Give role-based access to an Entra ID group
If you have Microsoft Entra ID configured as your identity provider, you can define role-based access in Calico Cloud and assign that role to an Entra ID (formerly Azure AD) security group. By managing membership in that security group, you can manage role-based access to Calico Cloud directly from your identity provider portal.
Prerequisites
- You have owner or administrator permissions to the Calico Cloud Manager UI.
- You set up Entra ID as your identity provider.
- You have administrator permissions for your organization in the Azure Portal.
- You have the Object ID for an Entra ID security group.
- The Email property for all users in the security group has a valid email address.
Procedure
- In Manager UI, click the user icon > Manage Team.
- Under the Roles tab, click Add Role and enter a name and description for the custom role. Under IdP Group Identifier, enter your Entra ID security group's Object ID and click Save.
- To add permissions, locate your new role under the Roles tab, select Action > Manage permissions > Edit, and then click Add Permission.
- Under Permission, choose a permission type from the list. Depending on the permission, you may also need to choose a namespace or policy tier.
- (optional) Click Add permission to add more permissions to your role for this cluster.
- Click Save to save these permissions to the role for this cluster.