How to Grant Users Access to OnePlan via Entra Groups

  • Updated

Direct Answer: How to Grant Users Access to OnePlan via Entra Groups

To grant users access to OnePlan via Microsoft Entra ID groups, go to the Resource Center, click the menu, then select Configure > Permissions. Click Load Groups to bring in your Enterprise Security Groups, then click into the AD Group field for the permission level you want to grant and select the Microsoft Entra ID group. Users in that group can then sign in to OnePlan with the assigned permissions, without being added as Resources.

Known limitation This feature only works reliably for users who are not also Resources in the Resource Center pool. If a user in the assigned Microsoft Entra ID group is also a named Resource, permission assignment through this method does not behave correctly. This is a confirmed product limitation (per SME review, August 2026). Additionally, this is a one-way push, not a live two-way sync — see the Why This Matters section below.


What This Article Covers: Permissions

This article explains how to grant a Microsoft Entra ID group access to your OnePlan site through the Permissions section of the Configure settings, so those users can sign in without becoming Resources available for planning. It also covers how to remove a Microsoft Entra ID group from a permission level.

What you will accomplish: By the end of this article, you will be able to load your Enterprise Security Groups, assign a Microsoft Entra ID group to a permission level, and remove a group when access is no longer needed.


Before You Begin: Granting Access via Entra Groups

  • Confirm you have Owner or Administrator permissions in OnePlan — this is required to access Configure > Permissions in the Resource Center.
  • Understand the difference between granting site access and adding a Resource: this method gives users the ability to log in to OnePlan, but does not make them available as Resources for planning. To add someone as a Resource, use How to Add Named Resources in OnePlan instead.
  • Review Enterprise Security Groups in OnePlan - Overview to understand the permission levels available in your environment before assigning Microsoft Entra ID groups to them.
  • Confirm the users in the Microsoft Entra ID group you plan to assign are not also Resources in the Resource Center pool — this feature is not confirmed to work correctly for users who are both.

Why This Matters: Permissions

Grant access without adding Resources

Not every user who needs to log in to OnePlan needs to be planned against as a Resource. Assigning a Microsoft Entra ID group under Permissions lets those users authenticate and use the site under a defined permission level, while keeping the Resource Center focused on people who are actually assigned work. See Users vs. Resources in OnePlan - Overview for more on this distinction.

This is a one-way push, not a live sync

Assigning a Microsoft Entra ID group under Permissions is a one-way push: adding someone to the assigned Microsoft Entra ID group grants them OnePlan access under that permission level, but removing them from the Microsoft Entra ID group does not automatically revoke their OnePlan access. Unlike a true two-way sync, OnePlan does not check group membership on an ongoing basis after the initial assignment — an administrator must manually remove a user’s access in OnePlan if they should no longer have it.

Does not work correctly alongside Resource pool membership

This feature is only confirmed to work correctly for users who are login-only and not also Resources in the Resource Center pool. If a user in the assigned Microsoft Entra ID group is also a named Resource, permission assignment through this method does not behave as expected. This is a known limitation, not an intentional restriction — treat it as a gap to work around until it’s addressed.


Step-by-Step: Granting Users Access to OnePlan via Entra Groups

Task: Assign a Microsoft Entra ID Group to a Permission Level

  1. Go to the Resource Center, click the menu, then select Configure > Permissions. [[administration/users-and-resources/How to Grant Users Access to OnePlan via Entra Groups/attachments/Access Users Settings.png]]

  2. Click Load Groups to load the Enterprise Security Groups configured for your OnePlan site. You can grant users different levels of access by assigning them to the different Enterprise Security Groups configured in your environment.

Click_Load_Groups.png

Groups_Loaded.png

  1. Click into the AD Group field for the permission group representing the level of access you want to grant, then select the Microsoft Entra ID group you want to assign to it.

Select_AD_Group.png

Users in the selected Microsoft Entra ID group can now access OnePlan with the permissions of the group you assigned them to (for example, Requestor permissions). These users will not be available as Resources for planning — they will only have access to your OnePlan site.

Task: Remove a Microsoft Entra ID Group from a Permission Level

  1. Click into the AD Group field for the permission group you want to update.
  2. Click the X next to the Microsoft Entra ID group you want to remove from your OnePlan site.

Remove_Group.png


Frequently Asked Questions: Permissions

Q: Does assigning an Entra group under Permissions make those users Resources?

A: In OnePlan, no. Users granted access through a Microsoft Entra ID group under Permissions can sign in to your OnePlan site, but they are not added as Resources and will not be available for planning. Use How to Add Named Resources in OnePlan to add someone as a Resource.


Q: What happens to a user’s access if they are removed from the Microsoft Entra ID group?

A: In OnePlan, nothing happens automatically. This feature is a one-way push, not a live sync — removing a user from the assigned Microsoft Entra ID group does not revoke their OnePlan access. An administrator must manually remove that user’s access in OnePlan if it should no longer apply.


Q: How do I remove a Microsoft Entra ID group’s access to OnePlan entirely?

A: In OnePlan, click into the AD Group field for the permission level, then click the X next to the group you want to remove. This removes the group’s assignment in OnePlan directly — it does not depend on any change in Microsoft Entra ID.


Q: Does this feature work if the user is also a Resource in the Resource Center?

A: In OnePlan, this is a known limitation — granting access via a Microsoft Entra ID group is only confirmed to work correctly for users who are not also Resources in the Resource Center pool. A feature request has been filed to address this.


What to Do Next: Permissions

Understand the permission structure you’re assigning groups to:

Manage related access and permissions settings:

Was this article helpful?

0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.