Integrations / Microsoft Entra ID
Microsoft Entra ID
Microsoft Entra ID identity and governance data for users, groups, service principals, app role mappings, access packages, assignments, policies, and reviews.
What Telara does
Capability matrix
Before you connect
Prerequisites
Vendor setup
Get the credential
Permissions Telara requests
- offline_accessOAuth 2.0
- openidOAuth 2.0
- profileOAuth 2.0
- emailOAuth 2.0
- User.ReadOAuth 2.0
- User.Read.AllOAuth 2.0
- User.ReadWrite.AllOAuth 2.0
- Group.Read.AllOAuth 2.0
- Group.ReadWrite.AllOAuth 2.0
- GroupMember.ReadWrite.AllOAuth 2.0
- Application.Read.AllOAuth 2.0
- Application.ReadWrite.AllOAuth 2.0
- AppRoleAssignment.ReadWrite.AllOAuth 2.0
- Directory.Read.AllOAuth 2.0
- Directory.ReadWrite.AllOAuth 2.0
- EntitlementManagement.Read.AllOAuth 2.0
- EntitlementManagement.ReadWrite.AllOAuth 2.0
- AccessReview.Read.AllOAuth 2.0
- AccessReview.ReadWrite.AllOAuth 2.0
- AuditLog.Read.AllOAuth 2.0
In Telara
Connect in Telara
In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.
Knowledge
What gets indexed
| Resource | Coverage |
|---|---|
| Users | Partial — not every record the vendor holds is synced |
| Group | Partial — not every record the vendor holds is synced |
Spend
What gets measured
Resolution: Aggregated buckets.
Attribution: Matched to people by email.
Vendor history: 30 days of vendor-side history.
Sync
Freshness & sync
| Resource | Lag | Deletions |
|---|---|---|
| Users | Up to 1 day | Removed records disappear on the next full sync |
| Group | Up to 1 day | Removed records disappear on the next full sync |
Data handling
Permissions & data handling
The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.
Excluded from semantic search: Users, Group.
After connect
Verify it worked
After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.
Honesty

