Skip to main content

Azure Active Directory Group - Create basic group and add member

 Azure Active Directory (AAD) Group can be helpful in multiple places to do authentication & authorization for Azure PaaS application. Currently, there are two types of AAD Group

  • Service (group): Used to manage computer and user access for a group of users. It can have users, group, device or another service principal as it's member and users. It can only have a service principal as it's the owner. 
  • Microsoft 365 (group): Used to give members access to shared email-box, files, calendar and more.. It can have only users as it's a member. It's can be users or service principal both. 

Let's see how to create AAD group (e.g. Microsoft 365 group): 

Step-1: Login to your Azure portal (https://portal.azure.com/)
 and go to Active Directory Group



Step-2: Select the group and click on Add new group



Step-3: Fill the required entries in New group form
  • Select the group type
  • Enter the group name. 
  • Enter the description. 
  • Click on Create button


Step-4: Once got created 
you can see the newly created Group under AAD => Groups tab


Step-5: Newly created AAD Group overview. 


Step-6: Newly create member will not have any member in it's member list. 


Step-7: Add member to the group  member list:
  • Click on members
  • Add member
  • Now on the right side search for the user from the search box. 
  • Here I've selected "Test User" 
  • Similarly, you can select multiple users and the will get added under "selected list" below. 
  • Once done click on "select" 


Step-8: and here member got added. 


And with this AAD Group created with one member. By default, the owner will be the person who has created this group. 

Now we can use this AAD group multiple places, like files, calendar, email-box access... even for Azure SQL access. 
The good part is as soon as we're adding a member to the AAD group, and using this group for Azure SQL login, at the same time particular user will be able to access Azure SQL. 

In next post, we'll see how to add a user to this AAD Group programmatically. 

Comments

Popular posts from this blog

EFCore - Collate function

Search in SQL server query is generally case insensitive (by default or based on database level collation). Suppose we have an employees table with a row having first-name column value as "My-First-Name", so if we want to do the case-sensitive search we have to explicitly use the related collate: In EF 5 (currently in Release Candidate version [RC.2.20475.6]) Collate function got introduced which helps us to use our specific collation based search.  C# with EF5 code sample: var employeeCaseSensitiveSearch = _dbContext.Employees .Where(x => EF.Functions.Collate(x.FirstName, "Latin1_General_CS_AS") == "my-first-name") .FirstOrDefault(); A related database query will be something like this: T-SQL: Case sensitive search (use specific collation e.g.: Latin1_General_CS_AS) SELECT * FROM dbo.Employees AS e WHERE e.FirstName Collate Latin1_General_CS_AS = 'my-first-name' Some of the useful CSharp function which g...

Azure SQL - User management with Active Directory Group

To manage the user's roles we use Service Account on OnPrem/IaaS servers. We can use this service account on our SQL Server and accordingly manage users' permissions for the users who are part of this service account. Suppose we have an Azure SQL and we want to manage set-of-users permission shall we create each-and-every users' user profile in Azure SQL and set the permissions accordingly. Obviously, we will not .  If we've anything like Service Account (or Group) on Azure we could create the user of this GROUP on Azure SQL and set its permission/role. Here comes the Azure Active Directory Group to help us.  In case if our organization has some scheduled tasks to sync Active Directory (service account) to Azure Active Directory (AAD group), already in place, there will be some delay when we add a user to the Service account and get reflected in the AAD Group. If we have a requirement that as soon as we add a user to our group we wan...

Git - Update submodule

Sometimes in the large project when we separate it in different repositories we need to take reference of one repository in another where some the sub-module concepts. Now if we move our submodule to a different repository or renaming its repo-path then we've to also update the repository where this sub-module is getting referenced. Let's see how to update the git submodule.  Step-1: First clone the repo Step-2: Open git UI to create a new local branch from master  Step-3: Open git bash -- Now run below command to (remove submodules & add them):  -- Remove submodule git submodule deinit YOUR_FIRST_REPO git rm YOUR_FIRST_REPO git commit -m "Removed submodule YOUR_FIRST_REPO" rm -rf .git/modules/YOUR_FIRST_REPO -- Add submodule git submodule add <<..YOUR_FIRST_REPO git URL>> Step-4: All good, let's push our changes to the master