Office 365 role assignment to Azure AD users is controlled or restricted by creating a new provisioning policy and applying the policy to the Organizational Unit.

To create and apply the new policy

  1. From the Active Roles Console, create a Policy Object. For instructions on creating a policy object, see the section Creating a Policy Object, in the Active Roles Administration Guide.

NOTE: In Active Roles Console, select Office 365 Roles Management as the Policy to Configure page.
  1. In the New Provisioning Policy Object Wizard, under Select the roles for policy validation, select and assign the required the Office 365 role for the user. Click Next.
  2. In the Enforce Policy window, add the Organizational Unit (OU) on which the policy must be enforced and click Next.
  3. Click Finish.

NOTE: While creating an Azure AD user from the Active Roles Web interface, if the policy conditions are not satisfied while assigning Azure AD User roles, the following policy violation error is displayed:

Administrative Policy returned an error. Exception in Office 365 Roles Management Policy violation: The Azure user Roles(s) <roles>, can be assigned. The policy prescribes that this Azure User requires only the specified role in the policy object to be assigned.