Azure AD Administrative Units Overview

Sdílet
Vložit
  • čas přidán 31. 07. 2020
  • A walkthrough of the new Azure AD Administrative Unit capability to provide granular scoped role assignment of Azure AD users and groups along with a demo.
  • Věda a technologie

Komentáře • 65

  • @MohamedGamal-zd3td
    @MohamedGamal-zd3td Před 3 lety +10

    Every time I'm stuck with a topic, you are my first resort to get a simplified explanation of this topic. many thanks, John :)

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      Great to hear, thank you!

  • @richardwaldron1684
    @richardwaldron1684 Před 2 lety +27

    I've seen other videos on AUs and no one else has mentioned that limitation on adding groups i.e. you can't manage the users within the groups, only the groups. It's your attention to detail in all you videos (very important detail if you want pass exams and be an effective Azure admin) that makes them so good. I would have a harder time understanding Azure if it wasn't for your training library. Thank you!

    • @jonathanwitherspoon32
      @jonathanwitherspoon32 Před 2 lety +1

      #facts The group thing is what really helped me because I was lost with how that worked

  • @michield6812
    @michield6812 Před rokem +1

    Short but sweet this video! I just noticed that AU can now be Dynamic User type (Preview)

  • @pahadifamily5428
    @pahadifamily5428 Před 2 lety +1

    Amazing content as always.... Short crisp .. to the point... perfect.

  • @TheSebolcat
    @TheSebolcat Před rokem +1

    Thanks John for clearly explaining the AU functions. I was confused about the group but now I'm more confident to set it up correctly for our users.

  • @sylviawylie9218
    @sylviawylie9218 Před měsícem

    Generic comment to show my appreciation. Keep winning John!

  • @jonathanwitherspoon32
    @jonathanwitherspoon32 Před 2 lety +5

    Bro! I just finished an online course on Udemy last night that I have access to through my alumni resources. After the course was over it had some practice test which, I took one and passed it, but still lacked confidence in several areas. Administrative Units was one of them. You just explained this so completely and with such precision that if you charged for this content you would have been paid immediately. I was able to take great notes in my OneNote and feel like I really understand Administrative Units now. I will now be moving to more of your videos for other areas, and I am excited to know that anything you have said can be backed up really easily with a quick search of Microsoft documentation. Not going to lie your channel has been fantastic. My exam is scheduled for June 4th at 3:30. I am trying to get as much as I can in. Thank you so much for your dedication and knowledge pass down.

  • @patrickslayden5239
    @patrickslayden5239 Před 2 lety +1

    This was one of the Best explanations on AU's that I have seen. Thank you so much.

  • @oliverl.1143
    @oliverl.1143 Před rokem

    As always, great explanation. Thank you.

  • @seattledan
    @seattledan Před 3 lety +1

    Another great video John! Thank you.

  • @Stateoftheheart
    @Stateoftheheart Před rokem

    Thanks John, so helpful as always!

  • @armandosse
    @armandosse Před 27 dny

    Fantastic explanation, thank you.

  • @MuhammadFarhan-tg3pd
    @MuhammadFarhan-tg3pd Před 3 lety +2

    Excellent explanation from John on AAD Admin Units, Very helpful stuff on my current project limiting the role of Automation account to specific role at reduced scope 😊

  • @kaushik4486
    @kaushik4486 Před 2 lety

    Good one.. This clears a lot of basic concepts

  • @bharatkamate
    @bharatkamate Před rokem

    I have seen other videos where they do ask for like and all.
    You are the one who really want people to come and learn here.
    i don't know how to say but you are the gem for learners.
    thank you so much for your efforts toward the Azure so that we can learn from pure technical perspective.
    Hats off you Brother.

  • @RockVult
    @RockVult Před rokem

    This was very helpful thank you :)

  • @GiovanniOrlandoi7
    @GiovanniOrlandoi7 Před 2 lety

    Very helpful. Thanks!

  • @gosconsultingoy7672
    @gosconsultingoy7672 Před 3 lety +2

    Cool, helped a ton, but man alive this dude is jacked!

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      lol, its the camera. it adds 10 lbs :-D

  • @loo6837
    @loo6837 Před 10 měsíci +1

    Your videos helped me lot, Thank you very much.

  • @aldosansan2335
    @aldosansan2335 Před rokem

    Was confusing at first, but after a couple of tries, I got it, you cannot manage users in groups if they are not in the AU you have the priviledges to!
    I know is an old vid, but great content as usual John! Ty!

  • @haidaraltaiar
    @haidaraltaiar Před rokem

    Thank you boss you made it so clear God bless you :)

  • @bernardpolydor3906
    @bernardpolydor3906 Před měsícem

    very good explanations

  • @revenueengine-financelesso8149

    Very helpful. I like the digital whiteboard setup. Will consider. Cheers.

  • @kenrq63
    @kenrq63 Před 3 lety

    Another good video John, thank you. Biggest takeaway from this is plan your operational structure ;-)

  • @Depstha
    @Depstha Před 3 lety

    Nicely explained. !!

  • @JayantSharma2202
    @JayantSharma2202 Před 2 lety

    Awesome explanation

  • @jatinnandwani6678
    @jatinnandwani6678 Před 2 lety

    Thank you

  • @omarnajjar4188
    @omarnajjar4188 Před 3 lety

    Hi John, love the content you provide! Is there a similar functionality for managing Hybrid joined devices/AAD only devices?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      most device type management would be more Intune than AAD and Intune does have grouping capabilities.

  • @MrHasie
    @MrHasie Před 3 lety

    Thank you for the clarification regarding groups. Uhh, why can it not reset!?!?!

  • @matrixman20101
    @matrixman20101 Před 3 lety

    Thank you , but May I ask what's new this feature added comparing to RBAC or customized policy ?, I'd like kindly ask you if you can explain more topics like encryption "BYOK, HYOK" and how we can use HYOK on Azure ? , also monitoring on Azure i.e VMs log analytics and log analytics workspace and how we can integrate it with service desk systems for alerts . Thank you in advance .

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +3

      So that's the point. This is complete separate from RBAC on Azure resources. This is specific to Azure AD user and group management delegation. You cannot use these for RBAC of Azure resources. Azure RBAC is based around ARM roles assigned to users and groups at a scope like subscription or resource group. These AUs are to grant Azure AD roles to users at a reduce scope, i.e. the AU.

  • @James-sc1lz
    @James-sc1lz Před 2 lety

    Another great video John. Admin Units sound like the same thing as using using a dynamic group and filtering user accounts by region and then applying RBAC to that AD group. Is this correct? In other words, can I achieve the same thing just doing it a different way? As you state wIth the flat AAD structure I guess this is needed because you can't simply apply permissions or policies to OUs like you can on-prem.

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety +1

      no. RBAC on a group is just managing the group, not things inside.

    • @James-sc1lz
      @James-sc1lz Před 2 lety

      @@NTFAQGuy Thank you.

  • @bobbymoore868
    @bobbymoore868 Před 3 lety

    It appears that you have to give any admins 'directory read-access to the whole tenant in addition to container permissions. The expected functionality I was hoping for was to only be able to view the users in the container I manage - I am doing something wrong, or is this expected?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      not sure following. normally users would have directory read for their local tenant. It's guests we tend to remove the directory read.

  • @Folio1Communications
    @Folio1Communications Před 3 lety

    Hay John, would you add Azure management groups into the mix?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +2

      So management groups are around management of azure resources and nothing really to do with azure ad. I’ll be covering them in detail in the governance lesson of my azure masterclass will be posting over next couple of weeks. Basically they let you create a hierarchy which subscriptions live in and you can apply policy, budget and rbac.

  • @CoopmanGreg
    @CoopmanGreg Před 3 lety

    How do you attach these Admin Groups to the different departments you talked about without setting those departments up as Management Groups? Thanks

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Management groups are azure arm constructs and nothing to do with azure ad admin units. You create admin units with the people in for that department then grant admins to that specific admin unit.

    • @CoopmanGreg
      @CoopmanGreg Před 3 lety

      @@NTFAQGuy Thank you

  • @AleksandarIvanov69
    @AleksandarIvanov69 Před 2 lety

    For the algorithm! 😁

  • @bhargavimanchikalapudi8111

    Thanks its Good one , How to add a permissions so that one particular person can add a set of groups to people

  • @inter7322
    @inter7322 Před 3 lety

    So since this is just in preview what is the current standard for handling azure ad like this?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Basically today unless you use an external governance solution you really can’t limit scope of roles. This is needed!

  • @gpalskis
    @gpalskis Před 3 lety

    I remember one MSFT man talked about this feature back in 2017. I wonder when it will go GA from Preview :)

  • @jatinnandwani6678
    @jatinnandwani6678 Před 2 lety

    Imagine there are 360 likes on this video at the moment..