Make Azure Security Groups owners of other Azure Security Groups
We have added single users as group owners within the portal, this is great and keeps us from distributing the User Admin role. With that said, my team would like to add security groups as group owners as well. This would help as our user base is constantly changing and we'd rather have one group as an owner of all our groups and make changes within it compared to having to go to each group and add/delete owners as they are hired/terminated.
sesha kavuri commented
We are plaing to use new Public Preview feature "Entitlement management" , to achieve this. We create a permission package with multiple Group ownership.
If this can protect from cyclical ownership, this would help us. It enables us to have an operations group who can all manage aspects of the group without having to give them a more powerful directory role. Oterwise, create a role action that purely enables group management (create/delete/update type operations) so we can assign that role a group for AD.