there are certain groups users needed to be added to to use the managed identity. otherwise, they must use sp
there are certain groups users needed to be added to to use the managed identity. otherwise, they must use sp