You need to delegate the ability to reset passwords for users in the 'Sales' department to a local helpdesk lead. You want to ensure the helpdesk lead cannot manage users in any other department. What should you create?
Administrative Units are the correct tool for this requirement. By placing the Sales users into an AU, you can then assign the 'Password Administrator' role to the helpdesk lead scoped specifically to that AU. This limits their authority strictly to the members of that unit, protecting other users.
Why this answer
Administrative Units (AUs) provide a way to define a boundary for administrative delegation within a Microsoft Entra tenant. This is vital for large organizations that need to distribute management tasks to regional or departmental IT staff without granting them broad permissions across the entire directory, adhering to the principle of least privilege.