question

pgaddam avatar image
0 Votes"
pgaddam asked amanpreetsingh-msft answered

How to connect Cloud AAD group to VMs?

Hello

This question is regarding Azure AD Groups,
Whenever I deploy a Virtual Machine (VM) through pipeline, I am also creating a group in Azure AD through a PowerShell script with "vmName-Admin". Now after the creation of VM and AAD group, when I try to add this newly created group to the VM's local admin section through Puppet, the machine says that a group with that name doesn't exist.
Apart from the above group, I am also adding one more group which is residing on on-prem. The on-prem group could be assigned to the VM without any difficulty.
Upon digging a little bit, I found out that the "vmName-Admin" group source is "Cloud" whereas "on-prem" group source is "Windows Azure AD" respectively.

Is there a work around on how I can create a AAD group with source "Windows Azure AD" or is there a different approach to get this dynamic group get alocated to the VM as a local admin group.

windows-server-powershellazure-virtual-machinesazure-ad-group-management
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

amanpreetsingh-msft avatar image
0 Votes"
amanpreetsingh-msft answered

Hi @Pranith-3606 • Thank you for reaching out.

The source attribute specifies where the group was originally created. When the group is directly created in Azure AD, the source is set to "Cloud" and if it is created in local AD and then synced to Azure AD, the source is set to "Windows Server AD". The value of this attribute cannot be set/changed manually. If you want to use the group "vmName-Admin" with "Windows Server AD" as the source, it has to be created in the on-premises AD and synced to Azure AD. However, in that case, the group members will also be required to sync from on-prem AD. Synced groups cannot contain Cloud-only users.

Also, as of now, only Azure AD users can be added to the local groups of the "Azure AD/hybrid Joined VM" by using the below command. Adding cloud-only groups to local groups is not yet supported.

net localgroup "Administrators" /add "AzureAD\the-UPN-attribute-of-your-user"


Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.