Give a client's own staff access to Avvi

Import the client's security groups, then map which of their admin groups may manage which user groups. Permissions add up rather than replacing each other.

Letting a client’s own people ask Avvi directly is how an MSP takes first-line requests off its queue. It is set up per client and is off until you do it.

The work has two halves. Import the client’s security groups, then map which of their admin groups may manage which of their user groups.

Everything a mapped group can do is granted deliberately. Nothing is switched on by importing alone.

Before you begin

Know which of the client’s security groups you want to use.

Agree with the client which of their staff should be able to manage others, because that is what the mapping decides.

Set up the access

  1. Open the client and go to User Access Control.
  2. Select Import from Entra. The client’s security groups appear in the table.
  3. Select Add mapping, then choose an admin group and the Managed-user group it may manage.
  4. Save the mapping. It appears in the list of mappings.
  5. Open the mapping and set what each side is allowed to do.

Avvi warns you if the same people appear in both the admin group and the user group it manages, and lets you continue if that is intended.

Good to know

Permissions are additive. Somebody in two mapped groups gets what both allow, rather than the narrower of the two.

An imported group with no mapping does nothing. Importing is preparation, not access.

Where the client is your own organisation, groups already used for portal access show as Reserved and cannot be chosen in a mapping. That does not apply to an ordinary client.

Verify it worked

Ask somebody in the mapped user group to open chat and ask for something simple about their own account.

Confirm that somebody outside the mapped groups is refused. Both halves are worth checking.

If something doesn’t look right

If a mapped person can do nothing, open the mapping and confirm permissions were set. A mapping with nothing selected grants nothing.

If somebody can do more than expected, check whether they are in a second mapped group. Permissions add up.

If none of that explains it, open a support conversation from the Help drawer. Include the client name and both group names.

FAQ

Q: Does this let the client’s staff manage each other?

A: Only where you map an admin group to a user group and grant it.

Q: Can I undo it?

A: Yes. Remove the mapping or narrow what it allows.

Q: Do I need consent for this?

A: Consent is what lets Avvi act in that client at all, so it has to be in place first.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy