Can I restrict who can edit Azure AD Security group membership?

Jinseng 41 Reputation points
2021-09-14T05:55:36.97+00:00

We have multiple administrators of various types in our tenant. Is it possible to limit who can modify a specific Security Group's membership? The security group is not configured for Azure AD Role assignment. In theory, this could be any Security group, but in this case I'm talking about the AAD DC Administrators group. I want to make sure that a very limited set of users are members of this group and that no other admins add themselves.

Thanks.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,453 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,306 Reputation points
    2021-09-14T07:38:14.267+00:00

    Hi @Jinseng • Thank you for reaching out.

    Unfortunately, this is not possible as of now. Users with Global Administrator role or any other role that includes microsoft.directory/groups/members/update permission can update members of Security groups and Microsoft 365 groups, except role-assignable groups.

    You can check Azure AD built-in roles document to see which roles include microsoft.directory/groups/members/update permission and update security group membership.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Jinseng 41 Reputation points
    2021-09-14T18:52:59.23+00:00

    Thanks for the confirmation. I was 99% sure that was the case, but it is a little disappointing. I really like the idea of using PIM to lock down a group, but it only works if the group is enabled for Azure AD Role assignment. That setting can only be enabled at group creation and is not set for the AAD DC Administrators group when enabling Azure AD Domain Services. It means anyone with User administrator (even first line support personnel) could add themselves to this group and gain Admin access to AADDS. We'll put in place paper policies and auditing checks.

    0 comments No comments