Entra ID Group - Ability to restrict group owners from adding any user accounts

Niggie Anwar (IT Services) 0 Reputation points
2023-12-20T08:55:24.33+00:00

We have created some groups and given owner access to a few nominated users so they have the ability to add/remove members of those groups.

Whilst we have advised that only accounts with say for example have -cloud in their names can be added they can still add any type of account or any username that exists in our Entra ID.

I have explored dynamic group, however it does not satisfy our needs as once a user attribute is assigned it automatically adds them to that group. There isn't the ability to add manually users in a dynamic group.

Is there anything in the pipeline to allow restriction on groups if they are not dynamic or update dynamic with ability to add users manually?

a. by type per group

b. Ability to restrict by using regular expression (regex) per group, this would help us to restrict part name of accounts that can be added to a particular group.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.