Assigning Azure Active Directory organizations to scopes through role eligibilities
To assign an organization to a scope
-
In the Manager, select the Azure Active Directory > Scoped role eligibilities category.
-
Select the role in the result list.
-
Select the Assign organizations task.
In the Add assignments pane, assign the organizations:
-
On the Departments tab, assign departments.
-
On the Locations tab, assign locations.
-
On the Cost centers tab, assign cost centers.
TIP: In the Remove assignments pane, you can remove assigned organizations.
To remove an assignment
-
Save the changes.
Related topics
Mapping Azure Active Directory objects in One Identity Manager
In One Identity Manager, you can map user accounts, groups, administrator roles, subscriptions, service plans, applications, service principals, and app roles of an Azure Active Directory tenant. These objects are imported into the One Identity Manager database during synchronization. You cannot display or edit their properties in the Manager.
Detailed information about this topic
Azure Active Directory core directories
For more information about the Azure Active Directory structure, see the Azure Active Directory documentation from Microsoft.
You must provide details about your organization the first time you register for a Microsoft cloud service. This detailed information is used to make a new Azure Active Directory directory partition. The organization represents one Azure Active Directory tenant. In One Identity Manager, you can edit the main data of each tenant. However, you cannot create new tenants in One Identity Manager.
A base domain is linked to the core directory in the cloud. You can also add other user-defined domains in Azure Active Directory, which you can then allocate to Microsoft cloud services. One Identity Manager only loads verified domain data into the database. It is not possible to edit data in One Identity Manager.
Detailed information about this topic
Azure Active Directory tenant
You must provide details about your organization the first time you register for a Microsoft cloud service. This detailed information is used to make a new Azure Active Directory directory partition. The organization represents one Azure Active Directory tenant. In One Identity Manager, you can edit the main data of each Azure Active Directory tenant. However, you cannot create new Azure Active Directory tenants in One Identity Manager.
To edit Azure Active Directory tenant main data
-
In the Manager, select the Azure Active Directory > Tenants category.
-
In the result list, select the Azure Active Directory tenant.
-
Select the Change main data task.
-
Edit the Azure Active Directory tenant's main data.
- Save the changes.
Detailed information about this topic