Can we add an On-premise AD Group as Owner of an Azure AD Group?

AiswaryaH-7390 0 Reputation points
2024-05-06T13:01:33.7533333+00:00

Can we add an On-premise AD Group as Owner of an Azure AD Group?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
25,048 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Alfredo Revilla - Upwork Top Talent | IAM SWE SWA 27,521 Reputation points Moderator
    2024-05-06T14:15:03.7033333+00:00

    Hello. That's not possible.

    Let me know if you need additional or more detailed guidance. If the answer was helpful, please accept it and rate it so that others facing a similar issue can easily find a solution.

    0 comments No comments

  2. Akhilesh Vallamkonda 15,315 Reputation points Microsoft External Staff Moderator
    2024-05-10T05:55:35.4333333+00:00

    Hi @AiswaryaH-7390

    Thank you for your post!

    To answer your question, you cannot add an owner to an Azure AD group that is synchronized from an on-premises server because the groups are managed in the on-premises directory and not directly in Azure AD

    By default, security groups that are synchronized from on-premises Active Directory to Azure AD are not allowed to be owners of Azure AD groups. This is because security groups are typically used for granting access to resources and allowing them to be owners of Azure AD groups could lead to unintended access to sensitive resources.

    If you would like to Change to synchronized groups must be made in the on-premises Active Directory.

    If you have set group owners in the on-premises AD in the “Managed by” field the group details like name and members are getting synced, the owner of the group is not synced to Azure AD
    Here is the full list of attributes that are synchronized by AD Connect. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-sync-attributes-synchronized

    Hope this helps. Do let us know if you any further queries.

    Thanks.

    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.