To add a scoped role assignment to a user account
-
In the Manager, select the Microsoft Entra ID > User accounts category.
-
Select the user account in the result list.
-
Select the Assign role assignments task.
-
Click Add and enter the following information.
-
Microsoft Entra ID role: Specify the role for authorization.
-
Application scope: Specify the organization for authorization.
-
Click next to the field.
-
Under Table, select the AADOrganization table.
-
Under Application scope, select the tenant.
-
Click OK.
-
- Directory scope: Specify the administrative unit, application, organization, or service principal for authorization.
-
Click next to the field.
-
Under Table, select one of the following tables:
-
To authorize an administrative unit, select AADAdministrativeUnit.
-
To authorize an application, select AADApplication.
-
To authorize an organization, select AADOrganization.
-
To authorize a service principal, select AADServicePrincipal.
-
-
Under Directory scope, select the tenant.
-
Click OK.
-
- Specify whether this assignment is a Direct assignment.
NOTE: The assignment specifications Indirect assignment and Assignment request are determined by processes and cannot be set manually.
- Request procedure: References the request procedure that results in the assignment.
NOTE: The request procedure is determined by processes and cannot be set manually.
-
-
Save the changes.