Roles

To manage the Microsoft Entra ID role objects, ensure that the following attributes are present in the group schema.

Backward Compatibility Note

The Microsoft Entra ID connector used to support roles as entitlement attribute on accounts but there was no support to aggregate roles as new separate group / entitlement type.

With that configuration, the connector used to show ‘displayName’ of role as entitlement value on the accounts. In order to continue support displayName based role entitlements, connector supports displayName as native Identity attribute of the new role object.

There are certain limitations in using displayName as native identity attribute :

  • Duplicate displayName is allowed for roles. If duplicate display names exists in your deployment, then avoid using displayName as native identifier.

  • displayName is an editable field, so it should not be edited if used as native identifier.