Home

Azure AD Group Base Licensing

%3CLINGO-SUB%20id%3D%22lingo-sub-288727%22%20slang%3D%22en-US%22%3EAzure%20AD%20Group%20Base%20Licensing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-288727%22%20slang%3D%22en-US%22%3E%3CP%3EWanting%20to%20move%20to%20Group%20base%20licensing%3B%20however%2C%20Azure%20AD%20having%20issues%20reading%20the%20membership%20from%20a%20MIM%20manage%20mail%20enable%20security%20group.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20have%20a%20MIM%20group%20with%20a%20mail%20nickname%20%22GROUP_NAME%22%20and%20the%20Dynamic%20Membership%20Rule%20((user.accountEnabled%20-eq%20True)%20-and%20user.mailNickName%20-eq%20%22GROUP_NAME%22).%20It's%20been%20over%20a%20week%20and%20still%20no%20members.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20MIM%20mail%20enable%20security%20group%20has%20four%20levels%20of%20nested%20groups%2C%20this%20group%20sync%20to%20Azure%20using%20one%20version%20behind%20the%20lastest%20version%20of%20Azure%20AD%20Connect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestion%3A%20Does%20a%20Azure%20AD%20Dynamic%20Group%20using%20Dynamic%20Membership%20Rule%20have%20an%20issue%20reading%20nested%20groups%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20You%2C%3C%2FP%3E%3CP%3E-Larry%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-288727%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-288760%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Group%20Base%20Licensing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-288760%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Larry%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYour%20suspicion%20is%20correct%20-%20at%20this%20time%2C%20Azure%20AD%20group-based%20licensing%20does%20not%20support%20nested%20groups%3A%26nbsp%3B%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fusers-groups-roles%2Flicensing-group-advanced%23limitations-and-known-issues%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20AD%20group-based%20licensing%20limitations%20and%20known%20issues%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20looks%20like%20they%20are%20working%20on%20it%20as%20it%20is%20a%20%3CA%20href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F169401-azure-active-directory%2Fsuggestions%2F15718164-add-support-for-nested-groups-in-azure-ad-app-acc%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Erequested%20change%20on%20User%20Voice%3C%2FA%3E%2C%20but%20never%20hurts%20to%20upvote%20to%20let%20them%20know%20you%20still%20care!%26nbsp%3B%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Larry Jones
Contributor

Wanting to move to Group base licensing; however, Azure AD having issues reading the membership from a MIM manage mail enable security group.


I have a MIM group with a mail nickname "GROUP_NAME" and the Dynamic Membership Rule ((user.accountEnabled -eq True) -and user.mailNickName -eq "GROUP_NAME"). It's been over a week and still no members.

 

This MIM mail enable security group has four levels of nested groups, this group sync to Azure using one version behind the lastest version of Azure AD Connect.

 

Question: Does a Azure AD Dynamic Group using Dynamic Membership Rule have an issue reading nested groups?

 

Thank You,

-Larry

1 Reply
Highlighted

Hi Larry,

 

Your suspicion is correct - at this time, Azure AD group-based licensing does not support nested groups:  Azure AD group-based licensing limitations and known issues

 

It looks like they are working on it as it is a requested change on User Voice, but never hurts to upvote to let them know you still care!  :)