Skip to content

Commit 6efec70

Browse files
committed
per jeremy
1 parent af0c185 commit 6efec70

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/active-directory/roles/groups-concept.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ Role-assignable groups are designed to help prevent potential breaches by having
5252
- By default, only Global Administrators and Privileged Role Administrators can manage the membership of a role-assignable group, but you can delegate the management of role-assignable groups by adding group owners.
5353
- For Microsoft Graph, the *RoleManagement.ReadWrite.Directory* permission is required to be able to manage the membership of role-assignable groups. The *Group.ReadWrite.All* permission won't work.
5454
- To prevent elevation of privilege, only a Privileged Authentication Administrator or a Global Administrator can change the credentials or reset MFA or modify sensitive attributes for members and owners of a role-assignable group.
55-
- Group nesting is not supported.
55+
- Group nesting is not supported. A group can't be added as a member of a role-assignable group.
5656

5757
## Use PIM to make a group eligible for a role assignment
5858

0 commit comments

Comments
 (0)