Manage roles with Entra ID groups
Choose which Microsoft Entra ID groups sync into CloudCard, and which CloudCard roles the people in each group get.
PlansProPremiumCompare plans
ForAdmins
On this page
With Microsoft Entra ID connected, you decide who gets CloudCard by choosing groups from your directory. For each group you also choose what its members can do in CloudCard. If someone is in more than one group, they get every role their groups allow.
Before you start
- Connect Microsoft Entra ID first.
- To have new people created, tick Automatically add new users from Active Directory in the connection setup. See Entra ID sync options.
Choose groups and roles
- Open the Microsoft Entra ID page: on Team Members, click Add Users, then Microsoft Entra ID import.
- Click Groups and roles.
- Use Search groups by name or description to find a group.
- Tick the group to include it.
- Under Can do in CloudCard, choose one or more roles for that group: Admin, User or Email Signature. If you don’t choose any, members get User.
- Repeat for each group you want.
- Click Save groups and roles, then Save groups and roles again in the window that opens.
CloudCard reads the groups, creates accounts and cards for anyone new, emails them an invitation, and takes you back to Team Members with a summary. The Groups and roles list on the Microsoft Entra ID page now shows each group and its roles.
See User roles for what each role can do.
Keep roles in sync, or set them once
What happens to people who already have a CloudCard account depends on Let Entra ID groups manage roles in the connection setup:
- Off: group roles are only given to people when their account is first created. Existing people keep their current roles, and you change roles by hand in CloudCard. The Groups and roles page reminds you with “These roles apply to new people only.”
- On: every sync brings everyone’s roles in line with their groups. Add someone to your Admins group in Entra ID and they become an admin in CloudCard at the next sync. Remove them from the group and the role is taken away.
Safeguards when roles sync
Even with role sync on, CloudCard won’t:
- remove the admin role from your organisation’s last active admin.
- demote the admin who is saving or syncing at that moment.
- change the roles of someone who belongs to more than one CloudCard organisation.
- touch people who aren’t in your directory at all, such as users you added by hand or from Excel.
Stop syncing a group
Untick the group on the Groups and roles page and save. If you tick it again later, CloudCard remembers the roles you’d chosen for it.
If no groups appear
If the page says “No groups found in your directory”, the app registration in Azure is usually missing the Group.Read.All permission or admin consent. See Entra ID shows “No groups found”.
Was this article helpful?
Thanks for letting us know.
Still stuck?
Send us a message and we'll know which article you were reading. Or email [email protected].