A cloud-based identity and access management service for securing user authentication and resource access
Technically speaking, you cannot restrict "view" access, even regular accounts get to see all objects within the organization by default. Now, depending on the implementation across the various admin endpoints, you can expect different results. For example, if you login to the Microsoft 365 admin center as user with only an AU-scoped admin role assignment, you will be presented with a trimmed UI, and will only be able to see the users/groups under the AU scope. Logging in to the Azure AD/Entra ID portal with the same user will still display all objects (regardless of the setting you toggled), as technically this is a user with an admin role. He will still only be able to make changes against objects within the scope of the AU, but visibility cannot be restricted.