> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/azure-identities/entra-id/administrative-units.md).

# Administrative Units

The `Administrative Units` page provides a list of enumerated administrative units in entire Azure. The list contains the `Display Name`, `Description`, `Member Management Restricted`, `Visibility`, `Member Count` and `Tier 0`.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-58450df893f654eb583679853e0077e8e1b92326%2Fresources.png?alt=media" alt=""><figcaption><p>Administrative Units</p></figcaption></figure>

## Administrative Units Details

Details page contains the `Risk Score` of the administrative Units,`Exposure Point`, `Information` panes.

{% hint style="info" %}
You can analyze objects in the `Graph module` by clicking the `Visualize` button on the upper left side of the `Information Pane`.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-d5b2617d53ab07fe208423ed4a3b99114b991988%2Fazure-identities-administrative-units-image-1.png?alt=media" alt=""><figcaption><p>Administrative Units Details</p></figcaption></figure>

## Information

`Information Pane` can contain different badges to highlight important attributes.

| Badge    | Description                                                            |
| -------- | ---------------------------------------------------------------------- |
| **Tier** | Indicates that the object tier according to risk score and importance. |

`Information Pane` contains `Details`, `Users`, `Groups`, and `Devices` tabs respectively.

## Details

Details tab contains attributes below about administrative unit object.

| Attribute                            | Description                                                                                                                                                       |
| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Display Name**                     | The name of the Administrative Unit as shown in the Azure portal; used to identify and organize groups of users, devices, or groups for delegated administration. |
| **Membership Rule**                  | This field defines the dynamic membership criteria, if any. It's blank when the AU uses manual (static) membership.                                               |
| **Description**                      | An optional text field describing the purpose or usage of the Administrative Unit; this is blank if not set.                                                      |
| **Membership Type**                  | Indicates whether members are added **dynamically** (based on rules) or **assigned manually**. If not specified, the AU is likely using manual assignments.       |
| **Visibility**                       | Defines who can see the Administrative Unit. When blank, it defaults to standard visibility within the tenant based on assigned permissions.                      |
| **Membership Rule Processing State** | Shows the status of dynamic rule evaluation (e.g., `Processing`, `Completed`, or `NotStarted`). If blank, the AU does not use dynamic membership.                 |
| **Tenant ID**                        | The unique identifier (GUID) of the Azure AD tenant where the Administrative Unit resides.                                                                        |
| **Is Member Management Restricted**  | When set to `False`, it means global administrators and other authorized roles can manage members without restrictions.                                           |
| **Object ID**                        | A globally unique identifier (GUID) assigned to the Administrative Unit within the Azure AD directory.                                                            |

## Users

Users tab contains a list of users that the administrative unit is a member of. This list also contains `Enabled` and `On Prem Sync Enabled` columns to identify the status of these users.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-128d0c4b97d73b0c06192c160b6ce25496aa1bfd%2Fazure-identities-administrative-units-image-2.png?alt=media" alt=""><figcaption><p>Users</p></figcaption></figure>

## Groups

Groups tab contains a list of groups that the administrative unit is a member of. This list also contains `Enabled` and `On Prem Sync Enabled` columns to identify the privilege levels of these groups.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-13b5bd2896a3147d6b813a1a5f31fbc0f10fd4cc%2Fazure-identities-administrative-units-image-3.png?alt=media" alt=""><figcaption><p>Groups</p></figcaption></figure>

## Devices

Devices tab contains a list of devices that the administrative unit is a member of. This list also contains `Account Enabled` , `Operating System` , `Operating System Version` and `Owner Users` columns to identify the status of these devices.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-5419ecf0722442208af57ed23fbc894b26163208%2Fazure-identities-administrative-units-image-4.png?alt=media" alt=""><figcaption><p>Devices</p></figcaption></figure>
