web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / Security Role not auto...
Power Apps
Unanswered

Security Role not auto assigned to Team

(0) ShareShare
ReportReport
Posted on by 150

Hi

I've created a Dataverse Team 'dvVolunteers' via Admin center (Settings-Teams) with Type 'Microsoft Entra ID Office Group', group name 'Volunteer' and assigned a Security Role to the Team.  I have shared a canvas app with a User who is a member of the Entra Group 'Volunteer', but when they try to open the app they can't see the Dataverse data.  It appears that they haven't been 'auto-assigned' the security role of dvVolunteers.

If I repeat these steps but using a Microsoft Entra Security Group, then it works.  Anybody know if there is a solution, or does the 'auto' bit of 'auto-assigned' roles just not work for M365 Groups?

I have the same question (0)
  • alexsolexToo Profile Picture
    37 on at

    I'm aceing the same issue : I create on the fly the BU and assign security role to default team. I'm pretty sure it was working fine : users in the team get the security role of the team. But since a couple of days it looks like my users don't get security role from teams. I need to assign the role to the user to make it work... Any idea ?

  • ivan_apps Profile Picture
    2,187 Moderator on at

    What is the ‘Team Member Inheritance’ configuration set to? It would have to be set to team and user unless you have a special setup.


    https://learn.microsoft.com/en-us/power-platform/admin/security-roles-privileges#define-the-privileges-and-properties-of-a-security-role

     

  • alexsolexToo Profile Picture
    37 on at

    Good point !
    I'm not really sure to understand well the difference between both settings. In my mind I would say that team only should work as the user get his role with the memberhsip of the team, but it looks like it's not the case....
    Or maybe "team only" needs user specific role to really give access to records ?

  • SteRe Profile Picture
    254 on at

    Hi, 

    there is a difference in the settings regarding permissions on user owned / team owned records. 

    I think MS doc describes pretty clear:

    https://learn.microsoft.com/en-us/power-platform/admin/security-roles-privileges#define-the-privileges-and-properties-of-a-security-role 

    From my experience, mostly the option "Direct User (Basic) access level and Team privileges" is used. 

  • jkic Profile Picture
    150 on at

    I was also confused by the difference, but rereading @SteRe 's link below, I get it now.  Setting it to Team privileges only means records are created with the Team as owner; the 'Direct User etc' option means records created with the individual user as the Owner.  Additionally, if a User only has access to view/edit their own records, with Team privileges only this means the Team and not just their own.  I don't think I can check now how I had it set up, since I switched to a Entra Security Group.  I think I came to the conclusion it doesn't work for 365 Groups, only Security Groups.  When sharing a Power App I noticed that the 365 Groups are not shown - only the Security Groups.

  • SteRe Profile Picture
    254 on at

    Hi @jkic ,

    this is also right. The M365 groups have a limited functionality compared to Entra Security Groups. 

    I'm not aware of all details, would not surprise me, if the kind of sharing you'd like to go for is only intended with the Entra Sec Groups.

  • Devvj Profile Picture
    1,132 Super User 2024 Season 1 on at

    Hi @jkic ,
    we had some issues with the sync time when we were using Teams with Entra Security groups a while back, i could take up to a day before the user was showing up in the team after being put in the AD-group by IT

  • Fubar Profile Picture
    8,338 Super User 2025 Season 2 on at

    @Devvj wrote:

    we had some issues with the sync time when we were using Teams with Entra Security groups a while back, i could take up to a day before the user was showing up in the team after being put in the AD-group by IT


    That's probably because they don't really sync, you'll find it in the notes, that the Dataverse Team doesn't automatically show the Entra members, each member only shows up in the Dataverse Team after their first access of the the environment - you'll see it documented about the 6th bullet point in the Notes here https://learn.microsoft.com/en-us/power-platform/admin/manage-group-teams#edit-a-group-team

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 793 Most Valuable Professional

#2
Michael E. Gernaey Profile Picture

Michael E. Gernaey 333 Super User 2025 Season 2

#3
Power Platform 1919 Profile Picture

Power Platform 1919 268

Last 30 days Overall leaderboard