Entra ID
Subscribe to Entra ID user and group changes through Microsoft Graph and receive them as typed events. Use them to provision accounts, disable leavers and review risky sign-ins.
Identity
Category
Events
Sync mode
p95 860 ms
Latency
8 min
Setup time
What it can do
- User createdEvent
- Account disabledEvent
- Group membership changedEvent
- Risky user flaggedPoll
- Look up a userRead
- Create a userWrite
- Add to a groupWrite
- Disable an accountWrite
- Revoke sign-in sessionsWrite
Overview
The Entra ID connector creates Microsoft Graph change notification subscriptions on users and groups, so Tessel learns about changes without scanning the directory. Each notification is resolved into a typed event with the changed properties, and it appears in the trace of the run it started.
Teams use it to set up mailboxes and Teams access when HR adds a hire in Workday, to disable accounts and revoke sessions when someone leaves, and to send risky users to a security review in Microsoft Teams.
Supported tenants
Microsoft Entra ID Free, P1 and P2
Commercial and GCC tenants, single or multi-tenant apps
Risky user triggers require Entra ID P2
How change notifications work
Tessel subscribes to /users and /groups and validates the endpoint with Graph's token handshake. Notifications carry a resource ID, which Tessel reads back through Graph to build the full event. Subscriptions expire, so Tessel renews them a day before they lapse.
Throttling
Graph throttles per app and tenant. Tessel reads Retry-After on 429 responses, backs off and retries. Writes carry the same request ID on retry, so a user is never created twice.
Permissions needed
Register an app in Entra ID with application permissions and grant admin consent. Read permissions cover lookups and triggers. Write permissions are only needed for the create, group and disable actions.
User.Read.AllandGroupMember.Read.Allfor triggersUser.ReadWrite.AllandGroupMember.ReadWrite.Allfor writesIdentityRiskyUser.Read.Allfor the risky user trigger
Five steps. About eight minutes.
Admin consent is usually the slowest part. Tessel tests each permission before you continue.
- Register an app and create a client secretEntra ID3 min
- Add Graph application permissionsEntra ID1 min
- Grant admin consent for the tenantEntra ID2 min
- Paste the tenant ID, client ID and secretTessel1 min
- Add a test user to a group and watch the eventVerify860 ms
Your directory, driving workflows today.
Connect Entra ID on the free plan. Up to three builders and 10,000 runs a month, no card required.