Azure AD Provisioning: Nested groups in Azure AD groups are not provisioned
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2022 01:28 AM
Hello,
Referring to On Azure, synchronizing nested groups (groups with groups inside) into ServiceNow imports empty reco...
We've configured provisioning from Azure AD to ServiceNow, and all works well. However, in some of our Azure AD groups we have groups that are members. Like this for example;
- Group = role.azuread.employee
- Members = Karen Olsen, Aidan Petro and role.azuread.part-time.employee (Group in Group)
As you can see in the exmaple, we have 2 users who are members and 1 group that are member, but it is only users that are synced to sys_user_grmember. Does anyone know if it's possible so also fetch groups?
As of on-prem AD we were able to have Nested Groups, because this value vas stored in the member attribute on the group. With this, we have a script that removes all users with specified OU location in AD, and remains with the nested groups. We then could connect nested groups in groups, but in Azure AD - this seems impossible?
This is how it looks like after provisioned;
And this is how it looks like in sys_user_grmember.list;
Please let me know if anything is unclear!
Best regards,
Adrian Holmestrand
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2022 02:48 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2022 02:53 AM

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2022 09:01 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-07-2022 06:02 PM
I have the exact same issue although we never implemented ours via AD and therefore only ever had this issue occur from AAD sync. We can see the parent group in Snow but we cannot see any sub group or users in those sub groups. Very frustrating as we want to clean up our user permissions as we still grant our access via security groups on-prem which syncs to AAD before provisioning to Snow.
It seems as though there is no re-occurring lookup for sub groups.
I hope someone from Snow helps soon, no one seems to know much about Snow, even Snow engineers 😞 (or at least volunteer to help)