Entra External ID features missing on one tenant

Vedran Opančar - dotSource SE 5 Reputation points
2025-01-24T06:48:40.98+00:00

Hello,

In my test default tenant, when I set up Entra External ID as a Global Administrator, I can access all available features. However, in my client’s Entra External tenant, where I have the roles of Application Administrator and Cloud Application Administrator, I notice several features are missing.

The missing features include but are not limited to:

  • Conditional Access
  • Custom Extension Submit options
  • Submit & Run User Flow button
  • Features labeled as "(Preview)"
  • etc

I would like to understand why these features are unavailable in my client tenant and how I can enable them.

Thank you for your assistance.

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
3,001 questions
{count} vote

2 answers

Sort by: Most helpful
  1. Abiola Akinbade 22,625 Reputation points
    2025-01-24T07:57:55.1133333+00:00

    Hello Vedran Opančar - dotSource SE,

    Thanks for your question

    This is an RBAC issue. The discrepancies you’re observing between your test tenant and your client’s Entra External ID tenant are likely due to the differences in the roles assigned to you in each environment. 

    For example To manage Conditional access you need at least the Conditional Access Administrator role as the cloud application administrator does not have the needed ppermissions for CA management:

    See: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#conditional-access-administrator

    To resolve the issue, for what you need on the tenant you need to have the appropriate roles assigned.

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola

    0 comments No comments

  2. Vedran Opančar - dotSource SE 5 Reputation points
    2025-01-24T10:47:05.34+00:00

    Thank you for your fast response and help, I appreciate it.
    Makes sense for some parts, for this it does not:

    1. How about the run user flow button missing? If we use the link format as in the test tenant we can use it without a button.
    2. Custom extension policy option in preview and all other preview features are missing...no error message..

    What I found out is that the client tenant has no linked subscription and that could be the reason.

    https://learn.microsoft.com/en-us/entra/external-id/external-identities-pricing#link-a-workforce-tenant-to-a-subscription


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.