---
title: Unable to add users to role-assignable groups
slug: unable-to-add-users-to-role-assignable-groups
docTags: 
createdAt: 2026-08-09T21:30:58.920Z
---

## Issue

Activate fails to add a user as a member of a Microsoft Entra ID role-assignable group.

The Activate logs show an error similar to:

:::BlockQuote
Error\:Groups\:Unable to add user to group \[group]
System.Exception: Error adding \[user] to group \[group]:
Insufficient privileges to complete the operation.

Microsoft.Graph.Models.ODataErrors.ODataError:
Insufficient privileges to complete the operation.
:::

Users may still be added successfully to standard Microsoft Entra ID security groups.

## Cause

Microsoft Entra ID applies additional security controls to **role-assignable groups**.

A role-assignable group is a security group that can have a Microsoft Entra administrative role assigned to it. Users added to the group can therefore inherit the administrative privileges associated with that role.

Role-assignable groups have the Microsoft Graph property:

:::BlockQuote
isAssignableToRole = true
:::

Because changing the membership of these groups can grant administrative privileges, Microsoft does not allow applications to manage their membership using standard group-management permissions alone.

For example, permissions that allow Activate to manage standard groups, such as:

:::BlockQuote
Group.ReadWrite.All
:::

do not provide sufficient privileges to modify the membership of a role-assignable group.

Microsoft Graph returns:

:::BlockQuote
Insufficient privileges to complete the operation.
:::

when Activate attempts the membership change without the additional role-management permission.

## Resolution

If Activate is required to manage membership of role-assignable groups, the Activate Microsoft Entra application requires the following Microsoft Graph **Application permission**:

:::BlockQuote
RoleManagement.ReadWrite.Directory
:::

Administrator consent must also be granted for this permission.

:::BlockQuote
**Important:** RoleManagement.ReadWrite.Directory is a highly privileged Microsoft Graph permission. It allows the application to perform role-management operations within Microsoft Entra ID. Review the security implications with the customer's identity or security team before granting this permission.
:::

### Add the required permission

1. Sign in to the **Microsoft Entra admin centre**.
2. Go to **Identity > Applications > App registrations**.
3. Locate the application registration used by Activate.
4. Select **API permissions**.
5. Select **Add a permission**.
6. Select **Microsoft Graph**.
7. Select **Application permissions**.
8. Locate and select\:RoleManagement.ReadWrite.Directory&#x20;
9. Select **Add permissions**.
10. Select **Grant admin consent** for the organisation.
11. Confirm that the permission shows as granted.

After granting the permission, retry the group membership operation in Activate.

## Confirm the group is role assignable

If standard groups work but a particular group returns an insufficient privileges error, check whether the affected group is role assignable.

In Microsoft Graph, a role-assignable group has:

:::BlockQuote
isAssignableToRole: true
:::

Role-assignable groups can also be identified in Microsoft Entra by checking whether the group is configured for Microsoft Entra role assignment.

If:

:::BlockQuote
isAssignableToRole = false
:::

the issue is not specific to role-assignable groups and the application's existing Microsoft Graph permissions should be investigated instead.

## Why standard group permissions are not sufficient

Microsoft deliberately separates normal group administration from role administration.

For a standard security group, adding a member grants access associated with that group.

For a role-assignable group, the same operation may indirectly grant a Microsoft Entra administrative role:

:::BlockQuote
User
&#x20; ↓
Added to role-assignable group
&#x20; ↓
Group has Microsoft Entra role
&#x20; ↓
User receives administrative privileges
:::

Microsoft therefore requires additional role-management privileges before an application can modify these memberships.

## Security consideration

Do not grant RoleManagement.ReadWrite.Directory solely to suppress an insufficient privileges error without first confirming that Activate is expected to manage role-assignable groups.

If the customer does not require Activate to manage these groups, retaining the existing lower-privilege Microsoft Graph permissions maintains a stronger least-privilege configuration.
