Unable to add users to role-assignable groups
Issue
Activate fails to add a user as a member of a Microsoft Entra ID role-assignable group.
The Activate logs show an error similar to:
Users may still be added successfully to standard Microsoft Entra ID security groups.
Cause
Microsoft Entra ID applies additional security controls to role-assignable groups.
A role-assignable group is a security group that can have a Microsoft Entra administrative role assigned to it. Users added to the group can therefore inherit the administrative privileges associated with that role.
Role-assignable groups have the Microsoft Graph property:
Because changing the membership of these groups can grant administrative privileges, Microsoft does not allow applications to manage their membership using standard group-management permissions alone.
For example, permissions that allow Activate to manage standard groups, such as:
do not provide sufficient privileges to modify the membership of a role-assignable group.
Microsoft Graph returns:
when Activate attempts the membership change without the additional role-management permission.
Resolution
If Activate is required to manage membership of role-assignable groups, the Activate Microsoft Entra application requires the following Microsoft Graph Application permission:
Administrator consent must also be granted for this permission.
Important: RoleManagement.ReadWrite.Directory is a highly privileged Microsoft Graph permission. It allows the application to perform role-management operations within Microsoft Entra ID. Review the security implications with the customer's identity or security team before granting this permission.
Add the required permission
- Sign in to the Microsoft Entra admin centre.
- Go to Identity > Applications > App registrations.
- Locate the application registration used by Activate.
- Select API permissions.
- Select Add a permission.
- Select Microsoft Graph.
- Select Application permissions.
- Locate and select:RoleManagement.ReadWrite.Directory
- Select Add permissions.
- Select Grant admin consent for the organisation.
- Confirm that the permission shows as granted.
After granting the permission, retry the group membership operation in Activate.
Confirm the group is role assignable
If standard groups work but a particular group returns an insufficient privileges error, check whether the affected group is role assignable.
In Microsoft Graph, a role-assignable group has:
Role-assignable groups can also be identified in Microsoft Entra by checking whether the group is configured for Microsoft Entra role assignment.
If:
the issue is not specific to role-assignable groups and the application's existing Microsoft Graph permissions should be investigated instead.
Why standard group permissions are not sufficient
Microsoft deliberately separates normal group administration from role administration.
For a standard security group, adding a member grants access associated with that group.
For a role-assignable group, the same operation may indirectly grant a Microsoft Entra administrative role:
Microsoft therefore requires additional role-management privileges before an application can modify these memberships.
Security consideration
Do not grant RoleManagement.ReadWrite.Directory solely to suppress an insufficient privileges error without first confirming that Activate is expected to manage role-assignable groups.
If the customer does not require Activate to manage these groups, retaining the existing lower-privilege Microsoft Graph permissions maintains a stronger least-privilege configuration.