Skip to content

Commit 7df85ae

Browse files
committed
add assign users redirect
1 parent f4ff7cb commit 7df85ae

File tree

4 files changed

+24
-183
lines changed

4 files changed

+24
-183
lines changed

.openpublishing.redirection.json

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -36710,7 +36710,12 @@
3671036710
},
3671136711
{
3671236712
"source_path": "articles/active-directory/application-access-assignment-how-to-add-assignment.md",
36713-
"redirect_url": "/azure/active-directory/manage-apps/methods-for-assigning-users-and-groups",
36713+
"redirect_url": "/azure/active-directory/manage-apps/assign-user-or-group-access-portal",
36714+
"redirect_document_id": false
36715+
},
36716+
{
36717+
"source_path": "articles/active-directory/manage-apps/methods-for-assigning-users-and-groups.md",
36718+
"redirect_url": "/azure/active-directory/manage-apps/assign-user-or-group-access-portal",
3671436719
"redirect_document_id": true
3671536720
},
3671636721
{
@@ -37040,17 +37045,17 @@
3704037045
},
3704137046
{
3704237047
"source_path": "articles/active-directory/active-directory-applications-guiding-developers-requiring-user-assignment.md",
37043-
"redirect_url": "/azure/active-directory/manage-apps/methods-for-assigning-users-and-groups",
37048+
"redirect_url": "/azure/active-directory/manage-apps/assign-user-or-group-access-portal",
3704437049
"redirect_document_id": false
3704537050
},
3704637051
{
3704737052
"source_path": "articles/active-directory/active-directory-applications-guiding-developers-assigning-users.md",
37048-
"redirect_url": "/azure/active-directory/manage-apps/methods-for-assigning-users-and-groups",
37053+
"redirect_url": "/azure/active-directory/manage-apps/assign-user-or-group-access-portal",
3704937054
"redirect_document_id": false
3705037055
},
3705137056
{
3705237057
"source_path": "articles/active-directory/active-directory-applications-guiding-developers-assigning-groups.md",
37053-
"redirect_url": "/azure/active-directory/manage-apps/methods-for-assigning-users-and-groups",
37058+
"redirect_url": "/azure/active-directory/manage-apps/assign-user-or-group-access-portal",
3705437059
"redirect_document_id": false
3705537060
},
3705637061
{

articles/active-directory/manage-apps/assign-user-or-group-access-portal.md

Lines changed: 13 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,9 @@ ms.collection: M365-identity-device-management
1818

1919
This article shows you how to assign users or groups to enterprise applications in Azure Active Directory (Azure AD), either from within the Azure portal or by using PowerShell. When you assign a user to an application, the application appears in the user's [My Apps access panel](https://myapps.microsoft.com/) for easy access. If the application exposes roles, you can also assign a specific role to the user.
2020

21-
For greater control, certain types of enterprise applications can be configured to *require* user assignment. This option blocks everyone from signing in, except those users you explicitly assign to the application. When user assignment is *not required*, unassigned users won't see the app on their My Apps access panel, but they can still sign in to the application by going directly to the application sign-in page or using the user access URL in the application's property page. For background, see [Managing access to apps](what-is-access-management.md).
21+
For greater control, certain types of enterprise applications can be configured to [require user assignment](#configure-an-application-to-require-user-assignment).
2222

23-
To assign a user or group to an enterprise app, you'll need to sign in as a global administrator, application administrator, cloud application administrator, or the assigned owner of the enterprise app.
23+
To [assign a user or group to an enterprise app](#assign-users-or-groups-to-an-app-via-the-azure-portal), you'll need to sign in as a global administrator, application administrator, cloud application administrator, or the assigned owner of the enterprise app.
2424

2525
> [!NOTE]
2626
> Group-based assignment requires Azure Active Directory Premium P1 or P2 edition. Group-based assignment is supported for Security groups only. Nested group memberships and Office 365 groups are not currently supported. For more licensing requirements for the features discussed in this article, see the [Azure Active Directory pricing page](https://azure.microsoft.com/pricing/details/active-directory).
@@ -33,7 +33,12 @@ With the following types of applications, you have the option of requiring users
3333
- Application Proxy applications that use Azure Active Directory Pre-Authentication
3434
- Applications built on the Azure AD application platform that use OAuth 2.0 / OpenID Connect Authentication after a user or admin has consented to that application.
3535

36-
When assignment is not required, either because you've set this option to **No** or because the application uses another SSO mode, users can access the application with a direct link. This setting doesn't affect whether or not an application appears on the My Apps access panel. Applications appear on users' My Apps access panels once you've assigned a user or group to the application.
36+
When user assignment is required, only those users you explicitly assign to the application will be able to sign in. They can access the app on their My Apps page or by using a direct link.
37+
38+
When assignment is *not required*, either because you've set this option to **No** or because the application uses another SSO mode, any user will be able to access the application if they have a direct link to the application or the **User Access URL** in the application’s **Properties** page.
39+
40+
This setting doesn't affect whether or not an application appears on the My Apps access panel. Applications appear on users' My Apps access panels once you've assigned a user or group to the application. For background, see [Managing access to apps](what-is-access-management.md).
41+
3742

3843
To require user assignment for an application:
3944

@@ -54,16 +59,16 @@ To require user assignment for an application:
5459

5560
## Assign users or groups to an app via the Azure portal
5661

57-
1. Sign in to the [Azure portal](https://portal.azure.com) with an administrator account, or as an owner of the application.
62+
1. Sign in to the [Azure portal](https://portal.azure.com) with a global administrator, application administrator, or cloud application administrator account, or as the assigned owner of the enterprise app.
5863
2. Select **Azure Active Directory**. In the left navigation menu, select **Enterprise applications**.
5964
3. Select the application from the list. If you don't see the application, start typing its name in the search box. Or use the filter controls to select the application type, status, or visibility, and then select **Apply**.
6065
4. In the left navigation menu, select **Users and groups**.
6166
> [!NOTE]
6267
> If you want to assign users to Microsoft Applications such as Office 365 apps, some of the these apps use PowerShell.
63-
1. Select the **Add user** button.
64-
2. On the **Add Assignment** pane, select **Users and groups**.
65-
3. Select the user or group you want to assign to the application, or start typing the name of the user or group in the search box. You can choose multiple users and groups, and your selections will appear under **Selected items**.
66-
4. When finished, click **Select**.
68+
5. Select the **Add user** button.
69+
6. On the **Add Assignment** pane, select **Users and groups**.
70+
7. Select the user or group you want to assign to the application, or start typing the name of the user or group in the search box. You can choose multiple users and groups, and your selections will appear under **Selected items**.
71+
8. When finished, click **Select**.
6772

6873
![Assign a user or group to the app](./media/assign-user-or-group-access-portal/assign-users.png)
6974

articles/active-directory/manage-apps/methods-for-assigning-users-and-groups.md

Lines changed: 0 additions & 169 deletions
This file was deleted.

articles/active-directory/manage-apps/what-is-access-management.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,9 +45,9 @@ With certain types of applications, you have the option of [requiring users to b
4545
* Application Proxy applications that use Azure Active Directory Pre-Authentication
4646
* Applications built on the Azure AD application platform that use OAuth 2.0 / OpenID Connect Authentication after a user or admin has consented to that application.Certain enterprise applications offer additional control over who is allowed to sign in.
4747

48-
When user assignment is *not required*, unassigned users don't see the app on their My Apps access panel, but they can still sign in to the application itself (known as service provider-initiated sign-on) or they can use the **User Access URL** in the application’s **Properties** page (known as identity provider-initiated sign on).
48+
When user assignment is *not required*, unassigned users don't see the app on their My Apps access panel, but they can still sign in to the application itself (also known as SP-initiated sign-on) or they can use the **User Access URL** in the application’s **Properties** page (also known as IDP-initiated sign on).
4949

50-
For some applications, the option to require user assignment isn't available in the application properties. In these cases, you can use PowerShell to set the appRoleAssignmentRequired property on the service principal.
50+
For some applications, the option to require user assignment isn't available in the application's properties. In these cases, you can use PowerShell to set the appRoleAssignmentRequired property on the service principal.
5151

5252
### Determining the user experience for accessing apps
5353

0 commit comments

Comments
 (0)