Active Directory Administrative Unit

This table represents the Active Directory Administrative Unit resource from Microsoft Azure.

azure.ad_administrative_unit

Fields

TitleIDTypeData TypeDescription
_keycorestring
deleted_date_timecorestringDate and time when this object was deleted. Always null when the object hasn't been deleted.
descriptioncorestringAn optional description for the administrative unit. Supports $filter (eq, ne, in, startsWith), $search.
extensionscorejsonThe collection of open extensions defined for this administrative unit. Nullable.
idcorestringThe unique identifier for an entity. Read-only.
is_member_management_restrictedcorebooltrue if members of this administrative unit should be treated as sensitive, which requires specific permissions to manage. If not set, the default value is null and the default behavior is false. Use this property to define administrative units with roles that don't inherit from tenant-level administrators, and where the management of individual member objects is limited to administrators scoped to a restricted management administrative unit. This property is immutable and can't be changed later. For more information on how to work with restricted management administrative units, see Restricted management administrative units in Microsoft Entra ID.
memberscorejsonUsers and groups that are members of this administrative unit. Supports $expand.
membership_rulecorestringThe dynamic membership rule for the administrative unit. For more information about the rules you can use for dynamic administrative units and dynamic groups, see Manage rules for dynamic membership groups in Microsoft Entra ID.
membership_rule_processing_statecorestringControls whether the dynamic membership rule is actively processed. Set to On to activate the dynamic membership rule, or Paused to stop updating membership dynamically.
membership_typecorestringIndicates the membership type for the administrative unit. The possible values are: dynamic, assigned. If not set, the default value is null and the default behavior is assigned.
namecorestring
resource_groupcorestring
scoped_role_memberscorejsonScoped-role members of this administrative unit.
subscription_idcorestring
subscription_namecorestring
tagscorehstore
visibilitycorestringControls whether the administrative unit and its members are hidden or public. Can be set to HiddenMembership. If not set, the default value is null and the default behavior is public. When set to HiddenMembership, only members of the administrative unit can list other members of the administrative unit.