Introduction
If you need to create an Organizational Unit (OU) security group for your department, it’s important to do so within your assigned Administrative Unit (AU) in Entra. This ensures the group is properly scoped, managed, and aligned with your department’s permissions.
Before getting started, make sure:
- You have the Groups Administrator role assigned through your OU’s operator group (OUname_Operators).
- That role is scoped to your department’s Administrative Unit.
Instructions
Create the group
- Sign in to the Microsoft Entra admin center.
- Go to Identity > Roles & admins > Admin units.
- Select your department’s administrative unit. It will be named [Department Name]-Users and Groups, such as “DoIT-Users and Groups” or “ECAP-Users and Groups”.
- In the left pane, select Groups.
- Select + New group, then complete the following fields:
- Group type: Select Security.
- Group name: Enter a name that follows your department’s naming convention.
- Group description: Add a brief description that explains the group’s purpose.
- Membership type: Select Assigned (or Dynamic, if appropriate).
- Select Create.
Important Notes
- Groups created this way are automatically scoped to your department’s administrative unit.
- Do not create groups from the top-level Groups > All groups page. Your scoped role does not include permission to create groups there.
- If you do not see your department’s administrative unit, contact your IT administrator or OU admin to verify your role assignment.