Access Catalog
An access catalog is a named, reusable set of access profiles you attach to a guest creation template. Each profile is a plain-language label — a title and a description — that an inviter picks from in the EasyLife 365 guest creation wizard. The inviter never sees the security groups a profile grants, or their names.
The profile is the authorization boundary, not the groups behind it. You decide what Abacus production access or Vendor — read only means in terms of groups, once, in EasyLife 365 Admin. Inviters choose from those labels, and can never grant access you have not defined.
Create a catalog
- Log in to EasyLife 365 Admin (https://admin.easylife365.cloud/collab/).
- Select
Access profile catalogsin the navigation. It sits directly belowTemplates, because a catalog is only ever used by a guest template. - Click
Create new, or select an existing catalog to edit. - On the
Generaltab, configure the catalog:- Title — how the catalog is listed in Cockpit. It is never shown to an inviter or a guest.
- Allow choosing several access profiles — off means the inviter can pick at most one profile, on means they can pick any number.
- Make access profile selection required — the guest cannot be provisioned until a profile is chosen.
- Active — only an active catalog reaches the guest creation wizard.
- On the
Access Profilestab, add the profiles and put them in the order you want the inviter to see. The order set here is the order the wizard renders. - Save the catalog.
A new catalog starts inactive. If you save one while it is still inactive, Cockpit asks Activate before saving? and offers to activate it in the same step — a template can point at an inactive catalog, but the inviter is never offered its profiles.
From the catalog list you can duplicate a catalog to reuse its profiles as the starting point for a new one, or delete one you no longer need. A catalog keeps a version history, so you can see and restore what it looked like before a change.
Catalogs are managed independently of templates, so the same catalog can be attached to more than one guest creation template.
Configure an access profile
Each profile is a card on the Access Profiles tab, with these settings:
- Title and Description — the label the inviter sees in the wizard. Both are required. Use the language picker on the card to add a translation per language; the text you enter first is the default and is used for any language you have not translated.
- Colour — the card colour in Cockpit, to help you tell profiles apart while editing. It is not shown in the wizard.
- Groups granted by this profile — one or more security groups. At least one is required. These are never shown to the inviter, in the wizard or anywhere else in EasyLife 365.
- Preselected — the profile is already selected when the wizard step opens. The inviter can still change it, unless the profile is also locked.
- Locked — the profile is shown to the inviter but cannot be changed by them.
Use the arrows on a card to move a profile up or down, and the delete action to remove it.
A profile that is both Preselected and Locked is always granted, regardless of anything else the inviter chooses. Use that combination for access every guest invited through the template must receive.
Groups that cannot be used
A profile can only grant a group whose membership EasyLife can actually write. These are refused when you save, with a message naming the reason:
| Group | Why it is refused |
|---|---|
| Role-assignable groups | They grant directory roles. Handing one out through a guest template would let a template audience escalate privilege. |
| Dynamic membership groups | They compute their own membership and reject members added by hand. |
| On-premises synchronised groups | Microsoft Graph cannot write the membership of a group mastered on premises. |
| Distribution lists and mail-enabled groups | Only security groups and Microsoft 365 groups are ever eligible. |
The same check runs again at the moment access is granted, so a group that becomes role-assignable after it was put in a catalog is still not written.
The internal name of a profile is generated when you create it and is never shown or editable. It is what a wizard selection carries and what the audit trail records, so it stays stable even when you rename the profile. A single-selection catalog can preselect at most one profile.
Attach a catalog to a template
- Open the guest creation template you want to attach a catalog to.
- Go to the
Settingstab and find the Access Catalog section. - Pick the catalog under
Catalog selection.Create new catalogandEdit catalogin the section header let you build or adjust the catalog without leaving the template — your template draft is kept. - Save the template.
A template can have at most one catalog. To offer a different set of profiles, select a different catalog, or edit the profiles inside the one already attached.
The Access Catalog section is only available on templates that create a new guest account. It is not offered on templates of the "add existing guest" type — those templates are unaffected by this feature.
If the attached catalog is inactive, has been deleted, or has no profiles, the wizard simply does not show the access profiles step and the guest is invited without any catalog access. Cockpit warns you on the template when that is the case.
What the inviter sees
When a guest creation template has an active catalog attached, the guest creation wizard shows an extra Access profiles step. It is the last step, after the guest details, the owners, guest memberships, and the approval step where those apply — the access decision is asked once the rest of the request is settled.
- Profiles are shown in a table, matching the guest memberships step. Each row has a checkbox, or a radio button when the catalog allows only one profile.
- A single-selection catalog that is not required also shows an explicit No additional access row, so the inviter always has a visible way back to "none" after choosing a profile.
- A locked profile's control is shown disabled — the inviter can see that access is being granted, but cannot change it.
- A required catalog blocks the wizard until a profile is chosen.
- Titles and descriptions are shown in the inviter's own language where you have translated them, and in the default language otherwise.
- At no point does the wizard show a security group name or object ID.
What happens after the invite
Access is not granted while the wizard is open. Once the guest is invited — and, where a template requires it, once the request is approved — the EasyLife 365 Engine resolves the submitted profile selection and reconciles the guest's group memberships to match it.
- The selection travels as profile identifiers, never group IDs, and is re-validated server-side. A hand-crafted or stale request that selects a locked profile, or more profiles than a single-selection catalog allows, is rejected.
- Every group is re-validated against the rules above at the moment it is written, in case it drifted since the catalog was built.
- The Engine adds the groups behind newly selected profiles, and removes groups only where this same catalog granted them before. Groups added any other way — including through the wizard's separate guest memberships step — are never touched.
- Additions respect your tenant's allow adding guests to groups setting, and the per-group version of it, which can refuse guests on one specific group. Removals are gated by neither: taking a guest back out of a group is not what those settings exist to prevent. See Allow to add guests to Microsoft 365 Groups.
- A group that is refused is skipped rather than failing the whole invitation — the guest is created, simply without that one group.
- Each group that is granted is written to the guest's event log, naming the group and the profile it came from, and EasyLife records which groups it granted per guest and catalog so the access can be audited later.
Related pages
- Templates — creating and managing templates in general
- Data Collection for guest accounts — the rest of the guest creation wizard's data collection
- Permissions — owner permissions on a guest account template
- Allow to add guests to Microsoft 365 Groups — the tenant setting that governs guest group additions