Skip to main content
This page explains how to assign SaaS apps to Microsoft Entra ID (Azure AD) users, and how to unassign them.

Prerequisites

Apps and services must already be linked via the Identity Provider Function (Microsoft Entra ID / Azure AD).
Currently, Microsoft Entra ID (Azure AD) is the only supported identity provider. Only users managed in Microsoft Entra ID (Azure AD) can be added to a workspace. This feature supports individual assignment by user and app only — group assignment and conditional access assignment are not supported.

Assign a user to an app

  1. In the service list, click Add account on the “Microsoft Entra ID (Azure AD)” row. The service list showing an Add account button on the Microsoft Entra ID (Azure AD) row
  2. On the “Add new user account” screen, select a workspace and click Next. The Add new user account screen with a workspace selector
  3. Select the employee to add.
    Existing user: Search by name or email.
    New user: Select Register a new user in Microsoft Entra ID (Azure AD). Enter the display name, email address (UPN), and department (optional).
    App role (optional): Set an app role if one is configured for the app.
    Three screens: selecting an employee, registering a new user, and setting the app role
  4. Click Register and assign (or Next if you selected an existing user).
  5. Once “Registration started” appears, the operation is complete. Click Done to close the screen. The completion screen showing "Registration started"

How long assignment takes to reflect

Assigning a user does not take effect immediately. The expected time and required follow-up differ by app type. You can check the assignment sync status in real time on the “Info” tab of the service detail screen. The service detail screen showing app assignment in progress, with a per-account sync status list For details on how to read the status and how to resolve errors, see Checking assignment status and errors.

Unassign an app

This revokes only the IdP-side assignment, removing access to a specific SaaS app. The user’s identity provider account itself is not deleted.
  1. You can unassign an app using either of the following two methods. a. Go to Services > select the SaaS > open the “Accounts” tab. Click the ⋮ menu next to the target account, then click Delete. The Accounts tab on the service screen, with Delete selected from the ⋮ menu b. Go to Directory > select the account to unassign > open the “Services” tab. In the “Actions” column for the target service, click Delete. The Services tab in Directory, with Delete selected in the Actions column
  2. On the “Unassign app” screen, confirm the target user and click Delete. It can take up to about 50 minutes for this to take effect. The confirmation screen for unassigning an app
    If the target user is also assigned to other apps through this identity provider, this action does not unassign those apps. Handle them individually if needed.
  3. Once “Account deletion complete” appears, click Close. The screen showing "Account deletion complete"
最終更新日 2026年8月26日