XSecurityGroup¶
Experimental
This API is experimental and may change without notice.
An Entra ID security group, with optional members and owners given as user principal names (UPNs). UPNs are looked up in Microsoft Graph and applied on the next reconcile, so membership changes take about one poll interval.
API¶
| Property | Value |
|---|---|
| Group | entraid.platform.example.org |
| Kind | XSecurityGroup |
| Plural | xsecuritygroups |
| Scope | Namespaced |
| Versions | v1alpha1 (referenceable) |
| Source | compositions/entraid/securitygroup/xrd.yaml |
Spec¶
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
name |
string |
yes | — | Display name of the Entra ID security group. Constraints: minLength: 1. |
members |
[]string |
no | [] |
Optional user principal names (UPNs) to add as members. |
owners |
[]string |
no | [] |
Optional user principal names (UPNs) to add as owners. When empty, the Crossplane service principal owns the group. |
Status¶
Populated by Crossplane once the underlying Azure resources exist. Every
composite in this repository exposes the provisioned Azure resource ID as
status.id.
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
id |
string |
no | — | Provider ID of the Entra ID group. |
objectId |
string |
no | — | Object ID of the Entra ID group. |
resolvedMembers |
[]object |
no | — | Members found in Entra ID (set by function-msgraph). |
resolvedMembers[].id |
string |
no | — | — |
resolvedMembers[].displayName |
string |
no | — | — |
resolvedMembers[].userPrincipalName |
string |
no | — | — |
resolvedMembers[].mail |
string |
no | — | — |
resolvedMembers[].accountEnabled |
boolean |
no | — | — |
resolvedOwners |
[]object |
no | — | Owners found in Entra ID (set by function-msgraph). |
resolvedOwners[].id |
string |
no | — | — |
resolvedOwners[].displayName |
string |
no | — | — |
resolvedOwners[].userPrincipalName |
string |
no | — | — |
resolvedOwners[].mail |
string |
no | — | — |
resolvedOwners[].accountEnabled |
boolean |
no | — | — |
unresolvedMembers |
[]string |
no | — | Member UPNs not (yet) found in Entra ID. |
unresolvedOwners |
[]string |
no | — | Owner UPNs not (yet) found in Entra ID. |
Common problems¶
The XR is not synced and events mention Authorization_RequestDenied or failing to validate a user.
Cause. The service principal lacks the Microsoft Graph application permissions Group.ReadWrite.All and User.Read.All, or admin consent is missing.
Fix. Re-run the bootstrap script as a Global Administrator or Privileged Role Administrator, or grant the permissions manually (see the cluster setup guides).
A UPN is listed in status.unresolvedMembers or status.unresolvedOwners.
Cause. The user does not exist in the tenant, or the lookup has not run yet for a newly added UPN.
Fix. Wait one reconcile; if the UPN stays listed, fix the spelling. Unknown UPNs are skipped, never applied.
The Crossplane service principal is an owner of the group.
Cause. spec.owners is empty, so Entra ID assigns the creating principal as owner.
Fix. Set at least one owner in spec.owners.
The Group managed resource is never created.
Cause. The groups.groups.azuread.m.upbound.io MRD is not activated.
Fix. Add it to activation-policies/azure/managed-resource-activation-policy.yaml.