Managing users with Microsoft Entra ID

Prev Next

Overview

This article describes the user management capabilities in Cost Analyzer for a Turbo360 account using Microsoft Entra ID authentication. Account owner and Owner roles can control who can access the module and what they can do inside it — adding Microsoft Entra ID users and groups, assigning roles at the module level or scoped to specific Cost management groups, and removing users or groups when access is no longer needed.

If your Turbo360 account uses Email authentication for sign-in instead, see Managing users with email authentication — user provisioning and role assignment work differently for that authentication mode.

Business value

Centralized user management lets you enforce least-privilege access across Cost Analyzer by reusing your organization's existing Microsoft Entra ID users and groups — granting broad access to administrators while restricting contractors or guest users to only the Cost management groups they need, reducing the risk of unintended cost data exposure.

Prerequisites

Your Turbo360 account must use Microsoft Entra ID for authentication. You also need the appropriate role in Cost Analyzer to manage users and groups — see Required permissions below.

Required permissions

Role Access
Account owner Full access — add, update, and remove users and groups
Owner Full access — add, update, and remove users and groups
Custom role with Manage users enabled Full access — add, update, and remove users and groups
Custom role without Manage users No access to user management

To perform user management operations, you must have the Account owner or Owner role, or a custom role with the Manage users permission enabled. Account owners can enable this under Specify management permissions when configuring a custom role.

Besides the built-in Account owner and Owner roles, a custom role can also be granted user management access. Under Roles > Add role > Specify management permissions, enabling Manage users lets that role add or remove users and groups, and update their permissions. It does not grant the ability to create, edit, or delete roles — that stays limited to Account owner and Owner. This permission applies module-wide and works the same way regardless of whether the account uses Email authentication or Microsoft Entra ID.

How it works

Cost Analyzer supports two ways to assign roles to a Microsoft Entra ID user or group:

  • Direct role assignment — assigns a role for the entire module. For example, assigning Reader directly to a user or group gives that user or group complete read access to all Cost management groups in Cost Analyzer.
  • Specified access — assigns different roles to different Cost management groups. For example, if your organization has separate Production and Development Cost management groups, a contractor or a Microsoft Entra ID group with guest users can be given Specified access, selecting only the group they should see and assigning a role scoped to it.

Users or groups already added to Turbo360 — as members of other modules, or with no module permission yet — can be added to Cost Analyzer from the Existing user and Existing group tabs instead of retrieving them fresh from Microsoft Entra ID.

Permission evaluation:

  • When a Microsoft Entra ID user is added directly as a member of Turbo360, permissions are evaluated against the roles assigned to that user. If the same user is also a member of a Microsoft Entra ID group added to Turbo360, the group's permissions are not evaluated — direct user membership takes precedence.
  • When a user signs in as a member of a Microsoft Entra ID group (not added directly), permissions are checked against the roles assigned to that group. If the user belongs to multiple groups, the highest-level permissions across all groups apply.
  • The same precedence applies when a user signs in as a direct owner of a Microsoft Entra ID group that has been added to Turbo360.

Although Turbo360 supports direct owners of Microsoft Entra ID groups, the recommended approach is to keep group owners as members of those groups as well.

Group authentication behavior:

  • Microsoft Entra ID group authentication is transitive — if a parent group is added to Turbo360, all child groups at every inner level are authenticated, even if those child groups are not added to Turbo360 directly.
  • Child groups can still be added individually if users in different child groups require different permissions based on business needs.

Steps

Use the following steps to add, manage, and remove Microsoft Entra ID users and groups in Cost Analyzer. Navigate to Cost Analyzer > User management > Users tab to get started.

Add a user or group

Adding a user or group grants Cost Analyzer access to that Microsoft Entra ID identity.

  1. Go to the Users tab in the User management section.
  2. Select Add user or Add group.
  3. In the retrieved list, select the required Microsoft Entra ID user or group. The first 500 users or groups are listed initially — use Load more to load additional results, or use the filter option above the list (by User principal name for users, or by group name for groups). If no match is found in the retrieved list, apply the same filter directly against Microsoft Entra ID to pull matching results.
  4. Assign either a direct role or Specified access to one or more Cost management groups.

Users or groups already part of Turbo360 can instead be added from the Existing user or Existing group tab under Add user and Add group respectively.

Update user or group permissions

Updating permissions lets you change a user's or group's role scope without requiring you to remove and re-add them.

  1. Navigate to the User management section of the module.
  2. Click Edit permission in the Actions column next to the user or group.
  3. Update the role — either as a direct role or with specified access.
  4. Click Update.

To update permissions for multiple users or groups at once:

  1. Select the users or groups whose roles you want to update.
  2. Click Edit permission above the list.
  3. Assign a role — either as a direct role or with specified access.
  4. Click Update.

Create, edit, or delete a role

Managing roles lets you define custom permission sets, rather than relying only on the built-in Owner, Contributor, and Reader roles. Only Account owner and Owner can perform this — a custom role with Manage users enabled cannot create, edit, or delete roles.

  1. Go to the Roles tab in the User management section.
  2. Select Add role to create a new custom role, or select an existing role to edit it.
  3. Configure account, management, feature, and optimization tab permissions for the role.
  4. Save the role. To remove a role that's no longer needed, delete it from the Roles list.

Remove a user or group

Removing a user or group revokes their access to Cost Analyzer. The user or group remains in Turbo360's directory and can be re-added later.

  • To remove a single user or group, click Remove user/group in the Actions column.
  • To remove multiple users or groups, select them and click Remove above the list.

A user or group removed from a module still exists in Turbo360's directory. Account owners can remove them completely from Turbo360 by navigating to Settings > Users and choosing Remove user/group.

Permission behavior

  • Account owner / Owner — can add users and groups, remove users and groups, edit any user's or group's role assignment, and create, edit, or delete roles, either directly across the module or scoped to specific Cost management groups.
  • Custom role with Manage users enabled — can add users and groups, remove them, and update their permissions, but cannot create, edit, or delete roles — that remains exclusive to Account owner and Owner.
  • Users/groups with Direct role assignment — inherit that role's permissions across the entire module; without Manage users enabled, they cannot manage other users' or groups' access.
  • Users/groups with Specified access — only see and act within the Cost management groups they've been explicitly granted, at the role level assigned for each group.
  • Users added directly to Turbo360 — take precedence over any Microsoft Entra ID group membership; group-level permissions are not evaluated for them.
  • Users signing in via group membership — are evaluated against the group's assigned role, or the highest-level role across all groups they belong to.

Example scenario

An organization has two Cost management groups: Production and Development. A contractor, or a Microsoft Entra ID group containing guest users, should not have even Reader access to Production. Instead of a Direct role assignment (which would apply module-wide), the Account owner assigns the contractor or group Specified access, selecting only the Development group and assigning a role scoped to it. The contractor or group members can now act only within Development, with no visibility into Production. When the engagement ends, the owner removes the user or group from the module.

Limitations

  • This article applies only to Turbo360 accounts using Microsoft Entra ID authentication. Accounts using Email authentication follow a different user provisioning flow — see Managing users with email authentication.
  • A user or group removed from Cost Analyzer still exists in Turbo360's directory and retains membership in other modules until an Account owner removes them completely from Settings > Users.
  • Creating, editing, and deleting roles is restricted to Account owner and Owner — this cannot be delegated via the Manage users permission.
  • Microsoft Entra ID group authentication is transitive across all inner levels of a parent group, which can grant access more broadly than expected if child group membership isn't reviewed.

Troubleshooting

  1. A known Microsoft Entra ID user or group doesn't appear in the list
    Cause: Only the first 500 users or groups from Microsoft Entra ID are loaded initially.
    Fix: Use the Load more option to load additional results, or use the filter option above the list. If still not found, apply the same filter directly in Microsoft Entra ID.

  2. A user's access doesn't reflect their Microsoft Entra ID group's role
    Cause: The user was added directly to Turbo360, so direct membership takes precedence and group permissions are not evaluated for that user.
    Fix: Check whether the user has a direct role assignment and edit that assignment instead of the group's.

  3. A user with Manage users can't create, edit, or delete a role
    Cause: Manage users only grants control over users, groups, and their role assignments — it doesn't extend to managing roles themselves.
    Fix: Ask an Account owner or Owner to create, edit, or delete the role; this can't be delegated to a custom role.

Related articles