You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:为订阅上的Azure AD组创建带部分所有者权限的自定义角色,并配置用户仅能管理指定组的成员且无法修改组设置

Hey there, let's tackle your Azure AD and subscription permission setup step by step. I've broken this into targeted parts to match your exact requirements, using Azure AD custom roles (since built-in roles can't provide this level of granularity) plus scoped assignments to lock things down properly.

1. Configure a Custom Role for Targeted Group Member Management (No Group Settings Access)

This solves your core need: letting a user add/remove members from 1-2 specific groups without allowing them to modify group settings.

  • Step 1: Navigate to Azure AD Custom Roles
    Log into the Azure Portal, go to Azure Active Directory > Roles and administrators > New custom role.
  • Step 2: Set Basic Role Details
    Name the role something clear like Limited Group Member Manager, with a description: "Can add/remove members from specified groups only; cannot modify group settings or access other groups."
  • Step 3: Select Granular Permissions
    We only want permissions for member management—avoid any permissions that let users modify group properties. Search for and select these two Azure AD directory permissions:
    • microsoft.directory/groups/members/add/action
    • microsoft.directory/groups/members/remove/action
      Double-check you don't select permissions like microsoft.directory/groups/update (which would let users change group names, privacy settings, etc.).
  • Step 4: Assign the Role to the User (Scoped to Specific Groups)
    This is the critical lock-down step:
    1. On the role assignment screen, select your target user.
    2. For the Assignment scope, choose Specific resources instead of the default global scope.
    3. Select the 1-2 groups you want the user to manage.
      This ensures the user's permissions only apply to those groups—they won't have access to modify any other groups in your tenant.
2. Create a Partial Owner Custom Role for Subscription-Linked AD Groups

If you need a role that grants limited "owner-like" access to the subscription-linked groups (beyond just member management), adjust the custom role with additional restricted permissions:

  • Step 1: Build on the Previous Custom Role
    Repeat the role creation process, but add a few limited owner-focused permissions (still avoiding group settings modification):
    • microsoft.directory/groups/owners/read (let the role holder view group owners)
    • microsoft.directory/groups/read (let them view group details without editing)
  • Step 2: Link to Subscription Permissions (If Needed)
    Since your AD group already has the Contributor role on the subscription, if you want the role holder to view the group's subscription permissions (but not modify them), add the Azure RBAC permission Microsoft.Authorization/roleAssignments/read at the subscription scope. Keep this restricted—don't grant permission to modify subscription role assignments unless absolutely necessary.
3. Validate Your Configuration

Test with the target user's account to confirm everything works as expected:

  • ✅ They can add/remove members from the specified groups
  • ❌ They get a "permission denied" error when trying to edit group names, descriptions, or privacy settings
  • ❌ They can't access or modify members of any other groups
  • ✅ The AD group's Contributor subscription permissions remain intact for group members

内容的提问来源于stack exchange,提问作者user13696433

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 10:02:48