Team & access
Enterprise SSO: managing user permissions in Microsoft Entra
On the Enterprise plan, your own Entra ID decides who can use M365Assessments and with which role: assign groups to Owner, Admin, Member or Viewer on the M365Assessments enterprise application.
- Who can do this
- Owner in M365Assessments + an Entra admin for enterprise apps
- Plan
- Enterprise
- Time
- 15 minutes
Before you start
- Your organization is on the Enterprise plan (the Single sign-on & roles card on the Team page shows an Enterprise badge).
- Someone with an Entra role that can manage enterprise applications: Cloud Application Administrator, Application Administrator or Global Administrator.
- Entra ID P1 or P2 to assign groups. Assigning individual users works on any plan.
- You are an Owner in M365Assessments and sign in with an account from your organization’s own tenant.
How it works
| App role (value) | M365Assessments role |
|---|---|
Owner (M365A.Owner) | Full control, including billing, single sign-on and managing owners |
Admin (M365A.Admin) | Manage teammates and customers, consent links, run assessments |
Member (M365A.Member) | Run assessments, view reports |
Viewer (M365A.Viewer) | View customers, assessments and reports |
- Every sign-in from your tenant follows your Entra assignments. Joiners get access without an invitation; leavers lose it when you remove the assignment or disable the account.
- Someone with several assignments (for example through two groups) gets the highest role.
- No SAML or SCIM setup is involved: it works with the normal “Sign in with Microsoft”.
Step 1: Assign roles in Microsoft Entra
In the Microsoft Entra admin center, go to Enterprise applications and open M365Assessments (the app your people sign in with; it appeared when the first person signed in).
Open Properties, set Assignment required? to Yes and select Save. Now only assigned people can sign in.
Open Users and groups, select Add user/group, choose a group (or user) and the role (Owner, Admin, Member or Viewer), then Assign. Start by assigning yourself as Owner.
Important
Assign groups whose members should get the role directly: Entra doesn’t pass app roles on to members of nested groups.
Step 2: Turn it on in M365Assessments
Sign out of M365Assessments and sign back in, so your new role is part of your sign-in.
Go to Team › Single sign-on & roles. Under Test my role, check that your sign-in shows
M365A.Owner→ Owner.Under Before you turn it on, tick that “Assignment required?” is set to Yes on the M365Assessments enterprise application. and the confirmation that members from your tenant keep access only with an app role.
Choose Signed in without a role: No access (recommended) or Viewer access (Viewer only matters if you leave Assignment required off). Optionally add Linked tenants.
Select Turn on single sign-on, then Turn on to confirm. The card shows Roles follow Entra ID.
Security note
Lock-out protection: single sign-on can only be turned on by an Owner whose current sign-in already carries the Owner app role, from your own tenant. So the organization still has an Owner after the switch, and your Entra admins can always re-assign Owner.
What changes when it’s on
- People from your tenant get their role from Entra at every sign-in. Their rows on the Team page show Managed in Entra ID; change their assignment in Entra instead.
- Current members from your tenant without an assignment lose access at their next sign-in (or get Viewer, if you chose Viewer access).
- Changes apply at the next sign-in or token refresh, usually within an hour. Signing out and back in applies them immediately.
- Every change made by the sync is recorded in your organization’s audit log.
Guests, partners and linked tenants
- People from other organizations (guests, partners, contractors) sign in from their own tenant, so your assignments don't apply to them. Keep using invitations for them (Inviting teammates).
- Inviting an address from your own tenant is refused with a hint to assign a role instead.
- If your organization has a second Microsoft 365 tenant, add its tenant ID under Linked tenants. It's accepted once an Owner or Admin of your M365Assessments organization has signed in from that tenant.
Turning it off
Owners can select Turn off at any time. Everyone keeps the role they have right now, and roles are managed on the Team page again. The same happens if your organization leaves the Enterprise plan.
Troubleshooting
“Your organization manages access to M365Assessments in Entra ID…”
You have no role assignment. Ask your Entra admin to assign you (or a group you are directly in) a role, then sign in again.
AADSTS50105 at Microsoft sign-in
Assignment required is on and you are not assigned to the app. Same fix: get an assignment, then sign in again.
Test my role shows “Your current sign-in has no M365Assessments app role.”
Sign out and back in. Check that the assignment is on the M365Assessments enterprise application in the tenant you sign in with.
Turn on single sign-on is disabled
The checklist shows what’s missing. Usually: assign yourself Owner in Entra, then sign out and back in. Only Owners can change single sign-on.
The group option is missing in Users and groups
Group assignment needs Entra ID P1 or P2. Assign users individually instead.
Single sign-on isn’t available
It’s included in the Enterprise plan. Contact us to upgrade.
Last updated