IT CanvassTalk to an advisor
Connectors · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · intermediate

Azure AD (Entra ID)

Governing cloud identity: aggregating and provisioning Azure AD (Microsoft Entra ID) users, groups and licenses.

Quick answer

The Azure AD (Entra ID) connector uses the Microsoft Graph API to aggregate cloud users and groups and to provision accounts, group membership and license assignments. It authenticates with an app registration and, unlike on-prem AD, does not require IQService.

Key takeaways
  • Uses Microsoft Graph API over REST
  • Authenticates via an Entra app registration
  • Aggregates users, groups and license state
  • Provisions accounts, group membership and licenses
  • Watch Graph API throttling on large aggregations

Azure AD, now Entra ID, is the identity backbone of Microsoft 365 and countless cloud apps. Governing it with SailPoint covers cloud account lifecycle, group and role membership, and licensing, complementing on-premise AD in hybrid estates.

Connector type and how it connects

The Azure AD (Entra ID) integration is a REST/API-based connector. It uses the Microsoft Graph API authenticated with an app registration (client credentials). As with every connector, the flow is the same: authenticate to Azure AD (Entra ID), read accounts and entitlements during aggregation, and write changes during provisioning.

Onboarding the source

  • 1. Configure the connection and credentials for Azure AD (Entra ID).
  • 2. Map the account schema, mapping Entra users, group memberships and directory roles to SailPoint accounts and entitlements.
  • 3. Set the correlation logic so Azure AD (Entra ID) accounts attach to the right identities (typically on a stable key such as employee ID or email).
  • 4. Run account aggregation and confirm accounts and entitlements load.
  • 5. Verify correlation, watching for uncorrelated/orphan accounts.

Provisioning capabilities

SailPoint can create, update, enable and disable Entra users and manage group and directory-role assignments through Microsoft Graph, driven by roles, requests and lifecycle events.

Entitlements and what to govern

Govern group memberships and directory roles, which grant access across Microsoft 365 and integrated apps. Privileged directory roles warrant close certification.

Troubleshooting

When Azure AD (Entra ID) aggregation or provisioning fails, work through the usual causes in order:

  • Verify the app registration client ID/secret or certificate and Graph permissions.
  • Confirm admin consent has been granted for the required Graph scopes.
  • Check network egress to Microsoft Graph endpoints.
  • Validate group/role schema mapping.

Common pitfalls

  • Credential expiry (tokens/secrets/certs) silently breaking the connector.
  • Insufficient rights on the Azure AD (Entra ID) service account for the operations you need.
  • Schema or correlation misconfiguration leaving accounts uncorrelated.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
The Azure AD connector talks to?

Frequently asked questions

What does the term Azure AD (Entra ID) connector refer to in SailPoint?
Azure AD, now Entra ID, is the identity backbone of Microsoft 365 and countless cloud apps. Governing it with SailPoint covers cloud account lifecycle, group and role membership, and licensing, complementing on-premise AD in hybrid estates.
What is the practical takeaway on Azure AD (Entra ID) connector?
As with every connector, the flow is the same: authenticate to Azure AD (Entra ID), read accounts and entitlements during aggregation, and write changes during provisioning.
What tends to go wrong with Azure AD (Entra ID) connector?
Credential expiry (tokens/secrets/certs) silently breaking the connector. Insufficient rights on the Azure AD (Entra ID) service account for the operations you need. Schema or correlation misconfiguration leaving accounts uncorrelated.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support