You can use the Active Roles Web Interface to delete an Azure security group from an Azure tenant. This is typically required when the group becomes redundant or is otherwise no longer required, for example because of a security policy change.
|
CAUTION: Deleting an Azure security group is a destructive operation that will delete the group from the Azure tenant on the Azure Portal as well. |
To delete an Azure security group
-
Navigate to Directory Management > Tree > Azure > <azure-tenant-name> > Security Groups.
The list of existing Azure security groups in the selected Azure tenant appears.
-
Select the group that you want to delete.
-
In the right-side pane, click Delete.
-
A confirmation dialog appears. To confirm the deletion of the group, click Yes.
The selected Azure security group is then deleted from the Azure tenant.
Active Roles supports managing cloud-only Azure users. Using the Active Roles Web Interface, you can:
Create, view, update, or delete cloud-only Azure users in the Azure AD of your organization.
-
Check the Azure membership details, Azure properties, Exchange Online properties, or the change history of Azure users.
-
Perform administrative operations on Azure users, such as rename them or reset their password.
When you create a new cloud-only Azure user for your organization, you must:
-
Specify a User Principal Name (UPN) and password for the Azure user.
-
Select the organization domain where the Azure user will be located within the Azure tenant.
To view cloud-only Azure user information, you can use the Active Roles Web Interface.
To view cloud-only Azure user
- On the Active Roles Web Interface navigation bar, click Directory Management.
-
On the Views tab in the Browse pane, click Azure > <Azure tenant> > Azure Users.
The Azure Users page is displayed and lists the Azure users that are available in Azure.
NOTE: Active Roles lists the available cloud-only Azure users, Azure guest users, and Azure contacts on the Active Roles Web Interface with the following restrictions:
-
Active Roles can initially list 999 items.
-
The items listed in the list have a sliding expiry of 8 hours, after which the objects that have not been accessed will be flushed.
-
Whenever you perform a search in the list, Active Roles will always fetch the list of objects from Azure to update the cache.
You can use the Active Roles Web Interface to create and enable a new cloud-only Azure user.
To create a new cloud-only Azure user
-
On the Active Roles Web Interface, navigate to Directory Management > Tree > Azure > <azure-tenant-name> > Azure Users.
The list of cloud-only Azure users in your Azure tenant then appears.
-
To start creating a new Azure user, in the right-side pane, click New User.
-
In the New User window, on the General tab, specify the details of the new Azure user (First name, Last name, Display name, User principal name, Alias, and Description).
|
CAUTION: Hazard of data loss!
The Display Name field supports special characters. However, to avoid any potential problems in Active Roles when managing the Azure object, do not use any semicolons (;) in the specified display name. |
NOTE: In accordance with Microsoft 365, Azure users may share the same name. However, their aliases must be different.
-
To apply your changes and create the new Azure user, click Finish.
The new cloud-only user then appears in the Azure Users list of the Active Roles Web Interface.