-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add Azure AD Group to Azure AD Enterprise Application #14016
Comments
add to S172 |
Azure CLI currently doesn't have a command for Adding Azure AD Group to Azure AD Enterprise Application. The doc Assign a user or group to an enterprise app in Azure Active Directory mentions alternatives for how to do that in Azure Portal and PowerShell. By capturing the network trace, I saw Azure Portal is calling an internal AppRoleAssignments API. POST https://main.iam.ad.ext.azure.com/api/ManagedApplications/60f762f9-4b9d-4819-8447-b96770d393f7/AppRoleAssignments
{
"objectId": "60f762f9-4b9d-4819-8447-b96770d393f7",
"applicationRoleId": "",
"userId": "5963f50c-7c43-405c-af7e-53294de76abd",
"groupId": null,
"passwordSSOCredentials": null,
"automaticManagedEnabled": false,
"rolloverFrequencyInDays": 0
} However, it looks a little different from appRoleAssignment in MS Graph API. I tried this API but got an error:
Let me further confirm with AAD team about how to do it with REST API. For examples about using MS Graph API, you may check #12946. |
I need to add a group to an Azure AD Enterprise application (Default Access). How do I do this using Azure CLI? This is possible using the portal UI. Is this possible with Azure CLI?
Greetings Damien
The text was updated successfully, but these errors were encountered: