In Dynamics AX 2012 a Windows Active Directory (AD) group could be established as a login with a set of security roles; subsequently any member of the Windows AD group could login to DynAX2012, have a user record established, and receive the group's security roles. Individual users did not need to be added in DynAX2012.
I am trying the same thing with Dynamics 365 for Finance & Operations (Dyn365FO) and Azure AD but can't seem to complete the loop. I have been able to establish an Azure AD group and assign Azure AD members to the group, and then import the group into Dyn365FO and assign security roles. But trying to login with a group member's credential (who has not been specifically added as a user in Dyn365FO but can login to the Azure AD where the group exists via portal.azure.com) I get "You are not authorized to login with your current credentials. You will be redirected to the login page in a few seconds."
Is there another step required to allow login to Dyn365FO via an Azure AD group? Maybe registering Dyn365FO as an app in the Azure AD but importing individual logins from the Azure AD into Dyn365FO works fine without adjustment. I would like to avoid setting roles for what will be 100+ logins changing several times a year (I am a university professor using Dynamics in courses). Any guidance appreciated.
*This post is locked for comments