Help Center/Enterprise Plan Features/Single sign-on with Microsoft Entra ID

How access changes take effect

When does a group change actually show up in TestCollab? A short guide to how roles are applied, when they refresh, and how to make a change take effect right away.

Once single sign-on and group mapping are in place, TestCollab keeps access in sync with your directory on its own. Knowing exactly when each change lands makes planning much easier.

Roles are applied at sign-in

Each time someone signs in through Entra, TestCollab reads their current groups and app roles and brings their TestCollab roles in line with them. Move someone from Viewers to Testers and their new role is applied in TestCollab instantly after the provisioning.

Removal does not wait for a sign-in

TestCollab checks the live Entra application assignment when it issues a session, and re-checks it for sessions already in use. Someone you remove from the enterprise application loses access straight away. They do not keep working until their token expires, and you do not have to wait for the next provisioning sync.

Accounts are created and removed on their own

If you have set up automatic user provisioning, adding or removing someone in your directory creates or removes their TestCollab account without anyone touching TestCollab. Entra checks regularly on its own; use Provision on demand in Azure when you want a single change pushed immediately.

Making sure Entra is the only way in

If you want your directory to be the single control point for access, turn on All users must use Entra authentication on the Microsoft Entra ID settings page. Email-and-password sign-in stops working for your company, so removing someone's access in your directory removes their way in to TestCollab.

Quick reference

Change you make

When it shows up in TestCollab

You add someone to a mapped group

At their next sign-in, or as soon as provisioning syncs, if it is set up

You move someone between mapped groups

As soon as provisioning syncs. Use Provision on demand to push it at once

You remove someone from a mapped group

As soon as provisioning syncs. Provision on demand drops them to the default role in the same run, without waiting for a sign-out

You remove someone from the application

Right away

Last updated 2026-07-23.