Skip to content

Assign Entra ID roles

This guide walks you through assigning Microsoft Entra roles to the Identity Stack enterprise application. The roles enable BusinessID features for users, such as password reset and MFA management.

Only assign the roles required for the services in your agreement:

RolePurpose
Authentication AdministratorPassword reset
Issuing a Temporary Access Pass (TAP)
Authentication Policy AdministratorManaging hardware OATH tokens (TOTP)

Prerequisites

The Identity Stack enterprise application must be installed in your tenant. See Setup Identity Stack.

1. Open Roles and administrators

Go to Roles and administrators in Microsoft Entra ID.

Roles and administrators in Microsoft Entra ID

2. Add an assignment for the role

Select the relevant role and click Add assignment. If both roles are needed, repeat steps 2–4 for each role.

Add assignment for the role

3. Select the Identity Stack application

Search for the application Identity Stack (Enterprise application) and click Select.

Select the Identity Stack application

4. Configure and assign

Click Next and select Active assignment and Permanently assigned. Enter a justification for the role assignment and click Assign.

Note: The assignment type and duration settings are only shown in tenants that use Microsoft Entra Privileged Identity Management (PIM). Without PIM, the role is assigned directly.

Assignment settings

The application can now perform the BusinessID actions covered by the assigned roles on behalf of users.