/

Entra ID

Identity connector

Entra ID

Subscribe to Entra ID user and group changes through Microsoft Graph and receive them as typed events. Use them to provision accounts, disable leavers and review risky sign-ins.

Connect Entra ID
Connect Entra ID
See setup steps
See setup steps

Identity

Category

Events

Sync mode

p95 860 ms

Latency

8 min

Setup time

What it can do

Triggers · 4
  • User createdEvent
  • Account disabledEvent
  • Group membership changedEvent
  • Risky user flaggedPoll
Actions · 5
  • Look up a userRead
  • Create a userWrite
  • Add to a groupWrite
  • Disable an accountWrite
  • Revoke sign-in sessionsWrite

Overview

The Entra ID connector creates Microsoft Graph change notification subscriptions on users and groups, so Tessel learns about changes without scanning the directory. Each notification is resolved into a typed event with the changed properties, and it appears in the trace of the run it started.

Teams use it to set up mailboxes and Teams access when HR adds a hire in Workday, to disable accounts and revoke sessions when someone leaves, and to send risky users to a security review in Microsoft Teams.

Supported tenants

  • Microsoft Entra ID Free, P1 and P2

  • Commercial and GCC tenants, single or multi-tenant apps

  • Risky user triggers require Entra ID P2

How change notifications work

Tessel subscribes to /users and /groups and validates the endpoint with Graph's token handshake. Notifications carry a resource ID, which Tessel reads back through Graph to build the full event. Subscriptions expire, so Tessel renews them a day before they lapse.

POST https://graph.microsoft.com/v1.0/subscriptions
{
  "changeType": "created,updated,deleted",
  "resource": "/users",
  "notificationUrl": "https://us-1.hooks.tessel.dev/entra",
  "expirationDateTime": "2026-11-01T00:00:00Z",
  "clientState": "<per-workspace secret>"
}
POST https://graph.microsoft.com/v1.0/subscriptions
{
  "changeType": "created,updated,deleted",
  "resource": "/users",
  "notificationUrl": "https://us-1.hooks.tessel.dev/entra",
  "expirationDateTime": "2026-11-01T00:00:00Z",
  "clientState": "<per-workspace secret>"
}
POST https://graph.microsoft.com/v1.0/subscriptions
{
  "changeType": "created,updated,deleted",
  "resource": "/users",
  "notificationUrl": "https://us-1.hooks.tessel.dev/entra",
  "expirationDateTime": "2026-11-01T00:00:00Z",
  "clientState": "<per-workspace secret>"
}

Throttling

Graph throttles per app and tenant. Tessel reads Retry-After on 429 responses, backs off and retries. Writes carry the same request ID on retry, so a user is never created twice.

Permissions needed

Register an app in Entra ID with application permissions and grant admin consent. Read permissions cover lookups and triggers. Write permissions are only needed for the create, group and disable actions.

  • User.Read.All and GroupMember.Read.All for triggers

  • User.ReadWrite.All and GroupMember.ReadWrite.All for writes

  • IdentityRiskyUser.Read.All for the risky user trigger

Setup

Five steps. About eight minutes.

Admin consent is usually the slowest part. Tessel tests each permission before you continue.

  1. Register an app and create a client secretEntra ID3 min
  2. Add Graph application permissionsEntra ID1 min
  3. Grant admin consent for the tenantEntra ID2 min
  4. Paste the tenant ID, client ID and secretTessel1 min
  5. Add a test user to a group and watch the eventVerify860 ms

Your directory, driving workflows today.

Connect Entra ID on the free plan. Up to three builders and 10,000 runs a month, no card required.

Connect Entra ID
Connect Entra ID
All integrations
All integrations

One email a month. Only what shipped.

A1

Product

C1

Layouts

D1

Company

E1

Template

F1

All systems operational
fra41 ms
iad38 ms
sin52 ms

C2

Elsewhere

XLinkedInGitHubYouTube

E2

Move across the wordmark168 blocks · iso 30°

One email a month. Only what shipped.

A1

Product

C1

Layouts

D1

Company

E1

Template

F1

All systems operational
fra41 ms
iad38 ms
sin52 ms

C2

Elsewhere

XLinkedInGitHubYouTube

E2

Move across the wordmark168 blocks · iso 30°

One email a month. Only what shipped.

A1

Product

C1

Layouts

D1

Company

E1

Template

F1

All systems operational
fra41 ms
iad38 ms
sin52 ms

C2

Elsewhere

XLinkedInGitHubYouTube

E2

Move across the wordmark168 blocks · iso 30°

Create a free website with Framer, the website builder loved by startups, designers and agencies.