Enterprise Application Add Assignment - Disabled Roles

rschiefer 6 Reputation points MVP
2020-08-03T16:25:27.377+00:00

Why are some of the roles disabled on the Enterprise Applications Add Assignment wizard?

All the roles were previously enabled.

I am currently using these "disabled" roles on login for users who were already assigned the roles but I can't assign the disabled roles to new users.

This is for SSO to AWS.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,201 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,668 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. soumi-MSFT 11,716 Reputation points Microsoft Employee
    2020-08-04T06:37:53.03+00:00

    @rschiefer , Thank you for reaching out. Can you check the app manifest for the AWS application under the Application Registration portal and check for the role name under the appRoles array. Look for the appRoles and check if the isEnabled key for each of those are set to true or false. If they are showing as disabled mostly they might have got disabled from app manifest somehow.

    Hope this helps.

    Do let us know if this helps and if there are any more queries around this, please do let us know so that we can help you further. Also, please do not forget to accept the response as Answer; if the above response helped in answering your query.