Administrative units restrict permissions in a role to any portion of your organization that you define. You could, for example, use administrative units to delegate the Helpdesk Administrator role to regional support specialists, so they can manage users only in the region that they support. https://docs.microsoft.com/en-us/azure/active-directory/roles/administrative-units