Office 365 role assignment to Azure AD users is controlled or restricted by creating a new provisioning policy and applying the policy to the Organizational Unit.
To create and apply the new policy
- From the Active Roles Console, create a Policy Object. For instructions on creating a policy object, see the section Creating a Policy Object, in the Active Roles Administration Guide.
- In the New Provisioning Policy Object Wizard, under Select the roles for policy validation, select and assign the required the Office 365 role for the user. Click Next.
- In the Enforce Policy window, add the Organizational Unit (OU) on which the policy must be enforced and click Next.
- Click Finish.