To add a scoped role assignment to a user account
- 
In the Manager, select the Microsoft Entra ID > User accounts category. 
- 
Select the user account in the result list. 
- 
Select the Assign role assignments task. 
- 
Click Add and enter the following information. - 
Microsoft Entra ID role: Specify the role for authorization. 
- 
Application scope: Specify the organization for authorization. - 
Click next to the field. 
- 
Under Table, select the AADOrganization table. 
- 
Under Application scope, select the tenant. 
- 
Click OK. 
 
- 
- Directory scope: Specify the administrative unit, application, organization, or service principal for authorization.
- 
Click next to the field. 
- 
Under Table, select one of the following tables: - 
To authorize an administrative unit, select AADAdministrativeUnit. 
- 
To authorize an application, select AADApplication. 
- 
To authorize an organization, select AADOrganization. 
- 
To authorize a service principal, select AADServicePrincipal. 
 
- 
- 
Under Directory scope, select the tenant. 
- 
Click OK. 
 
- 
- Specify whether this assignment is a Direct assignment. 
NOTE: The assignment specifications Indirect assignment and Assignment request are determined by processes and cannot be set manually. 
- Request procedure: References the request procedure that results in the assignment. 
NOTE: The request procedure is determined by processes and cannot be set manually. 
 
- 
- 
Save the changes. 
