Users, groups and roles
For Owners and Operators granting access: who can sign in to a Studio deployment (the StudioUser Role, per deployment), who can share into a Library (Contributor on the Library's Members tab), and what a person may do in the console (the other Roles and the Owner, Operator and Viewer tiers). An AccessAdministrator Role opens Roles; an IdentityProviderManager Role opens Users and Groups.
Before you start: Users and Groups read your connected Microsoft Entra ID tenant, so connect an identity provider first; without one both pages read Directory search is unavailable. A deployment accepts 20 users by default (engine setting ORG_MAX_USERS_PER_DEPLOYMENT, raised when Organisations is configured; see Limits and quotas), counted as distinct people holding StudioUser on it directly or through a group.
Find people in Users
Open Identity & Access Management → Users. Roles granted here are console permissions, org-wide or on one deployment or library; they do not grant pull access to a Library's contents, which is Contributor or Reader on the Library's Members tab (Libraries).
Type at least two characters in Search users by name and email. Results arrive 50 at a time ("Showing first 50 · refine your search"). Tick people or Select all, then click Assign role (N). Clicking a name opens the person's detail.
Assign a role to people
Assign a role has four fields:
- Principal: the people you selected.
- Role: StudioUser, LibraryViewer, LibraryContributor, LibraryManager, FleetViewer, FleetOperator, DeploymentOperator, AccountManager, AccountViewer, IdentityProviderManager, IdentityProviderViewer, AccessAdministrator, ProgrammaticAccessAdministrator, ProgrammaticAccessViewer, or the Owner, Operator and Viewer tiers.
- Applies to: Whole organisation, or A specific deployment, Library, AWS Account or Identity Provider for a resource-scoped Role. Tiers are always organisation-wide.
- The resource box, labelled Deployment (search by domain or id) for a deployment: type its app domain or paste its id; rows read "<domain> (<account> · <region>)" with the seats, "N of M users · room for N".
Click Assign. The header changes to Done and the dialog lists one line per person, a tick with the email or a cross with the error.
Give someone access to a Studio deployment. Role StudioUser, Applies to A specific deployment, pick the deployment. The console makes the matching assignment in your Entra tenant, so the person can sign in at once. Assign is disabled when the selection would not fit ("Only N more users fit in this deployment (20 max)"); a request that would exceed the cap is refused as a whole and nothing changes, in Entra or here, whether for one person, several, or a group whose members would take it over.
Give someone publishing rights on a Library. Add them as Contributor on the Library's Members tab (Libraries): Contributors publish from their Studio and pull, Readers pull. Roles granted here govern who manages the Library in the console, not who publishes.
Read a person's detail
The header shows Email, Role (their tier, if any) and Console access: Assigned, or "Missing: assign them to the Organisations console application in Microsoft Entra".
Role grants lists Role, Scope and Granted with Revoke. Revoking your own access asks Revoke your own <role> access?: you lose it immediately, and another owner must restore it.
Studio deployment assignments lists the deployments the person can sign in to, checked live against each deployment's identity provider, with Remove (they lose SSO sign-in immediately). Assign to a deployment grants StudioUser for one deployment from here.
Assign a role to groups
Identity & Access Management → Groups searches your directory ("Search groups by name"); columns are Name, Type ("Microsoft-managed" or "Security group") and Description. Tick groups, click Assign role (N). Assign a role to a group offers the Roles but not the tiers, then Applies to and the resource box; for StudioUser it shows the seats and each group's member count ("counting members…", "members unknown" or "N members") and disables Assign if the group would not fit. Every current and future member gets the grant. A group's detail lists its Role grants with Revoke.
Admins, Roles and Policies
Admins is a read-only roster of who holds Owner, Operator or Viewer (Email, Role, Granted by, Granted); Manage access in Roles → opens Roles.
Roles lists each Role with its Policies and Grants. A Role's page lists the Policies it bundles and its grants (Granted to, Scope, Granted, Revoke). Grant role opens Grant <role>: a Principal (email) picker that searches the directory or accepts a typed email, then Applies to and the resource box. The Owner, Operator and Viewer pages note they are org-wide Roles, not sets of Policies. A custom Role carries a Custom badge and Delete Role; grants already issued under it are unaffected.
Policies lists the permissions Roles are built from: Policy, Description, Resource type, Actions and Used by. A Policy's page shows its actions and the Roles that bundle it; only a custom Policy offers Delete Policy, refused while Roles still bundle it.
What you should see
- There is no Create Role or Create Policy button; the built-in set is what you grant.
- A person assigned StudioUser appears under the deployment's Who can sign in (Deployment detail) and can sign in to that Studio.
- Every grant and revoke is written to Audit.
Notes
- Tiers go to people, not groups.
- The cap is checked at assignment. If a group later grows in Entra, the deployment can end up over the cap; its Identity view flags it and the fix is to remove users.
- The last remaining Owner cannot be revoked; grant another first.
- Console access "Missing" means the person holds a grant but is not assigned to the console application in Entra.
- "members unknown": the assignment still works, but the cap check cannot predict the fit.