Skip to main content

Microsoft Entra ID

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. Its Microsoft Graph API lets you manage users, groups, applications, service principals, directory roles, and identity governance across your organization's tenant. Nexla connects to Microsoft Entra ID over the Microsoft Graph REST API using OAuth 2.0, so you can ingest directory data into your flows and push identity changes back into your tenant.

Microsoft Entra ID icon

Power end-to-end data operations for your Microsoft Entra ID API with Nexla. Our bi-directional Microsoft Entra ID connector is purpose-built for Microsoft Entra ID, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Microsoft Entra ID or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Microsoft Entra ID workflows fast, secure, and fully governed.

Features

Type: API

SourceDestination

  • Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
  • Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
  • API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
  • Request optimization with intelligent batching, retry, and caching to minimize API calls and costs

Prerequisites

Before creating a Microsoft Entra ID credential, you need to register an application in your Microsoft Entra tenant and obtain its Client ID and a Client Secret. Nexla connects to the Microsoft Graph API (https://graph.microsoft.com/v1.0) using the 3-legged OAuth 2.0 authorization code flow, authenticating on behalf of a signed-in user with delegated permissions.

To register an application and obtain credentials, follow these steps:

  1. Sign in to the Microsoft Entra admin center with an account that has permission to register applications (for example, an Application Administrator or Global Administrator).

  2. Navigate to Identity > Applications > App registrations, then click New registration.

  3. Enter a display name for your application (e.g., "Nexla Integration"), select the supported account types appropriate for your organization, and click Register.

  4. On the application's Overview page, copy the Application (client) ID. This is the Client ID you will enter in Nexla.

  5. Navigate to Certificates & secrets, click New client secret, add a description and expiry, then click Add. Copy the secret Value immediately, as it is shown only once and cannot be retrieved after you leave the page. This is the Client Secret.

  6. Navigate to API permissions, click Add a permission, select Microsoft Graph > Delegated permissions, and add the permissions your flows require (for example, User.Read.All, Group.Read.All, Directory.Read.All, or the corresponding write scopes such as User.ReadWrite.All). Some permissions require an administrator to click Grant admin consent for your tenant.

  7. Under Authentication, add a redirect URI if required by your Nexla environment's OAuth flow, and note the OAuth 2.0 authorization and token endpoints for your tenant (available via the Endpoints button on the app registration).

For detailed information about registering applications, permissions, and the Microsoft Graph API, see the Microsoft Graph API overview and Register an application with the Microsoft identity platform.

Authenticate

Credentials required

FieldRequiredSecretDescription
Authorization URLNoNoThe URL endpoint where users authenticate and authorize access
Client IDYesYesA unique public identifier assigned to your application
Access ScopeNoNoA space-separated list of permissions your application requests
Token URLNoNoThe URL endpoint where authorization codes are exchanged for access tokens
Client SecretNoYesA private key used to authenticate your application when requesting tokens
Base URLYesNoThe base URL for the Microsoft Entra ID (Microsoft Graph) API.

Create a credential in Nexla

  1. After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.

  2. Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.

  3. Enter the Client ID and Client Secret from your Microsoft Entra app registration, and confirm the Authorization URL, Token URL, Access Scope, and Base URL for your tenant. The Base URL defaults to https://graph.microsoft.com/v1.0.

  4. Complete the OAuth 2.0 authorization flow when prompted, signing in with the user account whose delegated permissions the connection should use.

    The Client Secret is sensitive information and should be kept confidential. If it is compromised, revoke it under Certificates & secrets in your app registration and generate a new one. For more information, see the Microsoft Graph authentication documentation.

  5. Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.

Use as a data source

To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Microsoft Entra ID connector tile, then select the credential that will be used to connect to Microsoft Entra ID, and click Next; or, create a new Microsoft Entra ID credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Microsoft Entra ID endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.

[Rest API] List Users

Returns a list of all users in the Azure AD tenant.

[Rest API] List Groups

Returns a list of all groups in the Azure AD tenant.

[Rest API] List Applications

Returns a list of all applications registered in the Azure AD tenant.

[Rest API] Get User Owned Deleted Items

Retrieves deleted directory items owned by a specific user.

[Rest API] List Directory Roles

Returns a list of all directory roles that are activated in the tenant.

[Rest API] List Directory Role Templates

Returns a list of all directory role templates available in Azure AD.

[Rest API] List Directory Audit Logs

Returns a list of directory audit logs for activities in the Azure AD tenant.

[Rest API] List Service Principals

Returns a list of all service principals in the Azure AD tenant.

[Rest API] List Available Identity Provider Types

Returns a list of available identity provider types that can be configured in Azure AD.

[Rest API] Get Admin Consent Request Policy

Retrieves the admin consent request policy for the Azure AD tenant.

[Rest API] Get AutoSuggest Suggestions

Returns a list of query suggestions based on a search query submitted to the Bing AutoSuggest API.

[Rest API] List members assigned to a specific directory role

List members assigned to a specific directory role

Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.

Manual configuration

Microsoft Entra ID data sources can also be manually configured to ingest data from any valid Microsoft Graph API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.

Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Microsoft Entra ID data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.

Use as a destination

Click the + icon on the Nexset that will be sent to the Microsoft Entra ID destination, and select the Send to Destination option from the menu. Select the Microsoft Entra ID connector from the list of available destination connectors, then select the credential that will be used to connect to Microsoft Entra ID, and click Next; or, create a new Microsoft Entra ID credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Microsoft Entra ID endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.

[Rest API] Register a new application in the directory

Register a new application in the directory

[Rest API] Create a new security group or Microsoft 365 group

Create a new security group or Microsoft 365 group

[Rest API] Create a new service principal for an application

Create a new service principal for an application

[Rest API] Create a new user in the Entra ID tenant

Create a new user in the Entra ID tenant

[Rest API] Add a member (user, service principal, or nested group) to a group

Add a member (user, service principal, or nested group) to a group

[Rest API] Remove a member from a group

Remove a member from a group

[Rest API] Delete (soft-delete) a user from the directory

Delete (soft-delete) a user from the directory

[Rest API] Update user profile properties (display name, job title, department, account enabled/disabled, etc.)

Update user profile properties (display name, job title, department, account enabled/disabled, etc.)

[Rest API] Restore a soft-deleted user, group, or application from deleted items.

Restore a soft-deleted user, group, or application from deleted items.

[Rest API] Assign a user or service principal to a directory role

Assign a user or service principal to a directory role

[Rest API] Update an existing application registration (redirect URIs, display name, required resource access, etc.)

Update an existing application registration (redirect URIs, display name, required resource access, etc.)

[Rest API] Update group properties such as display name, description, and membership rules

Update group properties such as display name, description, and membership rules

[Rest API] Update service principal properties (display name, preferred token signing key, tags, etc.)

Update service principal properties (display name, preferred token signing key, tags, etc.)

[Rest API] Create a new Conditional Access policy

Create a new Conditional Access policy

[Rest API] Update an existing Conditional Access policy. Docs fetch err

Update an existing Conditional Access policy.

[Rest API] Delete an application registration from the directory

Delete an application registration from the directory

[Rest API] Delete a group from the directory

Delete a group from the directory

[Rest API] Delete a service principal from the directory

Delete a service principal from the directory

Manual configuration

Microsoft Entra ID destinations can also be manually configured to send data to any valid Microsoft Graph API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.

Save & activate

Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Microsoft Entra ID endpoint, open the destination resource menu, and select Activate.

The Nexset data will not be sent to the Microsoft Entra ID endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.