Entra ID shows "No groups found"

Fix "No groups found in your directory" and other group errors when you set up roles from Microsoft Entra ID groups.

PlansProPremiumCompare plans

ForAdmins

On this page

When you open Groups and roles for your Microsoft Entra ID connection, you might see:

No groups found in your directory “CloudCard signed in to Microsoft Entra ID but found no groups to import. Check that the app registration has the Group.Read.All application permission and that admin consent has been granted for it.”

This means CloudCard connected to Microsoft successfully, but Microsoft returned an empty list of groups.

Why it happens

  • The app registration is in a different tenant from the one with your groups.
  • Your directory has no groups yet.
  • The Group.Read.All permission is missing, was added as a delegated permission instead of an application permission, or admin consent hasn’t been granted.

Fix it

  1. In the Azure portal, open App registrations and select the CloudCard app registration.
  2. Go to API permissions.
  3. Check that Microsoft Graph has these Application permissions (not Delegated):
    • Group.Read.All
    • User.Read.All
  4. If either is missing, add it.
  5. Click Grant admin consent for your organisation. The status for each permission should show it’s granted.
  6. Check the tenant ID in CloudCard matches the tenant that has your groups. On the No groups found message, click Review the connection to see your connection details.
  7. Go back to Groups and roles and reload the page.

New permissions can take a few minutes to apply in Microsoft.

MessageWhat to do
“Entra ID error message: …” followed by Microsoft’s text, such as “Insufficient privileges”The permission or consent is missing. Follow the steps above.
“CloudCard signed in to Microsoft Entra ID but could not read your groups. Check that the Group.Read.All permission is still granted.”Someone removed the permission or consent. Grant it again.
“The client secret may have expired.”See “The client secret may have expired”.

A group is there but some people are missing

CloudCard only syncs people who are direct members of a group. Members of nested groups inside it aren’t included. Add those people to the group directly.

See Manage roles with Entra ID groups and Connect Microsoft Entra ID.

Still stuck? Contact support.

Still stuck?

Send us a message and we'll know which article you were reading. Or email [email protected].

Contact support