Skip to main content

Give people the right role using Entra groups

Stop assigning roles one person at a time. Map an Entra group or app role to a TestCollab role once, and everyone in that group gets the right access automatically.

Who does this: the TestCollab administrator. Your Entra administrator needs to have completed the app registration first, including the Microsoft Graph permissions and admin consent.

How it works

You decide, once, what each Entra group or app role means in TestCollab - for example, everyone in QA Engineering becomes a Tester, and everyone in Product becomes a Viewer.

From then on, TestCollab reads a person's groups every time they sign in and gives them exactly the roles those groups earn. Roles you assign by hand in TestCollab are left alone. Only roles that came from a group mapping are managed this way.

Open the mapping wizard

Go to Enterprise → Single Sign On → Microsoft Entra ID. Under Group-based access control, select Set up group mapping.

The button becomes available once you have saved your Directory (tenant) ID and Application (client) ID.

Step 1 — Detect from Entra

Select Detect from a Microsoft sign-in and sign in once with your Microsoft account. TestCollab reads the security groups in your directory and the app roles defined for the application, and uses them to fill in the choices on the next step.

This step only gathers names. It does not give anyone access.

If you would rather not sign in, skip ahead and add groups or app roles by hand on the next step.

Step 2 — Assign TestCollab roles

You will see one card per group or app role. For each one, set:

  • TestCollab role — the role its members should get. Choose No access to leave that group out.

  • ProjectsAll for every project in your company, or Select to pick specific projects.

  • Priority — which mapping wins when someone belongs to more than one. 1 is the highest priority, 2 comes next, and so on.

Use Add group / role if you want to add a value that was not detected.

Step 3 - Review and save

Check the summary - each line reads group → role → projects → priority — then select Save mapping.

Your saved mapping now appears on the single sign-on page, so you can see at a glance who gets what.

Good to know

  • Roles apply at sign-in. Each time someone signs in through Entra, their roles are brought in line with their current groups. See How access changes take effect.

  • Groups and app roles both work. Use whichever your directory is organised around, or mix the two.

  • Priority settles overlaps. Someone in both QA Leads (priority 1) and QA Engineers (priority 2) gets the role from QA Leads on the projects both cover.

Did this answer your question?