Managing users - Microsoft Entra ID

Prev Next

Overview

The Users section in Turbo360 is the central place for managing user and group access across all modules. Account owners can add users and groups, grant or revoke account ownership, remove users from the account entirely, and export a permissions report in CSV format.

Turbo360 uses a Role-to-User model, which assigns roles to users rather than assigning users to roles. This approach simplifies access management at scale, particularly when using Microsoft Entra ID (formerly Azure Active Directory) for identity.

Business value

Centralized user management lets account owners maintain consistent access controls across Cost Analyzer, Business Applications, Business Activity Monitoring, and Azure Documenter from a single location. Exporting user permissions in CSV format supports compliance reviews and access audits without requiring direct portal access for each stakeholder.

Prerequisites

  • A Turbo360 account with at least one active subscription.
  • Microsoft Entra ID configured as the identity provider, if managing groups via Entra ID.

Required permissions

Only Account owners can access the Users section. Standard users and module-specific roles do not have access to this section.

Dependencies

  • Microsoft Entra ID (for group-based user management)
  • Module-level user management is separate. Changes made in the platform-level Users section affect the entire Turbo360 account, not just individual modules.
Note:

Each Turbo360 module also has its own user management section for module-specific role assignments.

How it works

The Users section lists all users and groups that have been added to the Turbo360 account. From here, account owners can perform the following operations:

  • Add user/group: invite a new user or group to the account.
  • Grant / Revoke account ownership: promote a user or group to account owner, or remove that privilege.
  • Remove users/groups: permanently remove a user or group from the account.

When adding a user or group, you assign either a platform-level role or module-level permissions:

  • Application-level role: one of the system-defined roles (Owner, Contributor, Reader) that applies across the entire Turbo360 Platform.
  • Module-level permissions: access scoped to individual products (Business Applications, Business Activity Monitoring, Azure Documenter, Cost Analyzer), assigned via the Specify product permissions dialog during the add flow.

Role assignment cannot be updated from the Users page after a user or group is added. To change permissions, use the module-level settings within each module. Custom roles can be created at the module level only. Platform-level role assignments are limited to the system-defined roles above.

The term Account owner replaces the legacy term Administrator. Multiple users and groups can hold account ownership simultaneously.

Important:

Removing a user or group from the Users section removes them from the entire Turbo360 account, not just from an individual module. This is different from removing a user within a specific module.

Steps

Add a user or group

Adding a user or group invites them to the Turbo360 account and assigns their initial access level, either as a platform-level role or with per-module permissions.

  1. Navigate to Settings > Users.
  2. Select Add user/group.
  3. Enter the user or group details.
  4. Under Role assignment, select Direct role assignment and choose a system-defined role (Owner, Contributor, or Reader) to apply across the entire Platform. To assign module-level permissions instead, select Specify product permissions, enable the toggle for each module, and select the role for that module.
  5. Confirm to send the invitation.

Role assignment cannot be changed from the Users page after the user or group is added.

Grant account ownership

  1. In the Users section, locate the user or group.
  2. In the Actions column, select Grant account ownership.

Revoke account ownership

  1. In the Users section, locate the user or group.
  2. In the Actions column, select Revoke account ownership.

Remove a user or group

  1. In the Users section, locate the user or group.
  2. In the Actions column, select Remove user/group.
Warning:

Removing a user or group here removes them from Turbo360 entirely, not just from an individual module.

Export user details with permissions

  1. In the Users section, select the export option.
  2. A CSV file is generated containing all users and groups along with their permission levels across the account.

Configuration

Option Description
Add user/group Adds a user or Microsoft Entra ID group to the Turbo360 account.
Grant account ownership Promotes the selected user or group to account owner level.
Revoke account ownership Removes account owner privileges from the selected user or group.
Remove user/group Permanently removes the user or group from the Turbo360 account.
Export user details Downloads a CSV file of all users and groups with their assigned permissions.

Permission behavior

With account owner access:
You can add, remove, grant ownership to, and revoke ownership from any user or group. You can also export the full permissions report.

Without account owner access:
The Users section is not visible. You cannot perform any user management operations at the account level. Use the module-level User management options within each module to manage module-specific access.

Example scenario

An IT administrator needs to onboard a new operations team using a Microsoft Entra ID group. They navigate to Settings > Users, select Add user/group, and add the Entra ID group. The group members gain access to the relevant Turbo360 modules based on the roles assigned at the module level. The administrator then grants account ownership to a senior team member, ensuring continuity. After the onboarding is complete, the administrator exports the user permissions CSV to send to the compliance team for review.

Limitations

  • Only account owners can access and manage the Users section.
  • Role assignment cannot be updated from the Users page after a user or group is added. To change permissions, use the module-level settings within the relevant module.
  • Custom roles can be created at the module level only. Application-level role assignments are limited to Owner, Contributor, and Reader.
  • Removing a user or group at the account level removes them from all Turbo360 modules simultaneously. This cannot be scoped to a single module from this section.
  • Module-specific role assignments must be managed within each module separately.
  • Users listed in Microsoft Entra ID must sign in using their Entra ID credentials. The email address used must match the domain configured in the Entra ID tenant where the user exists.

Troubleshooting

  1. The Users section is not visible.
    Cause: You may not have account owner privileges.
    Fix: Contact an existing account owner to grant you access or check your role assignment.

  2. I cannot grant account ownership to a group.
    Cause: The group may not yet be added to the Turbo360 account.
    Fix: Confirm the group is present in the Users list before attempting to grant ownership.

  3. A removed user still has access to a module.
    Cause: There may be a brief propagation delay, or the user is a member of a group still active in the account.
    Fix: Wait a moment and recheck. If access persists, verify whether the user belongs to a group that remains active.

  4. The exported CSV is missing some users.
    Cause: The CSV export reflects the current state of the Users section at the time of export.
    Fix: Ensure all expected users and groups have been added to the account before exporting.

  5. Revoking account ownership fails.
    Cause: There must be at least one account owner remaining after the revoke action.
    Fix: Ensure another account owner exists before revoking the last owner's privileges.

FAQs

  1. Can multiple users hold account ownership at the same time?
    Yes. Turbo360 supports multiple account owners. You can grant account ownership to any number of users or groups.

  2. Does removing a user from the Users section also remove them from all modules?
    Yes. Removing a user or group from the platform-level Users section removes them from the entire Turbo360 account, including all modules. To remove access from a single module only, use the module-level user management option within that module.

  3. What information is included in the exported CSV?
    The CSV includes all users and groups along with their permission levels at various module levels within the Turbo360 account.

Related articles