IT Admins Can Now Create Nested Dynamic Azure AD Groups
Microsoft has released a new update that allows IT teams to create dynamic Azure Active Directory (Azure AD) groups based on membership in other groups. This is one of the top requests from customers and intends to address certain limitations associated with the existing nested groups structure.
With this release, IT Pros can now use the memberOf attribute to include the individual members of up to 50 groups in each dynamic group. “Unlike existing nested security groups today, memberOf dynamic groups return a flat list of members, so can be used for licensing assignment and application assignment,” the company explained.
How to create nested Azure AD dynamic group
Microsoft added that IT admins will be able to set up dynamic groups via Azure portal, PowerShell, and Microsoft Graph. However, they will need to have the required permissions (i.e, Global Administrator, Intune Administrator, or User Administrator). It is important to note that the rule editor doesn’t support memberOf dynamic groups, and IT Pros will need to type the rule manually.
- Sign in to the Azure portal and select Azure Active Directory >> Groups, and then choose the New group option.
- Enter all the required information related to the group. IT admins can set the group type as “Microsoft 365/Security” and the membership type as “Dynamic Device/Dynamic User.”
- Now, select Add dynamic query and click the Edit option to type the rule in the Rule syntax box. For instance:
- User rule — user.memberof -any (group.objectId -in [‘groupId’, ‘groupId’])
- Device rule — device.memberof -any (group.objectId -in [‘groupId’, ‘groupId’])
- Finally, click the OK button and then choose the Create group option.
Microsoft is rolling out these dynamic group improvements in preview to customers with an Azure AD Premium license. Keep in mind that this preview release doesn’t allow users to create more than 500 dynamic groups. Microsoft has also outlined a couple of other limitations, and we invite you to check out this support document for additional information.
More in Azure Active Directory
Microsoft Releases Azure AD Certificate-Based Authentication Support on iOS and Android
Nov 2, 2022 | Rabia Noureen
Azure AD Conditional Access Policies Get Support for App Filters
Nov 1, 2022 | Rabia Noureen
Budget for Operational Resilience in 2023
Oct 20, 2022 | Russell Smith
Microsoft Adds Authentication Strength Support to Conditional Access Policies
Oct 17, 2022 | Rabia Noureen
Azure Active Directory Premium P1 vs. P2: A Features Comparison
Oct 14, 2022 | Arian Modiramani
Microsoft Blocks Unmanaged Azure AD Guest Accounts
Sep 6, 2022 | Rabia Noureen
Most popular on petri