Entra Security Groups for Access Grants¶
Several Forge features grant an Entra ID group or user principal access to your application's data through an entry that takes either an object_id or a group_name. This page owns the rules for choosing between them.
| Feature | Setting | Guide |
|---|---|---|
| Cosmos DB read-only access | data_readers in feature-database-cosmodb-vars.yaml |
Self-Service Read-Only Access |
| Service Bus subscription DLQ access | dlq_readers and dlq_managers in feature-event-subscription-dlq-vars.yaml |
Self-Service DLQ Access |
Some features accept only a literal object ID. Blob Storage's contributor_group_id and the Service Bus queue's dlq_reader_identities and dlq_manager_identities take a GUID and do not resolve group names; see Blob Storage and Service Bus Queue.
Group membership¶
You manage membership of the Entra ID groups you reference. Forge provisions the role assignment for the group; it does not manage who belongs to the group.
Prefer object_id¶
Use object_id when possible. It identifies exactly one group or user principal and avoids ambiguous display-name lookups.
Find a group's object ID in the Entra admin center under Microsoft Entra ID → Groups → select your group → copy the Object ID from the overview page, or with the Azure CLI:
group_name constraints¶
A group_name entry resolves the group by its Entra ID display name, restricted to groups with security_enabled = true. Two constraints follow:
- Display names must be unique across all security groups in the tenant. If multiple security groups share the same display name, the Terraform plan fails.
- Microsoft 365 groups are not supported. Only security groups match.