To add a scoped role assignment to a user account
- 
In the Manager, select the Microsoft Entra ID > User accounts category.
 - 
Select the user account in the result list.
 - 
Select the Assign role assignments task.
 - 
Click Add and enter the following information.
- 
Microsoft Entra ID role: Specify the role for authorization.
 - 
Application scope: Specify the organization for authorization.
- 
Click
next to the field.
 - 
Under Table, select the AADOrganization table.
 - 
Under Application scope, select the tenant.
 - 
Click OK.
 
 - 
 - Directory scope: Specify the administrative unit, application, organization, or service principal for authorization.
- 
Click
next to the field.
 - 
Under Table, select one of the following tables:
- 
To authorize an administrative unit, select AADAdministrativeUnit.
 - 
To authorize an application, select AADApplication.
 - 
To authorize an organization, select AADOrganization.
 - 
To authorize a service principal, select AADServicePrincipal.
 
 - 
 - 
Under Directory scope, select the tenant.
 - 
Click OK.
 
 - 
 - Specify whether this assignment is a Direct assignment. 
NOTE: The assignment specifications Indirect assignment and Assignment request are determined by processes and cannot be set manually.
 - Request procedure: References the request procedure that results in the assignment. 
NOTE: The request procedure is determined by processes and cannot be set manually.
 
 - 
 - 
Save the changes.