Recommended Default Groups
Setting up default groups during initial configuration saves time and ensures consistent access patterns. Suggested Partner Groups| Group Name | Description | Suggested Workspace Role |
|---|---|---|
| SOC Tier 1 | Front-line analysts handling initial triage | Incident Analyst |
| SOC Tier 2 | Senior analysts with response capabilities | Incident Responder |
| SOC Managers | Team leads overseeing operations | Admin |
| Integration Engineers | Technical staff managing connectors | Data Source Admin |
| Account Managers | Customer relationship managers | Incident Analyst (read-only) |
User Management Overview
Organizational Roles
Workspace Roles
User Roles at a Glance
ContraForce uses a two-tier role system: Organizational Roles control administrative access, while Workspace Roles control operational access.Workspace Roles Quick Reference
| Role | View Incidents | Run Gamebooks | Manage Endpoints | Manage Data Connectors | Manage Users |
|---|---|---|---|---|---|
| Admin | ✓ | ✓ | ✓ | ✓ | ✓ |
| Incident Responder | ✓ | ✓ | ✓ | — | — |
| Incident Analyst | ✓ | — | — | — | — |
| Data Source Admin | ✓ | — | — | ✓ | — |
Complete Role Reference
Adding Users During Onboarding
The easiest time to add users is during the initial ContraForce onboarding process.Onboarding Wizard
When you deploy ContraForce modules, the Onboarding Wizard provides the first opportunity to add users:
Select User
Verify Name
Assign Role
Add More Users
Managing Users After Onboarding
After initial setup, you can add and manage users through the Settings page.Step 1: Consent User Management Service Principal
Before you can manage users post-onboarding, you must consent the User Management service principal:Navigate to Workspaces
Open Workspace Settings
Find User Management
Click Consent

Step 2: Access User Management
Open Settings
Select User Management
View Current Users

Step 3: Add New Users
Click Add User
Search for User
Select User
Assign Roles
Save

Understanding Role Types
Organizational Roles
Organizational roles control administrative functions across your entire ContraForce instance:| Role | Add/Manage Users | Add/Manage Groups | Add Workspaces | View All Workspaces |
|---|---|---|---|---|
| Org Admin | ✓ | ✓ | ✓ | ✓ |
| User Admin | ✓ | ✓ | — | — |
| Workspace Admin | — | — | ✓ | ✓ |
| Org Member | — | — | — | — |
Workspace Roles
Workspace roles control what users can do within specific customer workspaces:- Admin
- Incident Responder
- Incident Analyst
- Data Source Admin
- View and manage all incidents
- Run any Gamebook action
- Manage endpoints and data connectors
- Configure workspace settings
- Manage workspace users
User Groups
Simplify access management by organizing users into groups.Benefits of Groups
Bulk Assignment
Easier Management
Consistent Access
Creating Groups
Navigate to Groups
Create New Group
Add Members
Assign to Workspaces
Assigning Users to Workspaces
Users need workspace assignments to access customer data.Individual Assignment
- Open the workspace settings
- Navigate to Users or Access
- Click Add User
- Select the user and assign a workspace role
- Save changes
Group Assignment
- Open the workspace settings
- Navigate to Groups or Access
- Click Add Group
- Select the group and assign a workspace role
- All group members inherit access
Managing Existing Users
Viewing User Details
Click any user in the User Management list to view:- Assigned organizational role
- Workspace assignments and roles
- Group memberships
- Last login time
Editing User Roles
Select User
Edit Roles
Save Changes
Removing Users
Select User
Click Remove
Confirm
Best Practices
Follow the principle of least privilege
Follow the principle of least privilege
Use groups for team-based access
Use groups for team-based access
Audit user access regularly
Audit user access regularly
Document role assignments
Document role assignments
Separate admin duties
Separate admin duties
Troubleshooting
Common Issues
| Issue | Possible Cause | Solution |
|---|---|---|
| Can’t see Add User button | Missing User Admin or Org Admin role | Contact your administrator for elevated permissions |
| User not found in dropdown | User doesn’t exist in Entra ID | Verify user exists in Microsoft Entra ID |
| Consent flow fails | Insufficient admin privileges | Use Global Administrator or appropriate admin account |
| User can’t access workspace | No workspace assignment | Assign user directly or via group to the workspace |
| User has wrong permissions | Incorrect role assignment | Edit user and assign correct workspace role |