Role Assignment Compare — User Guide
Overview
Role Assignment Compare shows which security roles users hold in each of your Dataverse environments, side-by-side. It highlights differences so you can quickly spot missing or unexpected role assignments across environments.
Prerequisites
- Two or more active connections to Dataverse environments
- Read access to users, teams, and security roles in each environment
Getting Started
- Select Role Assignment Compare from the sidebar
- Select the environments you want to compare
Workflow
1. Choose Environments
Add the environments to compare using the environment selector. You can compare two or more environments simultaneously.
2. Select Users
Choose the users to include in the comparison:
- Search by name or email address
- Select individual users or use Select All to include everyone
- Users are matched across environments by email address (UPN)
3. Load Assignments
Click Compare to fetch role assignments from all selected environments.
4. Review the Results
Results are displayed in a table with one row per user:
| Column | Description |
|---|---|
| User | Display name and email |
| [Environment name] | Comma-separated list of role names in that environment |
| Status | ✅ Match / ⚠️ Mismatch |
Expand a user row to see the full role list per environment with direct vs. team-inherited indicators.
Highlighting:
- Roles present in one environment only are highlighted in amber
- Users with identical assignments across all environments are shown without highlighting
- Users not found in a target environment are marked as Not found
5. Filter Results
| Filter | Description |
|---|---|
| Mismatches only | Show only users where role assignments differ between environments |
| Search | Filter by user name or email |
6. Export
Click Export to download the comparison as CSV or Excel. Each row includes the user and their role assignments per environment.
Tips
| Tip | Detail |
|---|---|
| Match by email | Users are matched by UPN — if the same person has different email addresses in each environment, they will appear as separate rows |
| Include team-inherited roles | Enable the "Include team roles" toggle to see the full picture, not just direct assignments |
| Use after user migration | Run after migrating users to a new environment to confirm all role assignments transferred correctly |
| Mismatches are expected between Dev and Prod | Filter to show only Production vs. UAT comparisons for meaningful audits |
Troubleshooting
| Problem | Resolution |
|---|---|
| User missing from target environment | The user account may not exist in that environment — they need to be provisioned separately |
| All users show as mismatch | Check that the environments contain the same security roles — custom roles may differ by environment |
| Roles appear with a GUID instead of name | The role name could not be resolved — this may occur for deleted or renamed roles |