Delegate Admin rights for one Service Group to a Team, without giving them Access to anything else.
TABLE OF CONTENTS
- Step 1: Prepare your AD Group
- Step 2: Create the Scoped Admin Role
- Step 3: Link the Automation Resources
Step 1: Prepare your AD Group
Create or choose an existing Active Directory or Entra ID Group containing the Users who should get the scoped Admin Access.
Step 2: Create the Scoped Admin Role
Create a new Scoped Admin Role, enter a Name, set the AD Group Name, and select the Service Group this Role should administer.
See our Scoped Admin Roles Article for every available Field
Step 3: Link the Automation Resources
Select at least one Azure Credential, SCO Instance or PowerShell Instance — without one of these, the Role cannot be saved. Members of the AD Group can now administer this Service Group using exactly these Automation Resources.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article