Skip to main content

Notifications

Community site session details

Community site session details

Session Id :
Power Pages - General Discussions
Unanswered

Allowing only specific Azure AD group to login into Power Pages

(0) ShareShare
ReportReport
Posted on by 309

Hi,

 

We have setup a process where an anonymous user uses a multistep form to submit a profile. We have a model driven app where an internal user verifies the form data and approves/rejects a profile. On approval, we have power automate flow that creates a guest account in our Azure AD and this sends an email to the external user to setup their account. the power automate also adds the user to a Azure AD security group. 

 

We want to ensure that only the users who are part of this security group can then log in to the power pages portal on clicking Azure AD in the screenshot below. How can we control this? Is this possible. Can we control this from the Azure Portal -> Microsoft Entra Id -> Enterprise Application -> User and Groups? 

 

prathyoo_0-1706610447532.png

 

Categories:
  • Fubar Profile Picture
    7,960 Super User 2025 Season 1 on at
    Re: Allowing only specific Azure AD group to login into Power Pages

    @jpaguiar you have to manually add individual users if using Private - think of Private as development mode.  If the users are in your Entra/Azure AD then do what the original poster did - restrict the App to a specific Azure AD Group and make the Site Public, then also in Power Pages implement Web Page Access Control Rules on any public pages (including the Home page), set each rule to restrict read, this will always push any visitors to your login page, and turn off the checkbox on the Anonymous Users web role (with it checked anyone who is logged out will get what ever permissions it has)

  • jpaguiar Profile Picture
    2 on at
    Re: Allowing only specific Azure AD group to login into Power Pages

    Hello community!

    I have a Power Pages site in development (private) and I manage accesses via Site Visibility.... adding internal or external email addresses and clicking "Share".

    jpaguiar_0-1716427022702.png

     

    I would like add a Security Group on Site Visibility and manage accesses using Microsoft Entra, so I could add/remove users quickly.

    Security Groups are not visible on Site Visibility.

    Is this a limitation? or should I need to change something? For example: move to production, make it public and then control everything on MS Entra.

     

    Thanks!!

  • psreek Profile Picture
    309 on at
    Re: Allowing only specific Azure AD group to login into Power Pages

    Looks like I got this to work by updating the corresponding Enterprise Application record in the Azure Portal - 

     

    Set "Assignment Required" to Yes - 

    prathyoo_0-1706611902652.png

     

    And then add the Azure AD group to the "Users and groups". Then only users in the group can sign in to the portal while others get an error.

     

    prathyoo_1-1706611967715.png

     

     

    prathyoo_2-1706612294559.png

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Michael Gernaey – Community Spotlight

We are honored to recognize Michael Gernaey as our June 2025 Community…

Congratulations to the May Top 10 Community Leaders!

These are the community rock stars!

Announcing the Engage with the Community forum!

This forum is your space to connect, share, and grow!

Leaderboard >