SOLVED

Dynamic Group Membership from Nested Group

%3CLINGO-SUB%20id%3D%22lingo-sub-1800670%22%20slang%3D%22en-US%22%3EDynamic%20Group%20Membership%20from%20Nested%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1800670%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20several%20distribution%2Fsecurity%20groups%20in%20our%20on-premise%20AD%20that%20have%20been%20in%20use%20for%20years.%20We%20recently%20implemented%20a%20BI%20tool%20and%20have%20several%20automated%20emails%20being%20sent%20throughout%20the%20day%20to%20these%20groups.%20We%20are%20getting%20a%20lot%20of%20bounce%20backs%20for%20users%20that%20no%20longer%20have%20mail%20boxes%20or%20have%20been%20terminated.%20My%20first%20thought%20is%20to%20create%20new%20dynamic%20groups%20and%20change%20the%20mail-to%20addresses%20in%20the%20BI%20tool.%20The%20thought%20was%20to%20make%20a%20rule%20that%20if%20the%20user%20is%20enabled%20and%20is%20a%20member%20of%20GroupX%2C%20then%20it%20would%20be%20added%20as%20a%20member%20of%20this%20new%20dynamic%20group%20(GroupY).%20We%20would%20then%20send%20the%20reports%20to%20send%20to%26nbsp%3B%3CA%20href%3D%22mailto%3AGroupB%40domain.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EGroupB%40domain.com%3C%2FA%3E%26nbsp%3Band%20it%20would%20always%20be%20up%20to%20date%20with%20our%20AD%20changes%20leaving%20GroupA%20intact.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20I'm%20unable%20to%20find%20is%20the%20option%20to%20add%20members%20to%20a%20group%20based%20on%20another%20group%20membership.%20I%20took%20a%20Teams%20administration%20class%20about%20a%20month%20ago%20and%20I%20brought%20this%20topic%20up%20for%20another%20issue%20and%20the%20instructor%20said%20I%20would%20be%20able%20to%20do%20exactly%20what%20I'm%20wanting%20to%20do%20now%2C%20just%20never%20had%20a%20use%20for%20it%20over%20the%20last%20few%20weeks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20possible%2C%20and%20if%20so%2C%20how%20can%20I%20accomplish%20it%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1800670%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1802356%22%20slang%3D%22en-US%22%3ERe%3A%20Dynamic%20Group%20Membership%20from%20Nested%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1802356%22%20slang%3D%22en-US%22%3E%3CP%3EThere's%20no%20support%20for%20nested%20groups%20for%20either%20dynamic%20membership%20rules%20or%20directly%20adding%20a%20group.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

I have a several distribution/security groups in our on-premise AD that have been in use for years. We recently implemented a BI tool and have several automated emails being sent throughout the day to these groups. We are getting a lot of bounce backs for users that no longer have mail boxes or have been terminated. My first thought is to create new dynamic groups and change the mail-to addresses in the BI tool. The thought was to make a rule that if the user is enabled and is a member of GroupX, then it would be added as a member of this new dynamic group (GroupY). We would then send the reports to send to GroupB@domain.com and it would always be up to date with our AD changes leaving GroupA intact.

 

What I'm unable to find is the option to add members to a group based on another group membership. I took a Teams administration class about a month ago and I brought this topic up for another issue and the instructor said I would be able to do exactly what I'm wanting to do now, just never had a use for it over the last few weeks.

 

Is this possible, and if so, how can I accomplish it?

2 Replies
best response confirmed by dalbright (New Contributor)
Solution

There's no support for nested groups for either dynamic membership rules or directly adding a group. 

@dalbright 

Nesting itself is not supported in Office 365 and Azure and MS encourage to convert nested groups to office365 groups.
 
It will not add actual group rather than members and managing these permissions for now is complex since there is no nesting supported by MS in Azure or Office 365.
 
With reference to adding support for Nesting Groups in AD: 
 

As per Microsoft Admins, they are currently evaluating an option that will provide the functionality offered by nested groups, but removes the complexity nested groups adds.

 

Below are use cases that can be explored:

 

Use case A: nested group in a cloud security group inherits apps assignment
Use case B: nested group in a cloud security group inherits license assignment
Use case C: nesting groups under Office 365 groups