UniAsset
Home/Knowledge Base/Users & People/Group to Role Mapping (Entra ID)
Back to Users & People

Group to Role Mapping (Entra ID)

5 minIntermediateLast updated: January 2, 2026

Overview

Group → Role Mapping lets you connect Microsoft Entra ID groups to UniAsset roles. When a user signs in with Microsoft, UniAsset reads their group membership and assigns the appropriate role automatically. Roles stay in sync with your directory — no manual reassignment needed when people change teams.

Requirements

  • Available on: Cosmos
  • Roles: Owner — the Integrations area is Owner-only
  • Prerequisite: Microsoft Entra ID must be connected. See Connecting Microsoft Entra ID.

Available roles

Four UniAsset roles can be mapped from Entra groups:

RoleAccess level
OwnerEverything, including users, organization settings, and billing
ManagerCreate and update assets, assign, manage maintenance, view reports
EmployeeRead and update assets, complete maintenance, check items out and in
ViewerRead assets, categories, departments, and checkouts

Admin cannot be assigned through a group mapping. Assign it directly at Dashboard → Users if someone needs it.

Full breakdown of what each role can do: Roles and permissions.

⚠️ WARNING: Mapping a group to the Owner role gives every member of that group full system access including billing. Reserve this for a single trusted administrator account, not a group.

Setting Up Group → Role Mapping

Step 1: Open Entra ID Settings

  1. Sign in as the Owner.
  2. Go to Settings → Integrations.
  3. Open Microsoft Entra ID.

Step 2: Open Group Mappings

  1. Under the connected tenant, click Group → Role Mapping
  2. UniAsset fetches your Entra groups and displays them in a list

💡 TIP: If your group list is empty or outdated, click Refresh Groups to pull the latest list from your directory.

Step 3: Assign Roles to Groups

For each Entra group you want to map:

  1. Find the group in the list
  2. Use the Role dropdown next to the group name to select a role
  3. Repeat for each group that should have a mapped role

Groups with no role selected are ignored — users in those groups receive the default role (Employee) if auto-provisioning is on, or their manually assigned role if they were invited directly.

Step 4: Save Mappings

  1. Click Save Mappings
  2. A confirmation message confirms the mappings are active

How Role Resolution Works

Mappings are applied at sign-in time, not in advance.

When a user signs in with Microsoft:

  1. UniAsset reads their current Entra group membership
  2. It checks which of their groups have a role mapping
  3. If multiple mapped groups apply, the highest-privilege role wins
  4. The user is signed in with that role

Example:

A user belongs to two groups:

  • Facilities Team → mapped to Employee
  • Facilities Managers → mapped to Manager

They sign in and receive the Manager role, because Manager outranks Employee.

💡 TIP: Role changes in mappings take effect on the user's next login. Existing active sessions are not affected immediately.

When Mappings and Manual Roles Interact

If a user was invited directly (not auto-provisioned) and also belongs to a mapped group, the mapped role applies at their next sign-in and overwrites their manually assigned role.

If you want a specific user to have a role that differs from their group mapping, remove the mapping for their group or move them out of that group in Entra.

Removing a Mapping

  1. Go to Settings → Integrations → Microsoft Entra ID → Group → Role Mapping
  2. Set the Role dropdown for the group back to No mapping
  3. Click Save Mappings

Users who were previously assigned a role via that mapping retain their current role until their next login, at which point UniAsset reassigns based on remaining active mappings.

Common mistakes

Mapping a group to Owner. Every member of that group gets billing and organization deletion access. There should be one Owner.

Mapping groups that overlap in confusing ways. The highest-privilege role wins, which is easy to forget when someone is in five groups.

Expecting a mapping change to apply to signed-in users instantly. Mappings resolve at sign-in.

Troubleshooting

I can't reach the group mapping page. Directory sync needs Cosmos, and the Integrations area is Owner-only.

My group list is empty. Refresh the group list. If it stays empty, the stored token may need reconnecting.

A user has the wrong role. Check which mapped groups they belong to — the highest-privilege mapping wins.

I need someone to be Admin. Admin is not a mapping target. Assign it at Dashboard → Users.

A manually set role keeps reverting. A mapped group is reasserting the role at sign-in. Remove the mapping, or move the person out of that group in Entra.

Related articles

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support