When Google started, when we assigned an admin role to a user, they only could see the ones assigned to them to manage. Now and for a few years it’s really messy as no matter if you assign a user just one OU they can see all in the company and even access it.
Is there anything planned to restore the view so admin users can only see the ones they have access to?
You can not mix local and global admin rights when you create custom admin roles, though.
So if you want a user to be able to manage passwords in one OU, but also manage groups, you can’t put both those admin rights in the same admin role, because the Groups admin right, which is global, will override the local password right.
You have to assign those rights as separate roles.