Overview
Group → Role Mapping lets you connect Microsoft Entra ID groups to UniAsset roles. When a user signs in with Microsoft, UniAsset reads their group membership and assigns the appropriate role automatically. Roles stay in sync with your directory — no manual reassignment needed when people change teams.
Requirements
- Available on: Cosmos
- Roles: Owner — the Integrations area is Owner-only
- Prerequisite: Microsoft Entra ID must be connected. See Connecting Microsoft Entra ID.
Available roles
Four UniAsset roles can be mapped from Entra groups:
| Role | Access level |
|---|---|
| Owner | Everything, including users, organization settings, and billing |
| Manager | Create and update assets, assign, manage maintenance, view reports |
| Employee | Read and update assets, complete maintenance, check items out and in |
| Viewer | Read assets, categories, departments, and checkouts |
Admin cannot be assigned through a group mapping. Assign it directly at Dashboard → Users if someone needs it.
Full breakdown of what each role can do: Roles and permissions.
⚠️ WARNING: Mapping a group to the Owner role gives every member of that group full system access including billing. Reserve this for a single trusted administrator account, not a group.
Setting Up Group → Role Mapping
Step 1: Open Entra ID Settings
- Sign in as the Owner.
- Go to Settings → Integrations.
- Open Microsoft Entra ID.
Step 2: Open Group Mappings
- Under the connected tenant, click Group → Role Mapping
- UniAsset fetches your Entra groups and displays them in a list
💡 TIP: If your group list is empty or outdated, click Refresh Groups to pull the latest list from your directory.
Step 3: Assign Roles to Groups
For each Entra group you want to map:
- Find the group in the list
- Use the Role dropdown next to the group name to select a role
- Repeat for each group that should have a mapped role
Groups with no role selected are ignored — users in those groups receive the default role (Employee) if auto-provisioning is on, or their manually assigned role if they were invited directly.
Step 4: Save Mappings
- Click Save Mappings
- A confirmation message confirms the mappings are active
How Role Resolution Works
Mappings are applied at sign-in time, not in advance.
When a user signs in with Microsoft:
- UniAsset reads their current Entra group membership
- It checks which of their groups have a role mapping
- If multiple mapped groups apply, the highest-privilege role wins
- The user is signed in with that role
Example:
A user belongs to two groups:
- Facilities Team → mapped to Employee
- Facilities Managers → mapped to Manager
They sign in and receive the Manager role, because Manager outranks Employee.
💡 TIP: Role changes in mappings take effect on the user's next login. Existing active sessions are not affected immediately.
When Mappings and Manual Roles Interact
If a user was invited directly (not auto-provisioned) and also belongs to a mapped group, the mapped role applies at their next sign-in and overwrites their manually assigned role.
If you want a specific user to have a role that differs from their group mapping, remove the mapping for their group or move them out of that group in Entra.
Removing a Mapping
- Go to Settings → Integrations → Microsoft Entra ID → Group → Role Mapping
- Set the Role dropdown for the group back to No mapping
- Click Save Mappings
Users who were previously assigned a role via that mapping retain their current role until their next login, at which point UniAsset reassigns based on remaining active mappings.
Common mistakes
Mapping a group to Owner. Every member of that group gets billing and organization deletion access. There should be one Owner.
Mapping groups that overlap in confusing ways. The highest-privilege role wins, which is easy to forget when someone is in five groups.
Expecting a mapping change to apply to signed-in users instantly. Mappings resolve at sign-in.
Troubleshooting
I can't reach the group mapping page. Directory sync needs Cosmos, and the Integrations area is Owner-only.
My group list is empty. Refresh the group list. If it stays empty, the stored token may need reconnecting.
A user has the wrong role. Check which mapped groups they belong to — the highest-privilege mapping wins.
I need someone to be Admin. Admin is not a mapping target. Assign it at Dashboard → Users.
A manually set role keeps reverting. A mapped group is reasserting the role at sign-in. Remove the mapping, or move the person out of that group in Entra.
Related articles
Need Help?
If you have questions not covered in this article, our support team is here to help.
Contact Support