Introduction
Connect Microsoft Entra ID to Sana to look up users, view profiles and managers, list and search groups, manage group membership, and create, update, or delete groups directly from Sana. In summary, the connector has the following key characteristics:
Category: Identity
Connector type: Real-time
Auth type: OAuth
Hosting type: Managed
Capabilities
This connector is able to do the following:
Capability |
List users |
Get user profiles |
Get managers |
Search groups |
List organization groups |
Create groups |
Update groups |
Update group members |
Tools
While the capabilities above describe what the connector can do at a high level, the underlying tools show exactly which operations the agent can use when you ask Sana about Microsoft Entra ID. In practice, the agent may call one or more tools to achieve a single capability.
Tool |
Add member to group |
Create group |
Delete group |
Get manager |
Get ms365 groups |
Get organization groups |
Get organization users |
Get profile |
Remove member from group |
Search groups |
Update group |
Update user |
Scope and permissions
This connector uses OAuth. When you connect your account, you will need to sign into your account and grant the required permissions:
Scope | Purpose |
User.Read | Read your basic account info and sign you in. |
View the email addresses on your account. | |
offline_access | Stay connected and refresh access when you're offline. |
openid | Verify your identity when signing in with Entra ID. |
profile | View your basic profile details (name, picture, etc.). |
Directory.ReadWrite.All | Read and update directory data across the tenant (admin consent). |
Group.ReadWrite.All | Read and manage Microsoft 365 groups in the directory (admin consent). |
User.ReadWrite | Read and update user profile information. |
Set up instructions
Prerequisites:
Your Sana workspace admin has enabled this integration – if the workspace admin has disabled the integration it won't appear in the list of available integrations.
Step 1: Go to the integrations page in Sana
In Sana, click on ... More in the sidebar, then select Integrations
Step 2: Find Microsoft Entra ID in the list of available integrations
Scroll to the Available integrations section and locate Microsoft Entra ID.
Step 3: Connect the integration
Click the integration card and select "Connect just for me", this will open a pop-up powered by Pipedream. Follow the steps in the pop-up to complete the set-up.
Step 4: Sign in to Microsoft Entra ID and approve the requested scopes
You'll be redirected to Microsoft Entra ID to go through their OAuth flow. Sign in and approve the scopes Sana needs to operate the connector.
Step 5: Complete the set up
You've successfully connected your Microsoft Entra ID account. Click Continue to complete the setup and start using the connector.
