IT Admins Can Now Create Nested Dynamic Azure AD Groups
Microsoft has released a new update that allows IT teams to create dynamic Azure Active Directory (Azure AD) groups based on membership in other groups. This is one of the top requests from customers and intends to address certain limitations associated with the existing nested groups structure.
With this release, IT Pros can now use the memberOf attribute to include the individual members of up to 50 groups in each dynamic group. “Unlike existing nested security groups today, memberOf dynamic groups return a flat list of members, so can be used for licensing assignment and application assignment,” the company explained.
How to create nested Azure AD dynamic group
Microsoft added that IT admins will be able to set up dynamic groups via Azure portal, PowerShell, and Microsoft Graph. However, they will need to have the required permissions (i.e, Global Administrator, Intune Administrator, or User Administrator). It is important to note that the rule editor doesn’t support memberOf dynamic groups, and IT Pros will need to type the rule manually.
- Sign in to the Azure portal and select Azure Active Directory >> Groups, and then choose the New group option.
- Enter all the required information related to the group. IT admins can set the group type as “Microsoft 365/Security” and the membership type as “Dynamic Device/Dynamic User.”
- Now, select Add dynamic query and click the Edit option to type the rule in the Rule syntax box. For instance:
- User rule — user.memberof -any (group.objectId -in [‘groupId’, ‘groupId’])
- Device rule — device.memberof -any (group.objectId -in [‘groupId’, ‘groupId’])
- Finally, click the OK button and then choose the Create group option.
Microsoft is rolling out these dynamic group improvements in preview to customers with an Azure AD Premium license. Keep in mind that this preview release doesn’t allow users to create more than 500 dynamic groups. Microsoft has also outlined a couple of other limitations, and we invite you to check out this support document for additional information.
More in Azure Active Directory
IT Admins Get New Azure AD Temporary Access Pass Feature to Create Time-Limited Passcodes
Jun 28, 2022 | Rabia Noureen
Microsoft Entra Verified ID Now Lets Users Recover Lost Credentials
Jun 23, 2022 | Rabia Noureen
IT Admins Get New Features for Managing Microsoft 365 App Updates
Jun 21, 2022 | Rabia Noureen
Microsoft's Out-Of-Band Patch Fixes Microsoft 365 and Azure AD Sign-In Issues on ARM Devices
Jun 21, 2022 | Rabia Noureen
Microsoft is Investigating Sign-In Issues Affecting Microsoft 365 and Azure AD on ARM Devices
Jun 20, 2022 | Rabia Noureen
Why You Should Restrict Access to Office 365 Using Microsoft Conditional Access Policies
Jun 15, 2022 | Liam Cleary
Most popular on petri