> For the complete documentation index, see [llms.txt](https://docs.siit.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.siit.io/integrations/iam/microsoft-entra-id.md).

# Microsoft Entra ID

Connect Microsoft Entra ID to Siit to sync your users, groups, and application assignments, and expose Entra actions directly inside Siit workflows, request side panels, and the IT Agent.

<figure><img src="https://451675063-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fz9xmM8V3atukfr2XaElR%2Fuploads%2F3O1o9QmGlf1hPH9A3E6g%2FSiit_Microsoft_Entra_Id.jpg?alt=media&amp;token=4c38893f-2d6d-4faa-8f6f-e391b2317880" alt=""><figcaption></figcaption></figure>

### What you get

* **Live directory** — Entra users, groups, and Enterprise Applications sync into Siit with full attribute coverage.
* **One-click actions from any request**: add to or remove from groups, suspend or unsuspend an account, force a password change, clear sessions, all from the request side panel, with no trip to the Microsoft admin center.
* **Workflow-driven provisioning** — use Entra actions in any workflow: access requests, Day-1 onboarding, offboarding, and more.
* **Microsoft 365 context** — pairs well with the Microsoft Teams integration so you get a fully unified employee experience across chat, identity, and requests.
* **Usage based app inventory**: application membership in Siit reflects who signs in to an app, not only who was assigned to it.

### What syncs from Entra ID

| Fields                                                                                    |
| ----------------------------------------------------------------------------------------- |
| Display name, user principal name (UPN), work email, object ID                            |
| Job title, department, manager, office location, usage location, start date, phone number |
| Security groups and Microsoft 365 groups, memberships, ownership                          |
| Enterprise Applications assigned to users, and applications reached through Entra SSO     |
| Active / blocked / deleted                                                                |

Work email (mail attribute or UPN) is the canonical identifier.

These attributes sync into People fields, and Entra ID can be set as the **Priority source** for any of them in **Settings → Context management → People fields**, alongside your HRIS. If more than one system feeds the same field, the priority source wins.

#### App discovery from SSO sign-ins

Siit reads Entra ID sign-in activity to establish who actually uses each application, not only who was assigned to it. Assignment tells you who was granted access; sign-in activity tells you who uses it. Siit combines both:

* **Assigned users**: anyone assigned to an Enterprise Application, directly or through an assigned group, appears in that app's **Active Users** list in Siit.
* **Signed-in users**: anyone who reaches an application through Entra SSO appears in that app's **Active Users** list, with or without an assignment.

Memberships derived from sign-in activity track current usage, so an unused SSO membership expires. Siit reference-counts access: a user who is also assigned to the application stays on the list, and a user whose only source was the expired sign-in drops off. Licence and access reviews therefore run against who signs in rather than who someone once assigned.

> **Note** - Sign-in based discovery requires a Microsoft Entra ID P1 or P2 licence. Microsoft exposes application sign-in logs only on those tiers. On Entra ID Free the rest of the integration works normally, and **Active Users** lists show assigned users only.

Changing an application's group assignments in Entra now recomputes the app list of every member of that group, so an app assigned to a single group shows everyone in it rather than nobody. The same applies to Okta.

#### Sync custom applications

By default Siit imports the Enterprise Applications it recognises from its own catalog. Turn on **Sync custom applications** and it also imports your tenant's own applications, plus third-party apps missing from the catalog.

The switch sits under the roles in the **Microsoft Entra ID** connect modal, and is prefilled with your current choice when you relink. It is off unless you turn it on, and it applies from the first sync after you connect.

With it on:

* Applications your tenant owns are imported when they are configured for SSO or when they require assignment. Plain app registrations stay out.
* An application matching nothing in Siit's catalog becomes an app in your catalog once it has at least one user or group assignment. The name comes from Entra, and the link is its SAML sign-on URL, its homepage, or its My Apps launcher URL, whichever exists first.
* Every Entra app has its name, link and status refreshed on each sync. Disabling an app in Entra deprecates its service in Siit; re-enabling it reverts that.
* An application deleted in Entra is marked missing and pruned two days later.

{% hint style="info" %}
The first sync after you turn the switch on is long by design: Siit reads a 30-day sign-in window for each newly discovered app. Expect a newly enabled tenant to fill in over roughly half an hour. No extra Microsoft Graph permission is needed.
{% endhint %}

#### Actions available

Entra actions run from three places: the **Microsoft Entra ID** block in the request side panel, the **Microsoft Entra** action list in the Workflow editor, and IT Agent playbooks. Whichever you use, the account change happens in your tenant and the request keeps the record of who ran it and when.

| Action                       | What it does                                                                        | Graph permission it needs            | Side panel | Workflow |
| ---------------------------- | ----------------------------------------------------------------------------------- | ------------------------------------ | :--------: | :------: |
| **Add user to groups**       | Adds the user to one or several Entra groups                                        | `GroupMember.ReadWrite.All`          |      ✓     |     ✓    |
| **Remove user from groups**  | Removes the user from one or several Entra groups                                   | `GroupMember.ReadWrite.All`          |      ✓     |     ✓    |
| **Suspend user**             | Disables the account in Entra ID, so the person can no longer sign in               | `User.EnableDisableAccount.All`      |      ✓     |     ✓    |
| **Unsuspend user**           | Re-enables an account that was suspended                                            | `User.EnableDisableAccount.All`      |      ✓     |     ✓    |
| **Force password change**    | Requires the user to set a new password at their next sign-in                       | `User-PasswordProfile.ReadWrite.All` |      ✓     |     ✓    |
| **Clear user sessions**      | Revokes active sign-in sessions and refresh tokens, signing the user out everywhere | `User.RevokeSessions.All`            |      ✓     |     ✓    |
| **Open profile in Entra ID** | Opens the user directly in the Microsoft Entra admin center                         | —                                    |      ✓     |     —    |

Sensitive actions can be gated behind an approval step, in a Workflow or in an IT Agent playbook. Every run is recorded on the request timeline and on the person's timeline.

> **Note** - Entra ID now exposes the same account actions as Google Workspace, Okta and JumpCloud, so a single offboarding or security Workflow reads the same whichever identity provider you run.

> **Note** - clearing sessions is not instant on Microsoft's side. Siit tells you so when the action succeeds: it can take a few minutes to fully propagate.

**What Siit refuses to do**

Some accounts are deliberately off limits, and Siit says which one it hit rather than failing silently:

* **The admin who connected Entra** cannot be suspended, have their password expired, or have their sessions cleared — that would lock Siit out of your tenant.
* **Accounts mastered on-premises** (synced into Entra from Active Directory) cannot be suspended, unsuspended, or forced to change their password. Change them in the source directory instead.
* **Guest accounts** cannot have their sessions cleared.
* A **person with no Entra account**, or one archived in Siit, is left untouched and Siit tells you why.

If a permission was never consented, the action stops before it runs and names the Graph permission to grant. Reconnect Entra to add it.

<figure><img src="https://451675063-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fz9xmM8V3atukfr2XaElR%2Fuploads%2FlFmCc3APkOvVo2z8BYB0%2Fimage.png?alt=media&amp;token=e93d1d00-dff9-4754-bab2-1292e889a680" alt=""><figcaption></figcaption></figure>

### Before you connect

* You'll need an **Entra ID Global Administrator** (or Privileged Role Administrator) to grant admin consent for the required permissions.
* Siit is installed as an Enterprise Application in your Entra tenant via OAuth consent — no certificates, manifests, or manual app registrations required.
* If your tenant blocks user consent for third-party apps, admin consent must be granted explicitly during the install flow.
* Sign-in based app discovery requires a **Microsoft Entra ID P1 or P2** licence on the tenant.

### Connect Entra ID

1. In Siit, go to **Settings → Workspace → Integration library**.
2. Find **Microsoft Entra ID** in the IAM section and click **Connect**. In the setup modal, pick the roles to import and decide whether to turn on **Sync custom applications**, then click **Configure**. You'll be redirected to Microsoft, and your choices are carried through the redirect.
3. Sign in with a Global Administrator account.
4. Review and grant admin consent for the requested Microsoft Graph permissions:
   * `User.Read.All` — read user profiles
   * `Group.Read.All` + `GroupMember.ReadWrite.All` — read groups, manage memberships
   * `Directory.Read.All` — read org structure
   * `Application.Read.All` — read Enterprise Applications
   * `User.EnableDisableAccount.All` — for **Suspend user** and **Unsuspend user**
   * `User-PasswordProfile.ReadWrite.All` — for **Force password change**
   * `User.RevokeSessions.All` — for **Clear user sessions**
   * `User-LifeCycleInfo.Read.All` — read start dates for People fields sync
   * `AuditLog.Read.All`: read application sign-in logs for SSO based app discovery
5. Once consent is granted, Microsoft redirects you back to Siit.
6. Siit runs an initial import of users, groups, and applications.
7. Review the imported data and click **Finish setup**.

> **Tip** — Install with a dedicated service / break-glass Global Admin account if your security policy prefers it. The OAuth grant is tenant-wide and survives the installing admin leaving the company.

### After the connection

* **Check your People list:** confirm the user count matches your Entra active users.
* **Scope the groups:** by default all groups are synced. In **Settings → Workspace → Integration library → Microsoft Entra ID**, you can scope to specific groups or OUs.
* **Try an action from a request**: open any request, find the **Microsoft Entra ID** block in the side panel, and open its **Actions** menu.
* **Build a workflow:** a classic starter: manager approval → Entra add to group → DM confirmation.

### Sync frequency

Entra data refreshes automatically every few hours. Actions run on demand, immediately, when triggered.

To pull the directory in straight away, open the **⋯** menu on the Microsoft Entra ID card in **Settings → Workspace → Integration library** and pick **Synchronize**. The action hides itself while a sync is running and for 15 minutes after the last one.

### Common workflows

**Access request.** *Trigger: Request submitted (service = "Request app access"). Actions: manager approval → Entra add to the group that carries the app → DM requester.*

**Group membership request.** *Trigger: Request submitted. Actions: approval → Entra add to group → confirmation message.*

**Day-1 onboarding (with HRIS).** *Trigger: Start date. Actions: Entra add to baseline groups → add to the department's app groups → notify manager.*

**Offboarding on end date.** *Trigger: End date. Actions: Entra clear user sessions → remove user from groups → suspend user → equipment pickup request.*

**Compromised account.** *Trigger: Request submitted (service = "Report a compromised account"). Actions: Entra clear user sessions → force password change → notify the manager.*

### SSO is separate

Connecting Entra here is about using it as a **directory and action source**. If you only want to let users sign in to Siit with their Microsoft account, see SAML - SSO. Most customers do both.

### Troubleshooting

**Admin consent error during install.** You signed in with an account that doesn't have Global Admin rights — or your tenant requires explicit admin consent. Retry with a Global Admin account.

**An action stops and names a Graph permission.** That permission was not consented at install time (for example `User.RevokeSessions.All` is missing for **Clear user sessions**). Reconnect Entra and re-grant the full permission set.

**"Insufficient privileges" when running an action.** The consent exists but Microsoft refused the call. Either the connecting administrator's Entra role is too narrow, the permission was not consented for this tenant, or the account is mastered outside Entra.

**Users missing from Siit.** Check whether guest accounts and deactivated users are excluded (they are, by default). Adjust the filter in **Settings → Workspace → Integration library → Microsoft Entra ID** if needed.

**Group not available as a target.** The group may be out of scope, or it's a distribution group that doesn't support programmatic membership management via Graph. Check group type in Entra.

**Connection shows as "needs reauthorization".** An admin revoked the Siit Enterprise Application's consent, or a conditional access policy is blocking the token refresh. Reconnect the integration.

**Active Users lists show assigned users only.** Application sign-in logs are unavailable on Entra ID Free. Confirm the tenant carries a Microsoft Entra ID P1 or P2 licence, then check that `AuditLog.Read.All` is granted in **Settings → Workspace → Integration library → Microsoft Entra ID**.
