Entra ID Access package for onprem AD groups

MyAzQuery 171 Reputation points
2023-10-07T04:44:04.65+00:00

i wanted to create an access package for the new joiners, which contains list of onprem AD groups. but while creating access package , it says as below

Directory Synced objects are not allowed

User's image

My question is how to add onprem AD groups in this Entra ID access package ?

Microsoft Security | Microsoft Entra | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2023-10-09T08:34:20.9933333+00:00

    @MyAzQuery Thank you for reaching out to us, As I understand you are trying to add a group managed in on-premise while creating access package.

    Synced groups cant be added to access package, hence getting this error message, same has been documented here - https://learn.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-access-package-resources#add-resource-roles:~:text=resource%20role%20sections.-,Add%20a%20group%20or%20team%20resource%20role,-You%20can%20have

    User's image

    Reference: https://www.reddit.com/r/sysadmin/comments/qu5lf9/azure_access_packages_directory_synced_objects/

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.