I wanted to give a selected set of users user management capability without being able to change anything in the tenant. I was able to setup delegated admin extension. But it shows a screen only to edit users. I would like to allow dedicated user admins to add/remove users from groups. Is there some way this can be achieved?
Thanks @rueben.tiow for the reply. I would also like this user to have permission to manage user groups so that they can add/remove users to specific groups depending on the team. Is that possible?
Unfortunately, the Delegated Admin Extension does not allow these Delegated Admin users to manage user groups.
If you would like to accomplish this behavior, it would be possible to invite them as a Tenant Administrator. And using the Authorization Extension to manipulate user groups/roles/permissions.
Inviting them as a tenant administrator has the apparent drawback of exposing your tenant to them. Therefore, if this is undesired, there will be no way to invite them to manage user groups.
In the meantime, I am collaborating with other team members to see if there are alternative solutions without exposing the entire tenant to the administrator user. If new information arises, I will relay that information to you.