> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports/azure-entities/entra-id/administrativeunit.md).

# AdministrativeUnit

## AdministrativeUnit

The **AdministrativeUnit** entity represents an Administrative Unit in Azure Active Directory (Entra ID), used for delegated administration of users, groups, and devices.

| Field                         | Type    | Possible Operators                                                 | Description                                            |
| ----------------------------- | ------- | ------------------------------------------------------------------ | ------------------------------------------------------ |
| Guid                          | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Unique identifier for the entity in Forestall          |
| ObjectID                      | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Object ID of the administrative unit          |
| FSName                        | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name used in Forestall                         |
| DisplayName                   | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name of the administrative unit in Azure AD    |
| Description                   | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Description of the administrative unit                 |
| IsMemberManagementRestricted  | BOOLEAN | True / False                                                       | Whether member management is restricted (protected AU) |
| MembershipRule                | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Dynamic membership rule expression                     |
| MembershipRuleProcessingState | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Processing state of the dynamic membership rule        |
| MembershipType                | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Membership type (e.g., Assigned, Dynamic)              |
| Visibility                    | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Visibility setting of the administrative unit          |
| TenantID                      | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Tenant ID the administrative unit belongs to  |
| AZTier                        | NUMBER  | Equal, Between, Smaller, Larger, Smaller or Equal, Larger or Equal | Azure tier classification assigned by Forestall        |
