Skip to main content

Notifications

Announcements

No record found.

Customer experience | Sales, Customer Insights,...
Answered

Security role from Azure AD

Posted on by 235
Hi Team,
Is it possible to add security roles to a user automatically by adding the user in a specific Azure AD group... ? Use Case - Add a user to Admin AD Group which provides him system admin role in CE too
Thanks
Mohan
  • Suggested answer
    Fubar Profile Picture
    Fubar 2,752 on at
    RE: Security role from Azure AD

    Its been a long time since I have actually set one up:

    a) can the user sign in (believe the AD Team in CRM may not list all the users assigned to it in AD just those that have logged in)

    b) user will still need a CRM licence assigned to them

    c) depending on your setup if you also have also setup a Security team added to the Instance you may still need to add the user in to that team also

    d) if the user does not see any error when logging in but a blank screen with a spinner, make sure the AAD Team in CRM has a Security Role with access to at least 1 app.

  • Mohan Prasad MAni Profile Picture
    Mohan Prasad MAni 235 on at
    RE: Security role from Azure AD

    Thanks LA,

    I did the steps and the users are not sycning to team members from AD. The AD group has three members when i associated the team the group and waited almost 4 hours, but the users are not syncing... Did i miss anything?

  • Suggested answer
    Shaina Profile Picture
    Shaina on at
    RE: Security role from Azure AD

    Hi Mohan, 

    This is something that you could refer https://docs.microsoft.com/en-us/power-platform/admin/manage-group-teams

    Regards,

    Shaina

  • Verified answer
    Fubar Profile Picture
    Fubar 2,752 on at
    RE: Security role from Azure AD

    It is possible.

    Create your Azure AD Security group (or Office Group), get the Azure AD Object Id for it.

    In CRM Create a Team,

    • Set  the Team Type to the type of Azure group.
    • Set the object Id to the Azure AD Object Id for the group you created in Azure AD
    • Assign Security Role(s) to the Team

    The add and remove members is then done by assigning the group in Azure/Office 365 not CRM (there can be an extra delay when adding and removing).

    (as the Security Roles are at Team level, you may want to look at using that Member's privilege inheritance dropdown on the Security Roles you are going to assign)

  • Suggested answer
    Adrian Begovich Profile Picture
    Adrian Begovich 21,009 Super User 2024 Season 2 on at
    RE: Security role from Azure AD

    Hi Mohan,

    Is it not currently possible to add security roles to a user automatically by adding the user in a specific Azure AD group. However, you can assign a security role to a user programmatically.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

December Spotlight Star - Muhammad Affan

Congratulations to a top community star!

Top 10 leaders for November!

Congratulations to our November super stars!

Tips for Writing Effective Suggested Answers

Best practices for providing successful forum answers ✍️

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 291,280 Super User 2024 Season 2

#2
Martin Dráb Profile Picture

Martin Dráb 230,214 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,156

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans