Skip to main content

entra administrativeunit roleassignment add

Assigns a Microsoft Entra role with administrative unit scope to a user


m365 entra administrativeunit roleassignment add [options]


-i, --administrativeUnitId [administrativeUnitId]

The id of the administrative unit. Specify either administrativeUnitId or administrativeUnitName.

-n, --administrativeUnitName [administrativeUnitName]

The name of the administrative unit. Specify either administrativeUnitId or administrativeUnitName.

--roleDefinitionId [roleDefinitionId]

The id of the role definition that the member is in. Specify either roleDefinitionId or roleDefinitionName.

--roleDefinitionName [roleDefinitionName]

The name of the role definition that the member is in. Specify either roleDefinitionId or roleDefinitionName.

--userId [userId]

The id of the user that is a member of the scoped role. Specify either userId or userName.

--userName [userName]

The name of the user that is a member of the scoped role. Specify either userId or userName.

-h, --help [help]

Output usage information. Optionally, specify which section of command's help you want to see. Allowed values are options, examples, remarks, response, full. Default is options.

--query [query]

JMESPath query string. See for more information and examples.

-o, --output [output]

Output type. json, text, csv, md, none. Default json.


Runs command with verbose logging.


Runs command with debug logging.



To use this command you must be either Global Administrator or Privileged Role Administrator.


Assign a role definition specified by id to a user specified by id for an administrative unit specified by id

m365 entra administrativeunit roleassignment add --administrativeUnitId 81bb36e4-f4c6-4984-8e56-d4f8feae9e09 --roleDefinitionId 4d6ac14f-3453-41d0-bef9-a3e0c569773a --userId 5f91f951-7305-4a27-9b63-7b00906de09f

Assign a role definition specified by name to a user specified by name for an administrative unit specified by name

m365 entra administrativeunit roleassignment add --administrativeUnitName 'Marketing Division' --roleDefinitionName 'License Administrator' --userName ''


"id": "5wuT_mJe20eRr5jDpJo4sVH5kV8FcydKm2N7AJBt4J_kNruBxvSESY5W1Pj-rp4J-2",
"principalId": "5f91f951-7305-4a27-9b63-7b00906de09f",
"directoryScopeId": "/administrativeUnits/81bb36e4-f4c6-4984-8e56-d4f8feae9e09",
"roleDefinitionId": "4d6ac14f-3453-41d0-bef9-a3e0c569773a"

More information