求助:为订阅上的Azure AD组创建带部分所有者权限的自定义角色,并配置用户仅能管理指定组的成员且无法修改组设置
Hey there, let's tackle your Azure AD and subscription permission setup step by step. I've broken this into targeted parts to match your exact requirements, using Azure AD custom roles (since built-in roles can't provide this level of granularity) plus scoped assignments to lock things down properly.
This solves your core need: letting a user add/remove members from 1-2 specific groups without allowing them to modify group settings.
- Step 1: Navigate to Azure AD Custom Roles
Log into the Azure Portal, go toAzure Active Directory>Roles and administrators>New custom role. - Step 2: Set Basic Role Details
Name the role something clear likeLimited Group Member Manager, with a description: "Can add/remove members from specified groups only; cannot modify group settings or access other groups." - Step 3: Select Granular Permissions
We only want permissions for member management—avoid any permissions that let users modify group properties. Search for and select these two Azure AD directory permissions:microsoft.directory/groups/members/add/actionmicrosoft.directory/groups/members/remove/action
Double-check you don't select permissions likemicrosoft.directory/groups/update(which would let users change group names, privacy settings, etc.).
- Step 4: Assign the Role to the User (Scoped to Specific Groups)
This is the critical lock-down step:- On the role assignment screen, select your target user.
- For the Assignment scope, choose
Specific resourcesinstead of the default global scope. - Select the 1-2 groups you want the user to manage.
This ensures the user's permissions only apply to those groups—they won't have access to modify any other groups in your tenant.
If you need a role that grants limited "owner-like" access to the subscription-linked groups (beyond just member management), adjust the custom role with additional restricted permissions:
- Step 1: Build on the Previous Custom Role
Repeat the role creation process, but add a few limited owner-focused permissions (still avoiding group settings modification):microsoft.directory/groups/owners/read(let the role holder view group owners)microsoft.directory/groups/read(let them view group details without editing)
- Step 2: Link to Subscription Permissions (If Needed)
Since your AD group already has theContributorrole on the subscription, if you want the role holder to view the group's subscription permissions (but not modify them), add the Azure RBAC permissionMicrosoft.Authorization/roleAssignments/readat the subscription scope. Keep this restricted—don't grant permission to modify subscription role assignments unless absolutely necessary.
Test with the target user's account to confirm everything works as expected:
- ✅ They can add/remove members from the specified groups
- ❌ They get a "permission denied" error when trying to edit group names, descriptions, or privacy settings
- ❌ They can't access or modify members of any other groups
- ✅ The AD group's
Contributorsubscription permissions remain intact for group members
内容的提问来源于stack exchange,提问作者user13696433

