AzureAD Role Delegation to Groups
Currently in AzureAD msolroles can only be assigned to users and servicePrincipals using the add-msolRoleMember cmdlet. Groups cannot be a msol-roleMember - although the add-msolroleMember cmdlets' RoleMemberType Parameter can be set to Group. But we always get an exception which says that this value is invalid....
Usually we delegate access to resources using ActiveDirectory Groups instead of users, which makes the Management much easier. To achieve a Role Delegation to Groups we have to deploy a Powershell that synchronizes Group-Members with Role-Members of a specific role. This is a valid Workaround but a nasty one compared to a direct delegation to AzureAD Groups.
We are working on it. There is an elevation of privilege concern associated with this feature. If a group is assigned a role, any IT admin who can manage group membership can manage that group’s membership and indirectly manage who gets the role. So, we have to ensure that the feature is secure.
We are taking a staged approach to execute this feature –
Stage 1: Supporting cloud groups to be assigned to roles
Stage 2: Supporting on-prem groups to be assigned to roles
Abhijeet Kumar Sinha
Azure Active Directory Team
If privilege escalation is the issue then tie Role Assignment --> AD Group to the use of Azure AD PIM. If someone wants to implement AD Groups in roles Azure AD PIM is a requirement. That way even if users are added to a group that is a member of a role they still have to go through PIM. This would solve that issue.
Gardam, Martin (Latitude Financial) commented
We too need this feature ASAP. I would like to tie the request process for PIM role eligibility into the Azure Identity Governance workflow, so we can approve eligibility for PIM roles using this workflow. If we can assign AAD privileged roles based on AAD group, then this can tie the two processes together.
Archimedes Trajano commented
Can you add the capability of doing it through the Azure AD Go SDK so it can be Terraformed as well?
Claude Cantin commented
I opened a support ticket because I could not add an AD group to an AD admin role. I do that with my cloud subscriptions all the time, so why should I not be able to manage AD admin roles using groups? Much easier to manage that way.
The MS support person pointed me to this thread for me to give feedback.
I say, as most people in the thread do, bring on that feature. It is needed!
Come on guys, when will this finally be implemented?! Last update on February 6, almost 4 months ago.... Are you really taking this enormous omission seriously?
Taylor Knight commented
Looking forward to once this feature becomes available, we need it!
Sorry but this isn't a valid approach IMO. The IT administrators who are managing on-prem groups are the same ones who will be managing cloud resources, so what's the concern? The cloud is an extension (or replacement) of on-prem infrastructure and the same people will ultimately be doing the job. Bottom line, if I've got rights to assign access via groups on prem it's a ridiculous argument that I wouldn't be allowed to do the same in the cloud.
Definitively a must to have this feature available. When will it be available?
Vlad Scheip commented
The organization I'm working for really really needs that ASAP.
Hector Jimenez commented
Any updates on when "Stage 1" will be ready?
I am in need of this feature and the ability to customize AAD roles for attributes outside of applications.
David Hernando commented
It would definitely be a must-have ! +1
After many years, it's nice to see Microsoft has decided to start working on this "high priority". Though it sounds like you're not sure how to do it, so I guess implementation is going to be a long ways out.
JR Johnson commented
This is a blocker for us moving services to Azure for +20K devices.
Ideally we need Custom Role to provide support for microsoft.directory/devices/bitLockerRecoveryKeys/read
As well as this feature being enabled.
Gilles Bignens commented
High priority but not implemented after almost 4 years. I dare not imagine the implementation time of a low or medium priority....
Please provide us this feature !
Hannes Lagler-Gruener commented
I’ve many costumers who want that functionality too. During the implementation time I’ve published my finished solution on GitHub.
Feel free and give me a feedback.
Stefan Roth commented
+1000 This is urgently needed for better automation / management of roles assignment, any update guys?
Ayo Dada commented
This is urgently needed for better automation of roles assignment, any update guys
We are also urgently needing this - is there any update on when this will come in preview (interested) or GA?