How to Control Access to Enterprise Applications with Microsoft Entra ID
Introduction
In a modern identity-first environment, controlling who can access an enterprise application is just as important as integrating the application itself. Microsoft Entra ID provides an Enterprise Applications experience that lets administrators add supported applications to the tenant and control which users or groups are assigned to them.
This walkthrough demonstrates a practical scenario: adding GitHub Enterprise Cloud – Enterprise Account from the Microsoft Entra application gallery and then assigning selected users to the application.
Scenario and expected outcome
The scenario is simple: an organization wants only specific users or groups to have access to an enterprise application.
The workflow has two main phases:
1. Add the enterprise application to the Microsoft Entra tenant.
2. Assign the intended users or groups to the application.
At the end, the GitHub Enterprise Cloud – Enterprise Account application is present under Enterprise applications, and the selected identities are visible under the application's Users and groups configuration.
Prerequisites
· Access to the Microsoft Entra admin center.
· An account with the administrative permissions required to add and manage
enterprise applications.
· A test user or group to assign to the application.
Step 1 — Add GitHub Enterprise Cloud to Microsoft Entra ID
1. Sign in to the Microsoft Entra admin center at https://entra.microsoft.com with an
account that has the required administrative permissions.
2. From the left navigation, under Entra ID, select Enterprise apps.
3. On the Enterprise applications page, select + New application.
4. On the Browse Microsoft Entra Gallery page, enter GitHub in the search box.
5. From the results, select GitHub Enterprise Cloud – Enterprise Account.
6. Review the application settings and select Create.
After creation, Microsoft Entra redirects you to the GitHub Enterprise Cloud – Enterprise Account application page.





Step 2 — Assign users or groups to the application
1. From the GitHub Enterprise Cloud – Enterprise Account application page, open
Overview.
2. Under Getting Started, select Assign users and groups.
3. Alternatively, under Manage, select Users and groups.
4. On the Users and groups page, select + Add user/group.
5. On the Add Assignment page, select None selected in the Users and groups
section.
6. Select the intended test user(s) and/or administrator account.
7. Select Select and then select Assign to complete the assignment.

Validate the configuration
After the assignment is completed, return to the application's Users and groups page and verify that the intended user or group appears in the assignment list.
This provides a simple administrative validation: the enterprise application exists in the Microsoft Entra tenant and the intended user/group has been explicitly assigned to the application.
Why application assignment matters
Application onboarding and application access are two separate administrative activities. Creating an enterprise application establishes the application object in Microsoft Entra ID. Assigning users or groups establishes the identities that are intended to use that application.
This separation is useful for controlled enterprise access because administrators can manage application membership explicitly. In the lab scenario, the final configuration demonstrates how access to a federated application can be governed through user/group assignment.
Conclusion
Microsoft Entra Enterprise Applications provides a practical administrative workflow for onboarding supported applications and controlling their assigned users or groups.
Using GitHub Enterprise Cloud – Enterprise Account as an example, the process is straightforward: Add application → Review/Create → Open Users and groups → Select identities → Assign → Validate.




Comments