how to find which group membership grants app access
Traces which AD or Entra group gives a user access to an application. Covers token groups, app assignment, and nested group expansion. Use when access works but nobody knows why, or to audit access paths. Not for fixing denied access (check assignment first).
TL;DR
Check the app's assignment in the IdP admin console first (Okta app assignments or Entra enterprise app users and groups). Then expand nested groups to confirm the membership path. For AD-native apps, check the user's tokenGroups to see the effective group list.
The error
(Audit or troubleshooting question; no error. "Why does this user have access?")Steps
- In the IdP, open the app > Assignments (Okta) or Users and groups (Entra enterprise app). Expected: the granting group is listed. This answers the question in most cases.
- If the assignment is a group, expand it: check the group's members and any nested groups. Expected: the membership chain user > nested group > assigned group is visible.
- For AD-native apps (file shares, legacy SSO), check the user's effective groups: PowerShell
whoami /groupsas the user, or check the tokenGroups attribute. Expected: full group list including nested. - Watch for "Authenticated Users" or "Domain Users" assignments. Expected: noted if present. These grant access to everyone and explain mystery access instantly.
- Document the path in the ticket: app > assigned group > nested groups > user. Expected: clear chain. This is what auditors want to see.
When to use
- Auditing why a user has access
- Cleaning up access before offboarding
- Troubleshooting unexpected access
When not to use
- Access denied errors (check assignment and licensing first)
- Real-time provisioning issues
Compatibility
- Okta, Entra ID, and Active Directory; PowerShell ActiveDirectory module for AD checks
Variants
Access via multiple paths
Users often have access through two groups. Remove one and test before removing both.
Dynamic groups in Entra
Membership is rule-based; check the rule, not a static member list.
Why it happens
Access flows through assignments, and assignments usually point at groups, which nest. Nobody memorizes the nesting, so the path has to be traced each time.
Edge cases
- Group nesting loops are prevented by AD, but deep nesting (5+ levels) is common in old domains.
- Privileged groups: finding Domain Admins nested inside an app group is a finding, not just an answer.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstH16DD7jshVUuCRiwdgbaA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.