Microsoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. Its Microsoft Graph API lets you manage users, groups, applications, service principals, directory roles, and identity governance across your organization's tenant. Nexla connects to Microsoft Entra ID over the Microsoft Graph REST API using OAuth 2.0, so you can ingest directory data into your flows and push identity changes back into your tenant.
Power end-to-end data operations for your Microsoft Entra ID API with Nexla. Our bi-directional Microsoft Entra ID connector is purpose-built for Microsoft Entra ID, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Microsoft Entra ID or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Microsoft Entra ID workflows fast, secure, and fully governed.
Features
Type: API
- Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
- Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
- API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
- Request optimization with intelligent batching, retry, and caching to minimize API calls and costs
Prerequisites
Before creating a Microsoft Entra ID credential, you need to register an application in your Microsoft Entra tenant and obtain its Client ID and a Client Secret. Nexla connects to the Microsoft Graph API (https://graph.microsoft.com/v1.0) using the 3-legged OAuth 2.0 authorization code flow, authenticating on behalf of a signed-in user with delegated permissions.
To register an application and obtain credentials, follow these steps:
-
Sign in to the Microsoft Entra admin center with an account that has permission to register applications (for example, an Application Administrator or Global Administrator).
-
Navigate to Identity > Applications > App registrations, then click New registration.
-
Enter a display name for your application (e.g., "Nexla Integration"), select the supported account types appropriate for your organization, and click Register.
-
On the application's Overview page, copy the Application (client) ID. This is the Client ID you will enter in Nexla.
-
Navigate to Certificates & secrets, click New client secret, add a description and expiry, then click Add. Copy the secret Value immediately, as it is shown only once and cannot be retrieved after you leave the page. This is the Client Secret.
-
Navigate to API permissions, click Add a permission, select Microsoft Graph > Delegated permissions, and add the permissions your flows require (for example,
User.Read.All,Group.Read.All,Directory.Read.All, or the corresponding write scopes such asUser.ReadWrite.All). Some permissions require an administrator to click Grant admin consent for your tenant. -
Under Authentication, add a redirect URI if required by your Nexla environment's OAuth flow, and note the OAuth 2.0 authorization and token endpoints for your tenant (available via the Endpoints button on the app registration).
For detailed information about registering applications, permissions, and the Microsoft Graph API, see the Microsoft Graph API overview and Register an application with the Microsoft identity platform.
Authenticate
Credentials required
| Field | Required | Secret | Description |
|---|---|---|---|
| Authorization URL | No | No | The URL endpoint where users authenticate and authorize access |
| Client ID | Yes | Yes | A unique public identifier assigned to your application |
| Access Scope | No | No | A space-separated list of permissions your application requests |
| Token URL | No | No | The URL endpoint where authorization codes are exchanged for access tokens |
| Client Secret | No | Yes | A private key used to authenticate your application when requesting tokens |
| Base URL | Yes | No | The base URL for the Microsoft Entra ID (Microsoft Graph) API. |
Create a credential in Nexla
-
After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.
-
Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.
-
Enter the Client ID and Client Secret from your Microsoft Entra app registration, and confirm the Authorization URL, Token URL, Access Scope, and Base URL for your tenant. The Base URL defaults to
https://graph.microsoft.com/v1.0. -
Complete the OAuth 2.0 authorization flow when prompted, signing in with the user account whose delegated permissions the connection should use.
The Client Secret is sensitive information and should be kept confidential. If it is compromised, revoke it under Certificates & secrets in your app registration and generate a new one. For more information, see the Microsoft Graph authentication documentation.
-
Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.
Use as a data source
To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Microsoft Entra ID connector tile, then select the credential that will be used to connect to Microsoft Entra ID, and click Next; or, create a new Microsoft Entra ID credential for use in this flow.
Endpoint templates
Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Microsoft Entra ID endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.
Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.
Manual configuration
Microsoft Entra ID data sources can also be manually configured to ingest data from any valid Microsoft Graph API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.
Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Microsoft Entra ID data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.
Use as a destination
Click the + icon on the Nexset that will be sent to the Microsoft Entra ID destination, and select the Send to Destination option from the menu. Select the Microsoft Entra ID connector from the list of available destination connectors, then select the credential that will be used to connect to Microsoft Entra ID, and click Next; or, create a new Microsoft Entra ID credential for use in this flow.
Endpoint templates
Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Microsoft Entra ID endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.
Manual configuration
Microsoft Entra ID destinations can also be manually configured to send data to any valid Microsoft Graph API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.
Save & activate
Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Microsoft Entra ID endpoint, open the destination resource menu, and select Activate.
The Nexset data will not be sent to the Microsoft Entra ID endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.