Share via

Failed to add group membership

Amparo Gomez Salazar 20 Reputation points
2025-05-20T22:42:44.22+00:00

Hi comnunity team,

I have a question, Actually my account in Microsoft Entra ID has assigned the role "Directory Readers" but for my activities I need to Add memberships to groups for SSO access.

I don't want an admin role, I only need permissions for add miemberships to groups.

¿What role can I have for this action only?

Thanks for your help.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author

Andy David - MVP 160.2K Reputation points MVP Volunteer Moderator
2025-05-20T23:56:16.35+00:00

If you cant have an admin role, then you need to be an owner of the group to update the membership.

Was this answer helpful?

1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Jyotishree Moharana 1,865 Reputation points Microsoft External Staff Moderator
    2025-05-21T14:19:41.0633333+00:00

    Hello @Amparo Gomez Salazar,

    To add on to the already provided information, if you want to review more details on the Group administrator role or the least privilege required to perform group modification please refer below documents.

    Groups-administrator
    Concept-learn-about-groups
    Assign-user-or-group-access-portal

    Was this answer helpful?

    1 person found this answer helpful.

  2. Megan Truong 800 Reputation points
    2025-05-21T08:15:48.3466667+00:00

    Hello @Amparo Gomez Salazar ,
    Thank you for contacting Q&A Forum. If you don’t want an admin role but you still need permissions for adding memberships to groups, here are 2 scenarios you can consider:

    If you wish to add memberships for groups that you create or got assigned to, the most suitable role for you is Group Owner. You can add or remove members, manage group settings (descriptions, subscriptions, name, etc,...), approve or deny join requests,.... This would be ideal for managing specific groups or least privilege access (no broader directory permissions)

    If you want to manage any group in the directory and assign roles or manage group-based policies outside of your own groups, Group Administrator would be suitable in this scenario. This role allows a user to create and manage all aspects of groups and group settings, add/remove members from any group (including security and Microsoft 365 groups) and manage group membership for access control and SSO scenarios.

    In summary, Group Owner is enough for specific groups and least privilege access which could fit your case. For broader control, consider having Group Administrator as your role.
    Kindly let me know if this work for you and please let me know if you have any further question.

    If I have answered your question, please accept this as answer as a token of appreciation and don't forget to thumbs up for "Was it helpful"!

    Best regards,
    Megan

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.