Can an user with User Administrator role add an Azure AD Joined \ Registered device to a Group

Shridhar Srinivasan 220 Reputation points
2023-08-03T06:21:42.6+00:00

Can an user with User Administrator role add an Azure AD Joined \ Registered device to a Group

  • The Group can be Security Group or Microsoft 365 Group
  • Membership of the Group is set to Assigned
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 119.5K Reputation points MVP Volunteer Moderator
    2023-08-03T06:26:47.5333333+00:00

    They can, yes. In the future, you can refer to this article for the minimum role required for certain admin operation: https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task#groups

    1 person found this answer helpful.

  2. Harpreet Singh Matharoo 8,396 Reputation points Microsoft Employee Moderator
    2023-08-03T06:45:10.7333333+00:00

    Hello @Shridhar Srinivasan ,

    Thank you for reaching out. I would like to confirm that User Administrator can manage add and remove member from Azure AD Groups. With regards to adding device User Admininstrators can add or remove device from the group. However please note that Devices can only be added to Security Enabled groups as stated on following documentation link: https://learn.microsoft.com/en-us/mem/intune/fundamentals/groups-add

    User's image

    I hope this helps and hence would request you to please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.