---
title: Entra Security Groups for Access Grants
description: Reference Entra ID security groups by object ID or display name when granting self-service data access.
---

# Entra Security Groups for Access Grants

Several Forge features grant an Entra ID group or user principal access to your application's data through an entry that takes either an `object_id` or a `group_name`. This page owns the rules for choosing between them.

| Feature | Setting | Guide |
| ------- | ------- | ----- |
| Cosmos DB read-only access | `data_readers` in `feature-database-cosmodb-vars.yaml` | [Self-Service Read-Only Access](../../data/cosmos-nosql.md#self-service-read-only-access) |
| Service Bus subscription DLQ access | `dlq_readers` and `dlq_managers` in `feature-event-subscription-dlq-vars.yaml` | [Self-Service DLQ Access](../../eventing/event-subscription.md#self-service-dlq-access) |

Some features accept only a literal object ID. Blob Storage's `contributor_group_id` and the Service Bus queue's `dlq_reader_identities` and `dlq_manager_identities` take a GUID and do not resolve group names; see [Blob Storage](../../data/storage-account.md#enable-blob-storage-feature-flag) and [Service Bus Queue](../../eventing/servicebus-queue.md#enable-the-service-bus-queue-feature-flag).

## Group membership

You manage membership of the Entra ID groups you reference. Forge provisions the role assignment for the group; it does not manage who belongs to the group.

## Prefer `object_id`

Use `object_id` when possible. It identifies exactly one group or user principal and avoids ambiguous display-name lookups.

Find a group's object ID in the Entra admin center under **Microsoft Entra ID** → **Groups** → select your group → copy the **Object ID** from the overview page, or with the Azure CLI:

```powershell
az ad group show --group "<group display name>" --query id -o tsv
```

## `group_name` constraints

A `group_name` entry resolves the group by its Entra ID display name, restricted to groups with `security_enabled = true`. Two constraints follow:

- **Display names must be unique** across all security groups in the tenant. If multiple security groups share the same display name, the Terraform plan fails.
- **Microsoft 365 groups are not supported.** Only security groups match.
