> For the complete documentation index, see [llms.txt](https://maqsoftware.gitbook.io/embedfast-technical-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://maqsoftware.gitbook.io/embedfast-technical-documentation/setting-up/pre-deployment/microsoft-entra-security-group.md).

# Microsoft Entra security group

Follow the steps below to create a security group for the Power BI tenant Settings and add a Power BI app registration to the security group.

## Create a security group

1. Type “**Microsoft Entra ID**" in the [Azure portal](https://portal.azure.com) search bar and select said option as it appears.

   <figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-b2eba2cf875d316a7ad9ed2ae328e2c157786325%2F16.2%20(1).png?alt=media" alt=""><figcaption></figcaption></figure>
2. Select **Groups** (under Manage) from the left pane.<br>

   <figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-81ea0f717b3b97e06d28b8062d93db72d29e05d4%2F4.11.png?alt=media" alt=""><figcaption></figcaption></figure>
3. Click on **New group** to create a new security group.<br>

   <figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-4e123400d115414df5035c26598471fdca02d010%2F4.12.png?alt=media" alt=""><figcaption></figcaption></figure>
4. Fill out the **New Group** form as detailed below:<br>

   <figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-caeb2675b028be8dd7ec1160ff096c47ec7342c7%2F4.7.png?alt=media" alt=""><figcaption></figcaption></figure>

   * Group type: "**Security**"
   * Group name: Create a name for the group. In our example, we named the group PowerBIAPISG, hence it will be referred to as such in this documentation's images, etc. Feel free to create your own group name.
   * Group description: Optional.
   * Membership type: Pre-selected, it should be "**Assigned**".
5. Click **Create** to create the security group.<br>

## Add Power BI App registration to the security group

1. Select **All groups** from the left pane of the Azure AD page.
2. Type your security group's name in the search bar and click on it.

{% hint style="info" %}
**Note:** As mentioned in the previous section, we named our group PowerBIAPISG, hence it will be referred to as such in this documentation.
{% endhint %}

<figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-0df4ccd47ba5e70e347c161502bfeb7edc6be635%2F4.14.png?alt=media" alt=""><figcaption></figcaption></figure>

3. Select **Members** (under Manage) from the left pane and click on **Add members**.

   <figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-ffeb192b93c5644104de53b2b41546c14d7baf5e%2F4.9.png?alt=media" alt=""><figcaption></figcaption></figure>
4. Search for the name of the app registration created for the Power BI Service and select it. Click on the **Select** button to add the app registration to the security group.

   <figure><img src="https://2643060172-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIwWVFb1sEdUq6IwVu5D2%2Fuploads%2Fgit-blob-b2e713bed152e7ba2977dc593733417d9466db4c%2F5.0.png?alt=media" alt=""><figcaption></figcaption></figure>
