If you are a Zammo on-tenant customer you can connect an Microsoft Entra ID (Azure AD) security group in which you can place “Super Admin” users.

Key Benefits

Overview of the Enabling Process

  1. Identify or Create a Security Group: Start with an existing Microsoft Entra ID (Azure AD) security group or create a new one to serve as your Super Admin group.
  2. Grant Access: Authorize the Zammo app to read group memberships through Microsoft Graph. This permission enables Zammo to only access object IDs within the group, ensuring security.
  3. Provide Object ID: Submit the security group's object ID to Zammo support for connection.
  4. Activation: Zammo support will enable the Super Admin group feature on your tenant, completing the setup.

Detailed Steps

Step 1: Creating or Identifying Your Super Admin Group

Before you begin, decide whether you will use an existing Microsoft Entra ID security group or create a new one for your Super Admins. If you choose to create a new group, follow these guidelines:

  1. Access Microsoft Entra ID (Azure AD): Log into your Microsoft Azure portal and navigate to your Microsoft Entra ID tenant.
  2. Security Groups: Go to the "Groups" section and click on "New group."
  3. Group Details: Fill in the necessary information, ensuring you select "Security" as the group type. Name the group in a way that clearly identifies its purpose, such as "Zammo Super Admins."
  4. Add Members: Include users who should have Super Admin privileges in this group.

Step 2: Granting Microsoft Entra ID App Access

To allow Zammo to read the memberships of your Super Admin group, follow these steps:

ℹ️ This step involves making modifications to the Zammo app registration within Microsoft Entra ID. If you're unsure of the app registration's name, Zammo support can assist by providing the "Client ID" for you which you can then use to find the app registration. Simply reach out to us at https://zammo.ai/support/, and we'll help locate the ID needed for these changes.

  1. API Permissions: Navigate to the Zammo app registration, select "API permissions," and add a permission for Microsoft Graph.