Skip to content

Entra Security Groups for Access Grants

Several Forge features grant an Entra ID group or user principal access to your application's data through an entry that takes either an object_id or a group_name. This page owns the rules for choosing between them.

Feature Setting Guide
Cosmos DB read-only access data_readers in feature-database-cosmodb-vars.yaml Self-Service Read-Only Access
Service Bus subscription DLQ access dlq_readers and dlq_managers in feature-event-subscription-dlq-vars.yaml Self-Service DLQ Access

Some features accept only a literal object ID. Blob Storage's contributor_group_id and the Service Bus queue's dlq_reader_identities and dlq_manager_identities take a GUID and do not resolve group names; see Blob Storage and Service Bus Queue.

Group membership

You manage membership of the Entra ID groups you reference. Forge provisions the role assignment for the group; it does not manage who belongs to the group.

Prefer object_id

Use object_id when possible. It identifies exactly one group or user principal and avoids ambiguous display-name lookups.

Find a group's object ID in the Entra admin center under Microsoft Entra ID → Groups → select your group → copy the Object ID from the overview page, or with the Azure CLI:

az ad group show --group "<group display name>" --query id -o tsv

group_name constraints

A group_name entry resolves the group by its Entra ID display name, restricted to groups with security_enabled = true. Two constraints follow:

  • Display names must be unique across all security groups in the tenant. If multiple security groups share the same display name, the Terraform plan fails.
  • Microsoft 365 groups are not supported. Only security groups match.