Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Permissions required to run Remove-AzureRMAdGroup

I'm using an SPN to remove an Azure AD group (Remove-AzureRMAdGroup), but get the error insufficient privileges.

I granted the SPN the following permissions:

Active Directory Graph (2) - Application Read and write all applications - Application Read and write directory data

Microsoft Graph (1) - Application Read and write groups

What permissions are apparently missing here? If we assign the SPN the Azure AD role UserAccountAdmin it works, but we'd prefer to have least privileged access.

like image 357
Don Avatar asked Oct 20 '25 05:10

Don


1 Answers

Currently, the Read and write directory data permission does not include the ability to do any deletions such as deleting groups. What you need is microsoft.directory/groups/delete permission.

enter image description here

But there is no support today for custom roles in Azure Active Directory. Only the predefined Administrator Roles. You have to grant the SPN the Azure AD role User administrator role which include group deletion permission.

Here are the steps.

like image 56
Tony Ju Avatar answered Oct 23 '25 01:10

Tony Ju



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!