Microsoft Azure AD Group Parent Child ACL Permission Inheritence

Balan Murugan 41 Reputation points
2024-12-06T14:34:49.88+00:00

I have below AD groups setup in place with parent child manner. The r-w ACL permission has been given to the Great-Grandparent AD group level. But, it is not getting propagated to the underlying Child Service Principal which is part of the Parent AD group.

At the moment, we are requesting for the r-w ACL permission for each of the child AD groups. I don't think this is the right approach.

ADLS-SOLN-SUPPLY-CHAIN-ANALYTICS-PROD-READ (Great-Grandparent Parent AD Group)

AZR-LAKE-SUPPLY-CHAIN-ANALYTICS-PROD-TEAM (GrandParent AD Group)

	AZR-LAKE-SUPPLY-CHAIN-ANALYTICS-PROD-SERVICE (Parent AD group) 

		Prod - MGS-AOHPLATFORM-ANALYTICS-SUPPLY-CHAIN-ANALYTICS (Child Service Principal)

Does the ACL permissions are inherited from Great-Grandparent all the way to the Child OR how does it work?

Can you please explain about this scenario for the solution?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
{count} votes

1 answer

Sort by: Most helpful
  1. Balan Murugan 41 Reputation points
    2024-12-06T14:36:47.73+00:00
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.