Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases now! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Exam Ref AZ-104 Microsoft Azure Administrator Certification and Beyond

You're reading from   Exam Ref AZ-104 Microsoft Azure Administrator Certification and Beyond A pragmatic guide to achieving the Azure administration certification

Arrow left icon
Product type Paperback
Published in Jul 2022
Publisher Packt
ISBN-13 9781801819541
Length 776 pages
Edition 2nd Edition
Tools
Arrow right icon
Authors (2):
Arrow left icon
Donovan Kelly Donovan Kelly
Author Profile Icon Donovan Kelly
Donovan Kelly
Riaan Lowe Riaan Lowe
Author Profile Icon Riaan Lowe
Riaan Lowe
Arrow right icon
View More author details
Toc

Table of Contents (30) Chapters Close

Preface 1. Part 1: Managing Azure Identities and Governance FREE CHAPTER
2. Chapter 1: Managing Azure Active Directory Objects 3. Chapter 2: Managing Role-Based Access Control 4. Chapter 3: Creating and Managing Governance 5. Chapter 4: Managing Governance and Costs 6. Chapter 5: Practice Labs – Managing Azure Identities and Governance 7. Part 2: Implementing and Managing Storage
8. Chapter 6: Understanding and Managing Storage 9. Chapter 7: Securing Storage 10. Chapter 8: Practice Labs – Implementing and Managing Storage 11. Part 3: Deploying and Managing Azure Compute Resources
12. Chapter 9: Automating VM Deployments Using ARM Templates 13. Chapter 10: Configuring Virtual Machines 14. Chapter 11: Creating and Configuring Containers 15. Chapter 12: Creating and Configuring App Services 16. Chapter 13: Practice Labs – Deploying and Managing Azure Compute Resources 17. Part 4: Configuring and Managing Virtual Networking
18. Chapter 14: Implementing and Managing Virtual Networking 19. Chapter 15: Securing Access to Virtual Networks 20. Chapter 16: Configuring Load Balancing 21. Chapter 17: Integrating On-Premises Networks with Azure 22. Chapter 18: Monitoring and Troubleshooting Virtual Networking 23. Chapter 19: Practice Labs – Configuring and Managing Virtual Networking 24. Part 5: Monitoring and Backing Up Azure Resources
25. Chapter 20: Monitoring Resources with Azure Monitor 26. Chapter 21: Implementing Backup and Recovery Solutions 27. Chapter 22: Practice Labs – Monitoring and Backing Up Azure Resources 28. Chapter 23: Mockup Test Questions and Answers 29. Other Books You May Enjoy

Creating Azure AD AUs

Azure AD AUs are used in scenarios where granular administrative control is required. AUs have the following prerequisites:

  • An Azure AD Premium P1 license is required for each AU administrator.
  • An Azure AD Free license is required for AU members.
  • A privileged role administrator or global administrator is required for configuration.

    Tip

    AUs can be created via the Azure portal or PowerShell.

The easiest way to explain AUs is by using a scenario. A company called Contoso is a worldwide organization with users across 11 countries. Contoso has decided that each country is responsible for its own users from an administrative point of view. That is where Azure AD AUs come in handy. With AUs, Contoso can group users per country and assign administrators that only have control over these users and cannot administrate users in other countries.

The following diagram displays a high-level overview of how AUs work in the same tenant across different departments. The following example is based on different regions:

Figure 1.8 – An AU overview displaying the separation of users for US sales and UK sales

Figure 1.8 – An AU overview displaying the separation of users for US sales and UK sales

The following roles can be assigned within an AU:

  • Authentication administrator
  • Groups administrator
  • Help desk administrator
  • License administrator
  • Password administrator
  • User administrator

    Important Note

    Groups can be added to the AU as an object; therefore, any user within the group is not automatically part of the AU.

Now, let's go ahead and create an AU via the Azure portal:

  1. Navigate to the Azure portal by opening a web browser and browsing to https://portal.azure.com.
  2. In the left-hand menu, select Azure Active Directory.
  3. Under the Manage blade of Azure AD in the left-hand menu, select Administrative units and click on + Add:
Figure 1.9 – The AU blade within Azure AD

Figure 1.9 – The AU blade within Azure AD

  1. Enter a name for the group. I'm using South Africa Users. In the Description field, it is best practice to add a brief description of what this AU is going to be used for:
Figure 1.10 – The creation blade for an AU

Figure 1.10 – The creation blade for an AU

  1. Next, under Assign roles, add the users that you want to be administrators based on the available roles. Then, select Password administrator and choose PacktUser1.
  2. Click on Review + create:
Figure 1.11 – The AU summary page

Figure 1.11 – The AU summary page

  1. The next step is to add all the users you want PacktUser1 to manage; in our case, we need to add PacktUser1, PacktUser2, and PacktUser3. On the left-hand side, under Manage, click on Add member and select the members:
Figure 1.12 – Adding users to the AU

Figure 1.12 – Adding users to the AU

  1. Now you will see that all three users have been added to the AU:
Figure 1.13 – Displaying the users added to the AU

Figure 1.13 – Displaying the users added to the AU

  1. You can now log in with PacktUser1, and you should be able to reset the password of PacktUser2.

    Important Note

    Remember, you need to assign an Azure AD P1 license to administrators within the AU.

In this section, we explained what an AU is and how it can be used. Additionally, we went through the creation of an AU step by step.

We encourage students to read up further by using the following links, which will provide additional information around AU management:

Now, let's move on and take a look at how to manage user and group properties.

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime