{"id":135,"date":"2020-02-17T16:24:09","date_gmt":"2020-02-17T15:24:09","guid":{"rendered":"https:\/\/help.metashare.com\/metashare-help-faq-how-do-i-assign-metashares-roles-in-azure\/"},"modified":"2025-08-05T09:41:01","modified_gmt":"2025-08-05T07:41:01","slug":"assign-application-roles","status":"publish","type":"page","link":"https:\/\/help.metashare.com\/en\/metashare\/get-started\/setup\/assign-application-roles\/","title":{"rendered":"Assign application roles"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Available user roles in MetaShare<\/h2>\n\n\n\n<p>There are a few roles that grant you different privileges in MetaShare. The roles are defined as Entra ID application roles that are managed from your Azure Portal. Any user must have at least one role. If you have the necessary Microsoft 365 licenses, roles can also be assigned to groups.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security administrator<\/h3>\n\n\n\n<p>Can manage security settings in MetaShare. Today, that is what users and groups are assigned as site collection administrator to SharePoint site collections created by MetaShare.<\/p>\n\n\n\n<div class=\"wp-block-group has-accent-2-background-color has-background\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">Recommended<\/h4>\n\n\n\n<p>It is strongly recommended that you assign a service account as Site collection administrator and a security group as Secondary site collection administrator in MetaShare\u2019s security setting after activation.<\/p>\n\n\n\n<p>This way you will not overshare with the global administrator that activated the app (that automatically becomes the site collection administrator in MetaShare workspaces) and you can easily manage administrative access to workspaces using security groups.<\/p>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-group has-accent-2-background-color has-background\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h4 class=\"wp-block-heading\">Caution!<\/h4>\n\n\n\n<p>Site collection administrator is the highest permission level within a SharePoint site. This should only be used for troubleshooting or advanced custom settings. To manage access to a workspace, it is enough to assign users to the Owners group in the SharePoint site, that has more limited permissions.<\/p>\n<\/div><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Content administrator<\/h3>\n\n\n\n<p>To access&nbsp;<a rel=\"noopener noreferrer\" href=\"https:\/\/app.metashare.com\/#\/settings\" target=\"_blank\">MetaShare&#8217;s settings<\/a> and there be able to&nbsp;configure MetaShare (normally just a few individuals per organisation should have these access-rights), the users need to be&nbsp;assigned the &#8220;Content Administrator&#8221; role. Users with this role will get the&nbsp;settings-icon, when they are in MetaShare&#8217;s start-page (MetaShare Workspace Manager):<br><img loading=\"lazy\" decoding=\"async\" width=\"107\" height=\"35\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-541.png\" alt=\"MataShare's settings icon\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Workspace creator<\/h3>\n\n\n\n<p>To be able to create MetaShare workspaces, the users need to be assigned the &#8220;MetaShare Workspace Creator&#8221; role. Users with this role will get the &#8220;New workspace&#8221; function in the toolbar of MetaShare&#8217;s start-page (MetaShare Workspace Manager):<br><img loading=\"lazy\" decoding=\"async\" width=\"226\" height=\"58\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-542.png\" alt=\"MataShare's &quot;New workspace&quot; function\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">MetaShare user<\/h3>\n\n\n\n<p>To be able to use MetaShare, as an end-user, without assigning any other roles, users need to be assigned the &#8220;MetaShare User&#8221; role.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to assign roles<\/h2>\n\n\n\n<p>The user that activated MetaShare in your Microsoft 365 tenant has automatically been assigned the &#8220;Content Administrator&#8221; and the &#8220;Workspace Creator&#8221; roles&nbsp;during the sign-up process. For other users that should have these roles you need to assign the roles in Microsoft Entra ID by following these instructions:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Go to <a rel=\"noopener noreferrer\" href=\"https:\/\/portal.azure.com\" target=\"_blank\">Azure Portal<\/a>.<\/li>\n\n\n\n<li>In the left navigation, click on &#8220;<a href=\"https:\/\/portal.azure.com\/#blade\/Microsoft_AAD_IAM\/ActiveDirectoryMenuBlade\/Overview\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Entra ID<\/a>&#8220;:<\/li>\n\n\n\n<li>Click on &#8220;<a rel=\"noreferrer noopener\" href=\"https:\/\/portal.azure.com\/#blade\/Microsoft_AAD_IAM\/StartboardApplicationsMenuBlade\/AppAppsPreview\/menuId\/\" target=\"_blank\">Enterprise applications<\/a>&#8220;:<br><img loading=\"lazy\" decoding=\"async\" width=\"474\" height=\"485\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-703.png\" alt=\"Click on &quot;Enterprise applications&quot;\"><\/li>\n\n\n\n<li>Click on the &#8220;MetaShare&#8221; application:<br><img loading=\"lazy\" decoding=\"async\" width=\"764\" height=\"635\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-704.png\" alt=\"Click on the &quot;MetaShare&quot; application\"><\/li>\n\n\n\n<li>Click on &#8220;Users and groups&#8221; and then &#8220;Add&#8221;:<br><img loading=\"lazy\" decoding=\"async\" width=\"748\" height=\"430\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-693.png\" alt=\"Click on &quot;Users and groups&quot; and then &quot;Add&quot;\"><\/li>\n\n\n\n<li>In the &#8220;Users and groups&#8221; blade, search for the user you want to assign to a role and when found, click on the name. It will then be displayed in the &#8220;Selected members&#8221; section, where you can add multiple users before you click the &#8220;Select&#8221; button:<br><img loading=\"lazy\" decoding=\"async\" width=\"904\" height=\"551\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-694.png\" alt=\"Search for the user you want to assign to a role\"><br>If you have Entra ID Premium you can assign security groups instead of individual users.<\/li>\n\n\n\n<li>Click on the &#8220;Select Role&#8221; blade and click on the role that you want to assign the users to (unfortunately you will not be able to select multiple roles, unless you have an Microsoft Entra ID premium licence) and then click the &#8220;Select&#8221; button:<br><img loading=\"lazy\" decoding=\"async\" width=\"904\" height=\"549\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-696.png\" alt=\"Click on the role that you want to assign the users\"><\/li>\n\n\n\n<li>Review you choices and click on the &#8220;Assign&#8221; button:<br><img loading=\"lazy\" decoding=\"async\" width=\"607\" height=\"505\" class=\"alignnone\" src=\"https:\/\/help.metashare.com\/wp-content\/uploads\/image-697.png\" alt=\"eview you choices and click on the &quot;Assign&quot; button\"><\/li>\n\n\n\n<li>The assigned users must log out and in again from MetaShare to get their new assigned privileges.<\/li>\n<\/ol>\n\n\n\n<p>Once users have been assigned any of the MetaShare roles, follow <a href=\"https:\/\/help.metashare.com\/en\/get-started\/pin-metashare-to-the-app-launcher-in-office-365\/\">these instructions<\/a> to pin the MetaShare app to <a rel=\"noreferrer noopener\" href=\"https:\/\/support.microsoft.com\/en-us\/office\/meet-the-microsoft-365-app-launcher-79f12104-6fed-442f-96a0-eb089a3f476a\" target=\"_blank\">Microsoft 365&#8217;s app launcher<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Available user roles in MetaShare There are a few roles that grant you different privileges in MetaShare. The roles are defined as Entra ID application roles that are managed from your Azure Portal. Any user &#8230; <a title=\"Assign application roles\" class=\"read-more\" href=\"https:\/\/help.metashare.com\/en\/metashare\/get-started\/setup\/assign-application-roles\/\" aria-label=\"Read more about Assign application roles\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"parent":10703,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":{"0":"post-135","1":"page","2":"type-page","3":"status-publish","5":"no-featured-image-padding"},"_links":{"self":[{"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/pages\/135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/comments?post=135"}],"version-history":[{"count":21,"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/pages\/135\/revisions"}],"predecessor-version":[{"id":12243,"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/pages\/135\/revisions\/12243"}],"up":[{"embeddable":true,"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/pages\/10703"}],"wp:attachment":[{"href":"https:\/\/help.metashare.com\/en\/wp-json\/wp\/v2\/media?parent=135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}