Identity GovernanceThis provider requires an Enterprise application from Microsoft Entra ID:
- Create your own Enterprise Application
- Provide a custom name e.g., Kantoku
- Configure an App Registration
- Click on All applications
- Click on the name of the Enterprise Application created at the previous step
- Take note of the Application (client) ID and Directory (tenant) ID required to configure this connector
- Click on Certificates & secrets in the sidebar
- Create a new client secret and take note of the value that is required below for the Client Secret Value
- Click on API permissions in the sidebar
- Click on Add a permission, select the Microsoft Graph API, and the following permissions:
- Directory.Read.All
- Group.Read.All
- GroupMember.Read.All
- User.Read.All
- Click on Grant admin consent for example.com
| Name | Description |
|---|
| Application (client) ID | The previous value retrieved at step 2.3. |
| Client Secret Value | The previous value retrieved at step 2.5. |
| Name | Description |
|---|
| Directory (tenant) ID | The previous value retrieved at step 2.3. |
| Name | Description |
|---|
| Groups | This option will retrieve all groups as privileges. |
| Directory Roles | This option will retrieve all directory roles as privileges. |