Application roles in Azure Active Directory (Azure AD) allows administrators to club permissions of an application into a single collective and assign it to resources. This allows them to decide who has control over certain data and functions of the application. Application roles can be assigned to Azure AD groups for granting permissions over an application to multiple members conveniently. The cmdlet Get-AzureADGroupAppRoleAssignment allows us to retrieve a list of the application roles assigned to an Azure AD group.
The following is an example script for retrieving a list of the application roles assigned to an Azure AD group.
where <GroupID> denotes the ObjectID of the group for which the application roles are to be retrieved.
ManageEngine ADManager Plus is a unified Active Directory (AD), Microsoft 365, Exchange, and Google Workspace management and reporting solution. With ADManager Plus, you can use the following features to improve your organizational workflow:
Entra ID user management
Entra ID reporting
Entra ID group management
Entra ID group reporting
Entra ID domain management
Entra ID contact management and reporting
Other Entra ID tasks