1

This idea was raised based on real customer feedback from Badal (HCF) during case 2604140030004241, who encountered the inconsistent behaviour first-hand and asked Microsoft to consider a fix.


Idea:

Today, when a user is added to an Entra ID security group that's linked to an environment, they are not provisioned into Dataverse until a trigger occurs such as their first sign-in or an API based action. Until that happens, the user doesn't appear in the Users tab and can't be picked for role/team assignment.


The inconsistent part is that the system still allowed the user to be manually added even though they weren't yet synced into Dataverse after being added to the security group. So the behaviour is mixed: the user can't be relied on to appear for normal provisioning, yet a manual add is permitted, which creates confusion about whether access is actually configured correctly.


Request: Make this behaviour consistent and predictable. Automatically provision users into Dataverse as soon as they're added to a linked security group (no first-login or API trigger required), so they're immediately available for security role and team assignment,

Category: Dataverse
STATUS DETAILS
New