikalapudi8111 3 роки тому

    Thanks its Good one , How to add a permissions so that one particular person can add a set of groups to people

  • @AleksandarIvanov69
    @AleksandarIvanov69 2 роки тому

    For the algorithm! 😁

  • @bobbymoore868
    @bobbymoore868 3 роки тому

    It appears that you have to give any admins 'directory read-access to the whole tenant in addition to container permissions. The expected functionality I was hoping for was to only be able to view the users in the container I manage - I am doing something wrong, or is this expected?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      not sure following. normally users would have directory read for their local tenant. It's guests we tend to remove the directory read.

  • @gpalskis
    @gpalskis 4 роки тому

    I remember one MSFT man talked about this feature back in 2017. I wonder when it will go GA from Preview :)

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +1

      Yeahhhhhh :-) Very soon :-D

    • @spudpuppy2000
      @spudpuppy2000 3 роки тому

      @@NTFAQGuy It just did.

  • @matrixman20101
    @matrixman20101 4 роки тому

    Thank you , but May I ask what's new this feature added comparing to RBAC or customized policy ?, I'd like kindly ask you if you can explain more topics like encryption "BYOK, HYOK" and how we can use HYOK on Azure ? , also monitoring on Azure i.e VMs log analytics and log analytics workspace and how we can integrate it with service desk systems for alerts . Thank you in advance .

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +3

      So that's the point. This is complete separate from RBAC on Azure resources. This is specific to Azure AD user and group management delegation. You cannot use these for RBAC of Azure resources. Azure RBAC is based around ARM roles assigned to users and groups at a scope like subscription or resource group. These AUs are to grant Azure AD roles to users at a reduce scope, i.e. the AU.

  • @James-sc1lz
    @James-sc1lz 2 роки тому

    Another great video John. Admin Units sound like the same thing as using using a dynamic group and filtering user accounts by region and then applying RBAC to that AD group. Is this correct? In other words, can I achieve the same thing just doing it a different way? As you state wIth the flat AAD structure I guess this is needed because you can't simply apply permissions or policies to OUs like you can on-prem.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому +1

      no. RBAC on a group is just managing the group, not things inside.

    • @James-sc1lz
      @James-sc1lz 2 роки тому

      @@NTFAQGuy Thank you.

  • @CoopmanGreg
    @CoopmanGreg 3 роки тому

    How do you attach these Admin Groups to the different departments you talked about without setting those departments up as Management Groups? Thanks

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Management groups are azure arm constructs and nothing to do with azure ad admin units. You create admin units with the people in for that department then grant admins to that specific admin unit.

    • @CoopmanGreg
      @CoopmanGreg 3 роки тому

      @@NTFAQGuy Thank you

  • @Folio1Communications
    @Folio1Communications 4 роки тому

    Hay John, would you add Azure management groups into the mix?

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +2

      So management groups are around management of azure resources and nothing really to do with azure ad. I’ll be covering them in detail in the governance lesson of my azure masterclass will be posting over next couple of weeks. Basically they let you create a hierarchy which subscriptions live in and you can apply policy, budget and rbac.

  • @inter7322
    @inter7322 4 роки тому

    So since this is just in preview what is the current standard for handling azure ad like this?

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      Basically today unless you use an external governance solution you really can’t limit scope of roles. This is needed!

  • @jatinnandwani6678
    @jatinnandwani6678 2 роки тому

    Imagine there are 360 likes on this video at the moment..