cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
Nariim Frequent Visitor
Frequent Visitor

Can't enter security group into app permissions

I have an app that we are trying to restrict by security group. One group, in particular, is problematic. It isn't mail-enabled, so it doesn't have a full email address. also, the name of the security group happens to be contained within the display name of many users. Since the typeahead only loads a few options, and the security group I want isn't in those options, I can't add it to the app. If I just type the name and hit enter, it chooses the first option from the typeahead, which is an individual user, not the security group. If I try to use the group's Guid, I get an error that the email address is invalid or a duplicate.

6 REPLIES 6
lndnbrg Member
Member

Re: Can't enter security group into app permissions

You almost pointed it out: The problem is here that it must be an email-enabled security group in order to use it in apps.

It is annoying, but there is currently no other way. Smiley Sad
Nariim Frequent Visitor
Frequent Visitor

Re: Can't enter security group into app permissions

I'm able to use other security groups that aren't mail-enabled with no issues- I just pick them out of the typeahead.

lndnbrg Member
Member

Re: Can't enter security group into app permissions

I am sorry, I didn’t read your initial post properly.

Does the group have a UPN like securitygroup@domain.com, that you may try to enter?
Nariim Frequent Visitor
Frequent Visitor

Re: Can't enter security group into app permissions

I'm not an AD wizard by any means, but it doesn't look like I can set a user principal on a security group.

 

v-huizhn-msft Super Contributor
Super Contributor

Re: Can't enter security group into app permissions

Hi @Nariim,

Could you please share a screenshot for further analysis?

Best Regards,
Angelia

Nariim Frequent Visitor
Frequent Visitor

Re: Can't enter security group into app permissions

@v-huizhn-msft here's what it looks like:

 

If I just type in the group name and hit enter, I get the second screenshot, where it just selects the first item in the typeahead, even if though there is an exact match. Interestingly, if I go to the O365 portal and search there, it shows up fine because it is searching by "begins with" instead of "contains"

Screenshot (33).pngScreenshot (34).pngo365 portal.png