Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

Azure Entra nested groups and Directory Sync: Limitations and workarounds

Blog post from WorkOS

Post Details
Company
Date Published
Author
-
Word Count
1,756
Company Posts That Month
50
Language
English
Hacker News Points
-
Post removed?
No
Summary

When using Directory Sync with Azure Entra ID, a common issue arises where users in child groups are not provisioned into applications due to SCIM's lack of support for nested group expansion. Azure Entra ID supports nested groups internally, but during SCIM provisioning, only the literal membership of the assigned group is synced, excluding users in nested groups. This design choice by Microsoft can result in various operational challenges, such as users being unable to log in, unexpected group hierarchies appearing flattened, and silent permission failures. To address these issues, organizations can choose to flatten group memberships, assign child groups directly, or supplement SCIM with the Microsoft Graph API for transitive member lookups. These solutions depend on the structure of the customer's Entra directory and their ability to manage these configurations. Unlike Google Workspace, which natively supports nested groups through pull-based APIs, Entra requires careful management and documentation to avoid provisioning issues and ensure accurate user access.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 6,457 1,307 242 +28%
Secrets Management 1 1,488 268 99 +7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.