Once single sign-on and group mapping are in place, TestCollab keeps access in sync with your directory on its own. Knowing exactly when each change lands makes planning much easier.
Roles are applied at sign-in
Each time someone signs in through Entra, TestCollab reads their current groups and app roles and brings their TestCollab roles in line with them. Move someone from Viewers to Testers and their new role is applied in TestCollab instantly after the provisioning.
Accounts are created and removed on their own
If you have set up automatic user provisioning, adding or removing someone in your directory creates or removes their TestCollab account without anyone touching TestCollab. Entra checks regularly on its own; use Provision on demand in Azure when you want a single change pushed immediately.
Making sure Entra is the only way in
If you want your directory to be the single control point for access, turn on All users must use Entra authentication on the Microsoft Entra ID settings page. Email-and-password sign-in stops working for your company, so removing someone's access in your directory removes their way in to TestCollab.
Quick reference
Change you make | When it shows up in TestCollab |
You add someone to a mapped group | At their next sign-in — or as soon as provisioning syncs, if it is set up |
You move someone between mapped groups | As soon as provisioning syncs, if it is set up |
You remove someone from a mapped group | As soon as provisioning syncs, if it is set up |
You remove someone from the application | As soon as provisioning syncs, if it is set up |
