How to Set Separate Administrators for Multiple Domains in Microsoft 365
Question details
The user needs a way to assign separate administrators to manage different domains independently within the same Microsoft 365 tenant.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Delegating administrative access so that one administrator can only manage users in domain A, while another manages users in domain B within a single tenant.
- Observed behavior
- By default, Microsoft 365 does not provide a simple capability to restrict administrative roles by domain name, making standard tenant-wide roles too broad.
Ensure you have Global Administrator privileges in your Microsoft 365 tenant to view or configure role assignments and administrative units.
Use Microsoft Entra ID Administrative Units
While you cannot restrict admins by domain directly in the M365 admin center, you can use Administrative Units in Microsoft Entra ID (formerly Azure AD) to achieve scope-based administration.
Administrative Units (AUs) allow you to subdivide your organization into smaller units and assign administrators who can manage only the members of that specific unit. You can group users by their domain and assign a scoped administrator to that specific group.
Sign in to the Microsoft Entra admin center at entra.microsoft.com as a Global Administrator.
Navigate to 'Identity' > 'Roles & admins' > 'Administrative units' and click the 'Add' button. Name the Administrative Unit (e.g., 'Domain A Users') and save it.
Open the newly created Administrative Unit, select 'Users', and add the user accounts that are associated with that specific domain.
Select 'Roles and administrators' within the Administrative Unit. Choose a management role, such as 'User Administrator' or 'Helpdesk Administrator', and assign the specific administrator for that domain. They will now only have privileges over the users in this unit.

Submit a Feature Request to Microsoft
If scope-based administration through Administrative Units does not fully meet your requirements for strict domain separation, you can submit direct feedback to Microsoft.
Simplify Your Workflow with WPS Office
While managing complex Microsoft 365 environments requires extensive administrative setup and costly licensing, daily document tasks shouldn't be complicated. WPS Office provides a lightweight, highly compatible alternative for your organization's standard productivity needs.
- 1. Visit the website: Go to the official WPS Office website.
- 2. Download the software: Click the 'Free Download' button to get the installation package for your operating system.
- 3. Install and launch: Follow the on-screen instructions to install WPS Office and begin creating documents immediately.

Frequently Asked Questions
Can I assign a Global Administrator to only one domain in a Microsoft 365 tenant?
No, the Global Administrator role is tenant-wide by definition. To restrict admin privileges, you must use scoped roles, such as User Administrator or Exchange Administrator, and assign them via Administrative Units.
Do I need a special license to manage administrators by domain using Administrative Units?
Yes, utilizing Administrative Units in Microsoft Entra ID requires at least a Microsoft Entra ID P1 license for each scoped administrator.
Can a user manage billing for just one domain in the tenant?
Currently, Billing Administrator roles are tenant-wide. While you can separate user and password management via Administrative Units, separating billing and certain tenant-wide configurations per domain is not natively supported in a single tenant.




