Skip to main content
Telara

Integrations / Microsoft Entra ID

Microsoft Entra ID logo

Microsoft Entra ID

Microsoft Entra ID identity and governance data for users, groups, service principals, app role mappings, access packages, assignments, policies, and reviews.

OAuth 2.0
Indexes
Spend
AI estate
Actions

What Telara does

Capability matrix

Before you connect

Prerequisites

A Microsoft Entra tenant you can administer.
An admin who can grant tenant-wide consent. Delegated user consent is not enough for directory discovery.

Vendor setup

Get the credential

1
Click Connect in Telara
Settings → Integrations → Microsoft Entra ID. Sign in as an admin and accept consent. You do not register an app in Entra or paste a client secret.
2
Re-consent if discovery is empty
If sign-in discovery is empty after a successful connect, an admin must connect again and grant the extra Graph permission this page lists. Older consents omit it.

Permissions Telara requests

  • offline_access
    OAuth 2.0
  • openid
    OAuth 2.0
  • profile
    OAuth 2.0
  • email
    OAuth 2.0
  • User.Read
    OAuth 2.0
  • User.Read.All
    OAuth 2.0
  • User.ReadWrite.All
    OAuth 2.0
  • Group.Read.All
    OAuth 2.0
  • Group.ReadWrite.All
    OAuth 2.0
  • GroupMember.ReadWrite.All
    OAuth 2.0
  • Application.Read.All
    OAuth 2.0
  • Application.ReadWrite.All
    OAuth 2.0
  • AppRoleAssignment.ReadWrite.All
    OAuth 2.0
  • Directory.Read.All
    OAuth 2.0
  • Directory.ReadWrite.All
    OAuth 2.0
  • EntitlementManagement.Read.All
    OAuth 2.0
  • EntitlementManagement.ReadWrite.All
    OAuth 2.0
  • AccessReview.Read.All
    OAuth 2.0
  • AccessReview.ReadWrite.All
    OAuth 2.0
  • AuditLog.Read.All
    OAuth 2.0

In Telara

Connect in Telara

OAuth 2.0

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

Knowledge

What gets indexed

ResourceCoverage
UsersPartial — not every record the vendor holds is synced
GroupPartial — not every record the vendor holds is synced

Spend

What gets measured

Resolution: Aggregated buckets.

Attribution: Matched to people by email.

Vendor history: 30 days of vendor-side history.

Sync

Freshness & sync

ResourceLagDeletions
UsersUp to 1 dayRemoved records disappear on the next full sync
GroupUp to 1 dayRemoved records disappear on the next full sync

Data handling

Permissions & data handling

The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.

Excluded from semantic search: Users, Group.

After connect

Verify it worked

After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.

Honesty

Known limitations

Guest and B2C tenants often lack the directory APIs Telara reads. That is an Entra plan/tenant type limit.
Consent granted by a non-admin user looks connected, then returns no users.