Assign groups
You grant access only by assigning groups. On the application’s Assignments tab, choose + Assignment:- Group: the group that should have the app.
- Roles: the role or roles applied to that group.
You cannot assign individual users to an application, and you cannot grant
access by role alone. Access always follows group membership.
Prefer group-based assignment
Access is always granted through groups, so it follows your directory membership automatically; there are no per-user app assignments to track.Access follows membership
When access is granted through a group, adding or removing a user from the
group grants or revokes the app automatically, with no per-app edits.
Less to maintain
One group can be assigned to many apps. You manage access by editing the
group, not by touching every application.
Automatic with Auto Groups
An Auto Group updates its own
membership from an attribute rule, so access tracks users’ profiles
(department, role, location) with no manual steps.
Clear and auditable
Reviewing one group’s membership is easier than reconciling individual
assignments across many apps.
Review assignments and effective users
On the Assignments tab, the table lists each group assigned to the app and the role or roles applied to that group. To confirm exactly who has access, open the Effective Users tab. It shows every user with access through an assigned group, with the date their access began. This resolved view is the source of truth for who can sign in, and (for apps with provisioning, who gets an account created in the app.Removing someone’s last path to access (removing them from every group
assigned to the app, or unassigning those groups from the app) drops them from
the effective set, and they can no longer sign in to the app.
Roles within an application
Some apps expect a role at sign-on (administrator, member, and so on), not just identity. When you choose + Assignment, the Roles field applies a role to the group you selected. Define the available roles and how they are asserted on the application’s Roles tab. See Roles & Bundles.When the role assertion method is set to None, only the Default
role can be assigned to groups on the Assignments tab.
Favorites
End users can mark the apps they use most as favorites from their app dashboard, which pins those apps for quick access. Favorites are a personal convenience and do not change who is assigned or what access anyone has.Where to go next
Roles & Bundles
Assert a role to the app and vary session length and risk by role.
Groups
Create the groups you assign to applications.
Auto Groups
Drive group membership (and therefore access) from attribute rules.
Provisioning
Turn assignment into real accounts in the app, created and removed as access
changes.
Authentication policies
Decide what assigned users must prove to sign in.