Skip to content

XSecurityGroup

Experimental

This API is experimental and may change without notice.

An Entra ID security group, with optional members and owners given as user principal names (UPNs). UPNs are looked up in Microsoft Graph and applied on the next reconcile, so membership changes take about one poll interval.

API

Property Value
Group entraid.platform.example.org
Kind XSecurityGroup
Plural xsecuritygroups
Scope Namespaced
Versions v1alpha1 (referenceable)
Source compositions/entraid/securitygroup/xrd.yaml

Spec

Field Type Required Default Description
name string yes — Display name of the Entra ID security group. Constraints: minLength: 1.
members []string no [] Optional user principal names (UPNs) to add as members.
owners []string no [] Optional user principal names (UPNs) to add as owners. When empty, the Crossplane service principal owns the group.

Status

Populated by Crossplane once the underlying Azure resources exist. Every composite in this repository exposes the provisioned Azure resource ID as status.id.

Field Type Required Default Description
id string no — Provider ID of the Entra ID group.
objectId string no — Object ID of the Entra ID group.
resolvedMembers []object no — Members found in Entra ID (set by function-msgraph).
    resolvedMembers[].id string no — —
    resolvedMembers[].displayName string no — —
    resolvedMembers[].userPrincipalName string no — —
    resolvedMembers[].mail string no — —
    resolvedMembers[].accountEnabled boolean no — —
resolvedOwners []object no — Owners found in Entra ID (set by function-msgraph).
    resolvedOwners[].id string no — —
    resolvedOwners[].displayName string no — —
    resolvedOwners[].userPrincipalName string no — —
    resolvedOwners[].mail string no — —
    resolvedOwners[].accountEnabled boolean no — —
unresolvedMembers []string no — Member UPNs not (yet) found in Entra ID.
unresolvedOwners []string no — Owner UPNs not (yet) found in Entra ID.

Common problems

The XR is not synced and events mention Authorization_RequestDenied or failing to validate a user.

Cause. The service principal lacks the Microsoft Graph application permissions Group.ReadWrite.All and User.Read.All, or admin consent is missing.

Fix. Re-run the bootstrap script as a Global Administrator or Privileged Role Administrator, or grant the permissions manually (see the cluster setup guides).

A UPN is listed in status.unresolvedMembers or status.unresolvedOwners.

Cause. The user does not exist in the tenant, or the lookup has not run yet for a newly added UPN.

Fix. Wait one reconcile; if the UPN stays listed, fix the spelling. Unknown UPNs are skipped, never applied.

The Crossplane service principal is an owner of the group.

Cause. spec.owners is empty, so Entra ID assigns the creating principal as owner.

Fix. Set at least one owner in spec.owners.

The Group managed resource is never created.

Cause. The groups.groups.azuread.m.upbound.io MRD is not activated.

Fix. Add it to activation-policies/azure/managed-resource-activation-policy.yaml.

Reference