logo
search
Others

How to Set Separate Administrators for Multiple Domains in Microsoft 365

Huma Ashraf ChHuma Ashraf Ch Sep 30, 2026 869 views

Question details

The user needs a way to assign separate administrators to manage different domains independently within the same Microsoft 365 tenant.

How to Assign Separate Administrators for Multiple Domains in One Microsoft 365 Tenant
Product
Microsoft 365
Device & OS
not provided
Scenario
Delegating administrative access so that one administrator can only manage users in domain A, while another manages users in domain B within a single tenant.
Observed behavior
By default, Microsoft 365 does not provide a simple capability to restrict administrative roles by domain name, making standard tenant-wide roles too broad.
Before you start

Ensure you have Global Administrator privileges in your Microsoft 365 tenant to view or configure role assignments and administrative units.

Solution 1Recommended

Use Microsoft Entra ID Administrative Units

While you cannot restrict admins by domain directly in the M365 admin center, you can use Administrative Units in Microsoft Entra ID (formerly Azure AD) to achieve scope-based administration.

Administrative Units (AUs) allow you to subdivide your organization into smaller units and assign administrators who can manage only the members of that specific unit. You can group users by their domain and assign a scoped administrator to that specific group.

1
Access Microsoft Entra admin center

Sign in to the Microsoft Entra admin center at entra.microsoft.com as a Global Administrator.

2
Create an Administrative Unit

Navigate to 'Identity' > 'Roles & admins' > 'Administrative units' and click the 'Add' button. Name the Administrative Unit (e.g., 'Domain A Users') and save it.

3
Add Users to the Unit

Open the newly created Administrative Unit, select 'Users', and add the user accounts that are associated with that specific domain.

4
Assign Scoped Roles

Select 'Roles and administrators' within the Administrative Unit. Choose a management role, such as 'User Administrator' or 'Helpdesk Administrator', and assign the specific administrator for that domain. They will now only have privileges over the users in this unit.

Use Microsoft Entra ID Administrative Units
Licensing Requirement: Using Administrative Units requires Microsoft Entra ID P1 or P2 licenses for the administrators.
Free Microsoft Office alternative

Simplify Your Workflow with WPS Office

While managing complex Microsoft 365 environments requires extensive administrative setup and costly licensing, daily document tasks shouldn't be complicated. WPS Office provides a lightweight, highly compatible alternative for your organization's standard productivity needs.

  1. 1. Visit the website: Go to the official WPS Office website.
  2. 2. Download the software: Click the 'Free Download' button to get the installation package for your operating system.
  3. 3. Install and launch: Follow the on-screen instructions to install WPS Office and begin creating documents immediately.
Highly compatible with Microsoft Word, Excel, and PowerPoint file formats.Free to use with a familiar, intuitive user interface that reduces employee training time.Lightweight installation with robust offline capabilities, requiring zero complex tenant administration.All-in-one suite combining documents, spreadsheets, presentations, and PDFs in a single tabbed window.
microsoft office alternative - wps office

Frequently Asked Questions

Can I assign a Global Administrator to only one domain in a Microsoft 365 tenant?

No, the Global Administrator role is tenant-wide by definition. To restrict admin privileges, you must use scoped roles, such as User Administrator or Exchange Administrator, and assign them via Administrative Units.

Do I need a special license to manage administrators by domain using Administrative Units?

Yes, utilizing Administrative Units in Microsoft Entra ID requires at least a Microsoft Entra ID P1 license for each scoped administrator.

Can a user manage billing for just one domain in the tenant?

Currently, Billing Administrator roles are tenant-wide. While you can separate user and password management via Administrative Units, separating billing and certain tenant-wide configurations per domain is not natively supported in a single tenant.