Kind of Entra group used to grant resource access. Its members, added by assignment or by dynamic rules, may be users, devices or service principals.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104SC-500AZ-802DP-600DP-700SC-401
Each book explains Security group in context, with comparison tables and the common traps.
Terms in this definition
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
Related terms
- Build Administrators
A project security group in Azure DevOps that looks after pipelines and, by default, has Administrator rights on every agent pool.
- EDM_DataUploaders
Only accounts in this security group can upload exact data match hashes with the EDM Upload Agent.
- Enrollment time grouping
An enrolment policy setting that puts devices into a static Microsoft Entra security group as they enrol, not later on, so their apps and policies are there at first check-in. The Intune Provisioning Client service principal owns the group.
- Force push
An Azure Repos permission that allows rewriting history and deleting branches and tags. By default no security group has it, although whoever creates a branch gets it on that branch.
- PIM for Groups
A part of Microsoft Entra Privileged Identity Management that lets people become members or owners of a security group or Microsoft 365 group only when needed and only for a limited time. Activation can be made to require approval, a justification or MFA, as with role activation.
- Role group
A bundle of Microsoft Purview roles. Any user or security group you add gets every permission in the bundle; you manage them from Settings > Roles and scopes.
- Shadow group
Since OUs can't receive permissions or fine-grained password policies directly, administrators keep a security group whose members mirror the users in an OU, normally maintained by a script.