Team & access

Enterprise SSO: managing user permissions in Microsoft Entra

On the Enterprise plan, your own Entra ID decides who can use M365Assessments and with which role: assign groups to Owner, Admin, Member or Viewer on the M365Assessments enterprise application.

Who can do this
Owner in M365Assessments + an Entra admin for enterprise apps
Plan
Enterprise
Time
15 minutes

Before you start

  • Your organization is on the Enterprise plan (the Single sign-on & roles card on the Team page shows an Enterprise badge).
  • Someone with an Entra role that can manage enterprise applications: Cloud Application Administrator, Application Administrator or Global Administrator.
  • Entra ID P1 or P2 to assign groups. Assigning individual users works on any plan.
  • You are an Owner in M365Assessments and sign in with an account from your organization’s own tenant.

How it works

Groups mapped to app rolesGroups in your Microsoft Entra tenant are assigned app roles on the M365Assessments enterprise application; at every sign-in the role is applied to the person's M365Assessments membership. Your Entra groupsApp role on "M365Assessments"In M365Assessments SG-M365A-Owners SG-M365A-Admins SG-SecOps-Analysts SG-Account-Managers M365A.Owner M365A.Admin M365A.Member M365A.Viewer Owner Admin Member Viewer each sign-in
App roles
App role (value)M365Assessments role
Owner (M365A.Owner)Full control, including billing, single sign-on and managing owners
Admin (M365A.Admin)Manage teammates and customers, consent links, run assessments
Member (M365A.Member)Run assessments, view reports
Viewer (M365A.Viewer)View customers, assessments and reports
  • Every sign-in from your tenant follows your Entra assignments. Joiners get access without an invitation; leavers lose it when you remove the assignment or disable the account.
  • Someone with several assignments (for example through two groups) gets the highest role.
  • No SAML or SCIM setup is involved: it works with the normal “Sign in with Microsoft”.

Step 1: Assign roles in Microsoft Entra

  1. In the Microsoft Entra admin center, go to Enterprise applications and open M365Assessments (the app your people sign in with; it appeared when the first person signed in).

  2. Open Properties, set Assignment required? to Yes and select Save. Now only assigned people can sign in.

  3. Open Users and groups, select Add user/group, choose a group (or user) and the role (Owner, Admin, Member or Viewer), then Assign. Start by assigning yourself as Owner.

Important

Assign groups whose members should get the role directly: Entra doesn’t pass app roles on to members of nested groups.

Step 2: Turn it on in M365Assessments

  1. Sign out of M365Assessments and sign back in, so your new role is part of your sign-in.

  2. Go to TeamSingle sign-on & roles. Under Test my role, check that your sign-in shows M365A.Owner → Owner.

  3. Under Before you turn it on, tick that “Assignment required?” is set to Yes on the M365Assessments enterprise application. and the confirmation that members from your tenant keep access only with an app role.

  4. Choose Signed in without a role: No access (recommended) or Viewer access (Viewer only matters if you leave Assignment required off). Optionally add Linked tenants.

  5. Select Turn on single sign-on, then Turn on to confirm. The card shows Roles follow Entra ID.

Security note

Lock-out protection: single sign-on can only be turned on by an Owner whose current sign-in already carries the Owner app role, from your own tenant. So the organization still has an Owner after the switch, and your Entra admins can always re-assign Owner.

What changes when it’s on

  • People from your tenant get their role from Entra at every sign-in. Their rows on the Team page show Managed in Entra ID; change their assignment in Entra instead.
  • Current members from your tenant without an assignment lose access at their next sign-in (or get Viewer, if you chose Viewer access).
  • Changes apply at the next sign-in or token refresh, usually within an hour. Signing out and back in applies them immediately.
  • Every change made by the sync is recorded in your organization’s audit log.

Guests, partners and linked tenants

  • People from other organizations (guests, partners, contractors) sign in from their own tenant, so your assignments don't apply to them. Keep using invitations for them (Inviting teammates).
  • Inviting an address from your own tenant is refused with a hint to assign a role instead.
  • If your organization has a second Microsoft 365 tenant, add its tenant ID under Linked tenants. It's accepted once an Owner or Admin of your M365Assessments organization has signed in from that tenant.

Turning it off

Owners can select Turn off at any time. Everyone keeps the role they have right now, and roles are managed on the Team page again. The same happens if your organization leaves the Enterprise plan.

Troubleshooting

“Your organization manages access to M365Assessments in Entra ID…”

You have no role assignment. Ask your Entra admin to assign you (or a group you are directly in) a role, then sign in again.

AADSTS50105 at Microsoft sign-in

Assignment required is on and you are not assigned to the app. Same fix: get an assignment, then sign in again.

Test my role shows “Your current sign-in has no M365Assessments app role.”

Sign out and back in. Check that the assignment is on the M365Assessments enterprise application in the tenant you sign in with.

Turn on single sign-on is disabled

The checklist shows what’s missing. Usually: assign yourself Owner in Entra, then sign out and back in. Only Owners can change single sign-on.

The group option is missing in Users and groups

Group assignment needs Entra ID P1 or P2. Assign users individually instead.

Single sign-on isn’t available

It’s included in the Enterprise plan. Contact us to upgrade.

Last updated

Can't find what you need?

Our team is happy to help. Missing an article? Suggest it on the Feedback board in the app and vote for the ones you want.