> ## Documentation Index
> Fetch the complete documentation index at: https://support.i.moneyforward.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Assigning and unassigning apps for Entra ID-managed users

> Steps to assign and unassign SaaS apps for users managed in Microsoft Entra ID (Azure AD).

This page explains how to assign SaaS apps to Microsoft Entra ID (Azure AD) users, and how to unassign them.

#### Prerequisites

Apps and services must already be linked via the [Identity Provider Function (Microsoft Entra ID / Azure AD)](/en/integrations/4l37o2sowt-idp-entraid).

<Info>
  Currently, Microsoft Entra ID (Azure AD) is the only supported identity provider. Only users managed in Microsoft Entra ID (Azure AD) can be added to a workspace. This feature supports individual assignment by user and app only — group assignment and conditional access assignment are not supported.
</Info>

<h2 id="assign-user">
  Assign a user to an app
</h2>

1. In the service list, click **Add account** on the "Microsoft Entra ID (Azure AD)" row.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/saas-list-add-account.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=35f91612d76249f97e6204f10e01887e" alt="The service list showing an Add account button on the Microsoft Entra ID (Azure AD) row" width="1920" height="163" data-path="images/it-management/idp-account-management/app-assignment/saas-list-add-account.png" />

2. On the "Add new user account" screen, select a workspace and click **Next**.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/add-account-select-workspace.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=5ad443e8f9a3168fc991f71cc616b376" alt="The Add new user account screen with a workspace selector" width="764" height="614" data-path="images/it-management/idp-account-management/app-assignment/add-account-select-workspace.png" />

3. Select the employee to add.\
   **Existing user:** Search by name or email.\
   **New user:** Select **Register a new user in Microsoft Entra ID (Azure AD)**. Enter the display name, email address (UPN), and department (optional).\
   **App role (optional):** Set an app role if one is configured for the app.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/add-account-employee-and-role.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=ceebf84e50f4c60c31d9503df9ad0045" alt="Three screens: selecting an employee, registering a new user, and setting the app role" width="1686" height="808" data-path="images/it-management/idp-account-management/app-assignment/add-account-employee-and-role.png" />

4. Click **Register and assign** (or **Next** if you selected an existing user).

5. Once "Registration started" appears, the operation is complete. Click **Done** to close the screen.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/add-account-complete.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=1c595114181536ac567ac0c6fd01f02c" alt="The completion screen showing &#x22;Registration started&#x22;" width="786" height="542" data-path="images/it-management/idp-account-management/app-assignment/add-account-complete.png" />

<h3 id="assignment-timing">
  How long assignment takes to reflect
</h3>

Assigning a user does not take effect immediately. The expected time and required follow-up differ by app type.

| App type            | Expected time                                   | Required action                                                  |
| ------------------- | ----------------------------------------------- | ---------------------------------------------------------------- |
| SCIM-supported apps | Up to about 50 minutes                          | None (reflected automatically based on Entra ID's sync behavior) |
| Non-SCIM apps       | No automatic sync (create/delete not supported) | Manual setup is required separately                              |

You can check the assignment sync status in real time on the "Info" tab of the service detail screen.

<img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/assignment-status-processing.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=4a33d2bf697b35e4eb6d8fe8051ace9f" alt="The service detail screen showing app assignment in progress, with a per-account sync status list" width="1920" height="755" data-path="images/it-management/idp-account-management/app-assignment/assignment-status-processing.png" />

For details on how to read the status and how to resolve errors, see [Checking assignment status and errors](/en/it-management/idp-account-management/entraid-assignment-status).

<h2 id="unassign-app">
  Unassign an app
</h2>

This revokes only the IdP-side assignment, removing access to a specific SaaS app. The user's identity provider account itself is not deleted.

1. You can unassign an app using either of the following two methods.

   a. Go to **Services** > select the SaaS > open the "Accounts" tab. Click the ⋮ menu next to the target account, then click **Delete**.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/saas-account-unassign-button.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=8ed1f7276c212444e1df33a7889224fa" alt="The Accounts tab on the service screen, with Delete selected from the ⋮ menu" width="1920" height="164" data-path="images/it-management/idp-account-management/app-assignment/saas-account-unassign-button.png" />

   b. Go to **Directory** > select the account to unassign > open the "Services" tab. In the "Actions" column for the target service, click **Delete**.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/directory-service-unassign-button.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=63ebe150512034e12894ec16edb97d32" alt="The Services tab in Directory, with Delete selected in the Actions column" width="1920" height="448" data-path="images/it-management/idp-account-management/app-assignment/directory-service-unassign-button.png" />

2. On the "Unassign app" screen, confirm the target user and click **Delete**. It can take up to about 50 minutes for this to take effect.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/unassign-confirm-modal.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=ded40f75fde0a106acde3c4749ef2144" alt="The confirmation screen for unassigning an app" width="1302" height="778" data-path="images/it-management/idp-account-management/app-assignment/unassign-confirm-modal.png" />

   <Info>
     If the target user is also assigned to other apps through this identity provider, this action does not unassign those apps. Handle them individually if needed.
   </Info>

3. Once "Account deletion complete" appears, click **Close**.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/app-assignment/unassign-complete-toast.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=83d0625be4b571446b459d5a588f13a8" alt="The screen showing &#x22;Account deletion complete&#x22;" width="1004" height="132" data-path="images/it-management/idp-account-management/app-assignment/unassign-complete-toast.png" />

## Related pages

* [Identity Provider Function (Microsoft Entra ID / Azure AD)](/en/integrations/4l37o2sowt-idp-entraid)
* [Disabling and deleting an Entra ID](/en/it-management/idp-account-management/entraid-id-lifecycle)
* [Checking assignment status and errors](/en/it-management/idp-account-management/entraid-assignment-status)
