Microsoft Entra ID identity integration with GenticFlow
Connect Microsoft 365 support, reports, and monitoring through Entra ID
Connect Microsoft tenants to GenticFlow for account support, Secure Score, Service Health, MFA Registration, and license capacity monitoring. Microsoft Entra ID also provides separately configured OIDC single sign-on. Manage accounts in the Microsoft 365 web workspace, from eligible web and mobile tickets, or from Customer / Organization pages on the web without creating a ticket. Reset passwords, sign out sessions, clear supported MFA methods, enable or disable accounts, change groups or licenses, and create users. Each change requires technician review and confirmation. Ticket outcomes appear in internal notes; standalone outcomes appear in Audit Log. The connector does not import directory users, groups, or devices as endpoints.
What GenticFlow does with this integration
OIDC Single Sign-On
- Authenticates the technician console and agent chat through Entra ID
- Issuer URL auto-discovers the OIDC endpoints from the Microsoft login tenant
- Authorization code with PKCE, with accounts created on first sign-in
- Roles map from Entra groups or App Roles; SSO can be enforced with a break-glass account
Risky User Monitoring
- Watches Entra ID Protection for high-risk users marked at risk or confirmed compromised
- Raises an alert for each flagged account, deduplicated per user and cleared when the risk resolves
- Alerts email opted-in users and, under your ticket policy, open a ticket that can notify technicians on mobile
- Monitoring reads risk data without changing accounts or importing users, groups, or devices as endpoints
Microsoft 365 Reports and Monitoring
- Select a connected tenant in the web workspace to review its enabled account, license, sign-in, and risk views
- Review Secure Score history, assessed controls, and Microsoft guidance; optional score monitoring raises platform alerts without automatic remediation
- Enable Service Health to read Microsoft service issues and updates, with service and status filters
- Enable MFA Registration to review registered methods, registration, and capability; this does not establish MFA enforcement
- Enable license capacity monitoring with a configurable available-seat threshold; it measures allocation, not actual usage, and never purchases licenses
- Reports show fetch times and support explicit refresh. Service Health and MFA Registration do not create alerts
Requirements and Handling
- Single sign-on uses the tenant's Entra app registration client ID and secret
- Risky user monitoring requires Microsoft Graph read permissions and a Microsoft Entra ID P2 license
- Secure Score requires SecurityEvents.Read.All; Service Health requires ServiceHealth.Read.All; MFA Registration requires AuditLog.Read.All and Entra ID P1 or P2; license capacity requires Organization.Read.All or an accepted broader grant
- Grant tenant administrator consent for the selected capabilities. Read-only reports can be enabled independently of Account Actions; scheduled monitoring uses the configured connector sync interval
- When a risk alert opens a ticket, it can reach a technician on their phone under your alert and notification settings
- Token renewal and Microsoft Graph pagination are handled automatically
- Account actions require an assigned Entra connector, explicit enablement, tenant admin consent, and the Microsoft permissions and directory roles needed for the selected change
Microsoft 365 Account Actions
- Look up accounts by name or email in the assigned Microsoft tenant, with tenant selection when more than one connector is available
- Reset passwords, sign out existing sessions, clear supported MFA methods, enable or disable accounts, add or remove group membership, assign or remove licenses, and create users with optional groups and a license
- Work from the Microsoft 365 web workspace, eligible web and mobile tickets, or the Microsoft 365 tab on a Customer / Organization page on the web without creating a ticket
- Sign Out Sessions revokes existing sessions without changing the password or whether the account is enabled
- Review tenant name and default domain, Member / Guest account type, enabled state, sign-in name, email, groups, licenses, registered sign-in methods, and recent sign-ins when available
- Verify requester identity and authorization, then review and confirm each change. Ticket outcomes are internal notes that can reach linked ticketing systems; standalone outcomes are recorded in Audit Log, including failed, partial, and unconfirmed changes
- Temporary passwords are shown once and omitted from notes and audit records. Confirmed ticket results can be used to draft a public reply without including the password. Account actions do not automatically resolve or close tickets
- Recent sign-in history requires additional Microsoft permissions and licensing. Unavailable account facts are marked without blocking supported actions. Clear MFA leaves hardware OATH and unsupported methods in place
- Shared mailboxes, mail forwarding, aliases, Send As rights, and SharePoint permissions are outside this account workflow
How It Works
Register GenticFlow in Entra
For single sign-on, create an app registration and configure the OIDC redirect URIs. Single sign-on is configured separately from the Graph connector.
Configure Optional Single Sign-On
Add the client ID and secret, map Entra groups or App Roles to GenticFlow roles, and optionally enforce SSO.
Configure the Graph Connector
Connect the Microsoft tenant and assign it to the relevant Customer / Organization for workspace access. Choose Account Actions, Secure Score, Service Health, MFA Registration, and the risky-user, Secure Score, or license capacity monitors you need. Enable a scheduled Sync interval for scheduled monitoring.
Grant Permissions and Test
Follow the connector setup instructions to add the required Microsoft Graph application permissions and grant tenant admin consent. Reconnect with Microsoft can request consent for permissions already configured on the app; it does not add missing permissions. Test Connection reports connection results and permission warnings; directory roles and licensing must also be checked.
Review and Confirm the Change
Open the Microsoft 365 web workspace, an eligible web or mobile ticket, or a Customer / Organization page on the web. Look up the account and choose a change. Verify requester identity and authorization, review the change, and confirm it. Internal handoff notes link technicians from external ticketing systems to the ticket and its Microsoft 365 actions.
Identity context for support workflows.
Connect the Microsoft 365 workspace for account support, security and service reports, and optional monitoring alongside endpoint tools. Technicians confirm account changes; outcomes appear in internal ticket notes or Audit Log. Entra ID single sign-on is configured separately.