Overview
This article describes how to add, assign roles to, and remove users and Microsoft Entra ID groups in Business Activity Monitoring (BAM) for a Turbo360 account using Microsoft Entra ID authentication. Users and groups are selected directly from your organization's Entra ID directory and can be assigned roles at the module level or scoped to individual Business Processes.
Business value
Microsoft Entra ID integration allows organizations to manage BAM access through their existing identity infrastructure. Groups can be assigned roles in bulk, and transitive group membership means access hierarchies are automatically honoured without manual re-entry in Turbo360.
Prerequisites
Required permissions
You must hold the Account owner or Owner role to add, update, or remove users and groups in Business Activity Monitoring.
How it works
Users and Microsoft Entra ID groups are retrieved directly from your organization's Entra ID directory. The first 500 entries are listed by default; use Load more to retrieve additional entries. You can also filter the list by user principal name (for users) or group name (for groups). If a user or group is not found in the initial list, apply the filter directly against Microsoft Entra ID to retrieve them.
Role assignments work in two ways:
- Direct role assignment — a single role applied to the entire module. A user or group with a direct Reader role, for example, has read access to all Business Processes in the module.
- Specified access — different roles assigned to different Business Processes or Business Process groups. Use this when a user or group should only access a subset of Business Processes.
Users and groups already in the Turbo360 directory can be added without reconfiguration via the Existing user and Existing group tabs respectively.
Steps
Use the following steps to manage users and groups in Business Activity Monitoring. Navigate to Business Activity Monitoring > User management to get started.
Add a user or group
Adding a user or group from Microsoft Entra ID assigns them a role and grants immediate access — no activation email is required.
- Go to the Users tab in the User management section.
- Click Add user or Add group.
- Select the required users or groups from the directory list.
- Click Add.
If the entry you need is not visible, use the filter above the list to search by user principal name or group name. If no results appear after filtering the local list, the same filter will search directly in Microsoft Entra ID.
Assigning a direct role grants the user or group that role across all Business Processes in the module.
Specified access restricts the user or group to only the Business Processes you select, with a distinct role per Business Process. Use this when a contractor or a guest-user group should not access production Business Processes.
Users and groups already in the Turbo360 directory appear in the Existing user and Existing group tabs.
Update a user or group's permissions
Updating permissions lets you change a role assignment, switch between direct and specified access, or adjust the scope for a user or group.
- Go to the User management section.
- Click the Edit permission icon next to the user or group.
- Update the role — either at a specified level or as a direct role.
- Click Update.
To update permissions for multiple users or groups simultaneously:
- Select the users or groups whose permissions you want to update.
- Click Edit permission at the top of the list.
- Assign a role — either at a specified level or as a direct role.
- Click Update.
The selected role is applied to all chosen users and groups.
View and manage access at a specified level
Viewing access at the Business Process level lets you see which users and groups have access to a particular group or Business Process and revoke direct access where needed.
- Click the Context menu ( ⋮ ) next to the Business Process group or Business Process in the tree view.
- Select Users.
Only users and groups with direct access to a Business Process or Business Process group can have that access revoked from the Users widget. Users or groups with module-level access must be updated from the User management section.
Remove a user or group
Removing a user or group revokes their access to Business Activity Monitoring. They remain in the Turbo360 directory and can be re-added at any time.
To remove a single user or group:
- Click the Remove user icon next to the user or group in the Users tab.
To remove multiple users or groups at once:
- Select the entries you want to remove.
- Click Remove above the list.
A user or group removed from a module still exists in the Turbo360 directory. To remove them from Turbo360 entirely, navigate to Settings > Users and choose Remove user/group.
Permission evaluation
Understanding how Turbo360 evaluates permissions for Microsoft Entra ID users is important when a user belongs to both a directly added account and one or more groups.
- Direct user takes precedence — if a user is added directly to Turbo360 and is also a member of an Entra ID group that has been added, only the direct user's role assignment is evaluated. Group permissions are ignored for that user.
- Group membership applies when no direct account exists — if a user is not added to Turbo360 directly but belongs to an Entra ID group that has been added, their permissions are evaluated against the roles assigned to that group.
- Multiple group membership — when a user belongs to multiple Entra ID groups, the highest-level permissions across all group role assignments apply.
- Group ownership — the same rules apply when a user is an owner (rather than a member) of an Entra ID group that has been added to Turbo360.
Although Turbo360 supports direct owners of Microsoft Entra ID groups, the recommended approach is to use group members where owners are also members of their groups.
How group authentication works
Microsoft Entra ID group authentication in Turbo360 is transitive. If you add a parent group to Turbo360, all child groups at every nesting level within that parent are also authenticated, even if those child groups are not explicitly added to Turbo360.
Child groups can be added separately when different nested groups require different permission levels based on business requirements.
Troubleshooting
-
A user or group does not appear in the Add user/group dialog.
Cause: The directory list shows the first 500 entries only, and the user or group may not be within that set.
Fix: Use the filter above the list to search by user principal name or group name. If no result is found locally, apply the same filter to search directly in Microsoft Entra ID. -
A user's permissions do not match the group role assigned to them.
Cause: The user may have been added directly to Turbo360 as well as belonging to an Entra ID group. Direct user assignments take precedence over group assignments.
Fix: Check whether the user has a direct account in the Turbo360 Users list. If so, update the direct role assignment to match the intended permissions. -
Removing a group does not revoke access for all group members.
Cause: Some members of the group may also be added directly to Turbo360, which grants access independently of the group.
Fix: After removing the group, review the Users list for any individually added members and remove them separately if required. -
Transitive child group members have unexpected access levels.
Cause: Transitive authentication means all child groups inherit the parent group's role. If child group members should have different permissions, those child groups must be added separately with their own role assignments.
Fix: Add the child groups explicitly to Turbo360 and assign appropriate roles. This overrides the inherited parent role for those members. -
Bulk permission update applied the wrong role to some users or groups.
Cause: Bulk edit applies a single role selection to all selected entries simultaneously, overwriting any existing individual assignments.
Fix: Review each affected user or group individually using the Edit permission icon and reassign the correct role.