Microsoft Entra ID
Developer

Assign User Or Group Access Portal

In brief

The enterprise application page received spelling corrections in its user, group, and app-role assignment guidance.

What Entra admins need to know

No action is required; administrators can continue following the existing procedures.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For greater control, certain types of enterprise applications can be configured to require user assignment. For more information on requiring user assignment for an app, see Manage access to an application. Applications that require users to be assigned to the application must have their permissions consented by an administrator, even if the user consent policies for your directory would otherwise allow a user to consent on behalf of themselves.

Prior to integration with Microsoft Entra, your application may already have one or more users. Using the account discovery functionality, you can generate a report of all the users in your application, identify which users have matching accounts in Entra, and which users are local to your application with one click. Learn more about the account discovery functionality here. This enables you to simplify onboarding to Entra, while also pereodicallyperiodically monitoring for unauthorized access.

Prerequisites

  1. Assign the AppRole name to the $app_role_name variable. In this example, we want to assign Britta Simon the Analyst (Limited access) Role.

    $user = Get-Entrauser -ObjectId "<objectId>"
    $spo = Get-EntraServicePrincipal -ObjectId "<objectId>"
    
    #Get the ID of role assignment
    $assignments = Get-EntraServicePrincipalAppRoleAssignedTo -ObjectId $spo.ObjectId | Where {$_.PrincipalDisplayName -eq $user.DisplayName}
    
    #if you run the following, it will show you what is assigned what
    

Assign users and groups to an application using Microsoft Graph PowerShell

  1. Open an elevated Windows PowerShell command prompt.

  2. Run Connect-MgGraph -Scopes "Application.ReadWrite.All", "AppRoleAssignment.ReadWrite.All" and sign in as at least a Cloud Application Administrator.

  3. Use the following script to assign a user to an application:

    
    

Example

This example assigns the user Britta Simon to the Microsoft Workplace Analytics application using Microsoft Graph PowerShell.

  1. In PowerShell, assign the corresponding values to the variables $userId, $app_name, and $app_role_name.

    # Assign the values to the variables
    $userId = "<Britta Simon's user ID>"
    $app_name = "Workplace Analytics"
    
  2. In this example, we don't know the exact name of the application role we want to assign to Britta Simon. Run the following command to get the service principal ($sp) using the service principal display name.

    # Get the service principal for the app
    $sp = Get-MgServicePrincipal -Filter "displayName eq '$app_name'"
    
  3. Run the following command to find the app roles exposed by the service principal.

    # Get the app roles exposed by the service principal
    $appRoles = $sp.AppRoles
    # Display the app roles
    $appRoles | ForEach-Object {
        Write-Output "AppRole: $($_.DisplayName) - ID: $($_.Id)"
    }
    
  1. Assign the role name to the $app_role_name variable. In this example, we want to assign Britta Simon the Analyst (Limited access) Role.

    # Assign the values to the variables
    $app_role_name = "Analyst (Limited access)"
    $appRoleId = ($sp.AppRoles | Where-Object { $_.DisplayName -eq $app_role_name }).Id
    
  2. Prepare the parameters and run the following command to assign the user to the app role.

    # Prepare parameters for the role assignment
    $params = @{
        "PrincipalId" = $userId
        "ResourceId" = $sp.Id
        "AppRoleId" = $appRoleId
    }
    
    # Assign the user to the app role
    New-MgUserAppRoleAssignment -UserId $userId -BodyParameter $params |
        Format-List Id, AppRoleId, CreationTime, PrincipalDisplayName,
        PrincipalId, PrincipalType, ResourceDisplayName, ResourceId
    

To assign a group to an enterprise app, replace Get-MgUser with Get-MgGroup and replace New-MgUserAppRoleAssignment with New-MgGroupAppRoleAssignment.

For more information on how to assign a group to an application role, see the documentation for New-MgGroupAppRoleAssignment.

Unassign users and groups from an application using Microsoft Graph PowerShell

```
  1. Run the following command to show the list of users assigned to the application

    $assignments | Select *
    
  2. Run the following command to remove the AppRole assignment.

    Remove-MgServicePrincipalAppRoleAssignedTo -AppRoleAssignmentId  '<AppRoleAssignment-id>' -ServicePrincipalId $sp.Id
    

    GET https://graph.microsoft.com/v1.0/users/{userPrincipalName}

    
    
  3. Assign the user to the application.

    POST https://graph.microsoft.com/v1.0/servicePrincipals/{resource-servicePrincipal-id}/appRoleAssignedTo
    
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…