> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Add Users to TOTAL via Azure AD

1. Sign in to the [Entra Portal](https://entra.microsoft.com/#home)
2. In the left sidebar, click **Enterprise applications**
   <Frame>
     <img src="https://mintcdn.com/truu-2/oIO4SaQWAf6TpJHr/images/image-56.png?fit=max&auto=format&n=oIO4SaQWAf6TpJHr&q=85&s=9535a6a4b58b3a538faaace7c31c2371" alt="Image" width="227" height="516" data-path="images/image-56.png" />
   </Frame>
3. Select your **TOTAL** application, then select **Users and Groups**
   <Frame>
     <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-57.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=0f0132e954019844b793dc5f59db8937" alt="Image" width="901" height="786" data-path="images/image-57.png" />
   </Frame>
4. Click **Add user/group**
   <Frame>
     <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-58.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=274f1d3db809ef973d2f240192ebbac5" alt="Image" width="898" height="543" data-path="images/image-58.png" />
   </Frame>
5. Under "Users and Groups", click **None Selected**
   <Frame>
     <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-59.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=ce349a7225c98ca3be4e2ea661c6019d" alt="Image" width="282" height="102" data-path="images/image-59.png" />
   </Frame>
6. Search for and select any combination of:
   * Individual users you want to provision
   * Existing groups whose members should be provisioned
   * A new group — if you need one, create it first:
     * Microsoft Entra ID → Groups → New group
       <Frame>
         <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-60.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=4f8bc8cbe399cc0efb8ea3b0504d3197" alt="Image" width="1130" height="786" data-path="images/image-60.png" />
       </Frame>
     * Set "Group type" to **Security**
     * Enter a *Group name* (e.g. TOTAL - Engineering)
     * Set "Membership type" to **Assigned** (or Dynamic for rule-based)
     * Click **Add members**, select users, click **Select**, then **Create**
       <Frame>
         <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-61.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=05598847f2380db018f7cdef6d619b96" alt="Image" width="619" height="786" data-path="images/image-61.png" />
       </Frame>
     * Return to Enterprise applications → TOTAL → Users and groups → Add user/group and search for the new group
7. Click **Select**, then click **Assign**
   <Frame>
     <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-62.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=7adbbde62c5aa9d44f60ea48197c2e75" alt="Image" width="549" height="788" data-path="images/image-62.png" />
   </Frame>
   <Frame>
     <img src="https://mintcdn.com/truu-2/JLmgue9xoFZKzd_x/images/image-63.png?fit=max&auto=format&n=JLmgue9xoFZKzd_x&q=85&s=dada022666dd83fade6d7f019760b54f" alt="Image" width="573" height="161" data-path="images/image-63.png" />
   </Frame>
8. Trigger provisioning — either:
   * Wait for the next automatic cycle (\~40 minutes), or
   * Provision on demand: Enterprise applications → TOTAL → Provisioning → Provision on demand, search for the user or group, and run it
   ### Key points:
   * Adding a user to an already-assigned group automatically provisions them — no need to re-assign the group
   * Removing a user from all assigned groups/users will deprovision them on the next sync
   * Admins are not part of the monitored group by default. If you want admins to be monitored, you must also add them to the monitored group.
