Skip to main content

Microsoft Entra ID

Connection

Setup

1

Register an application

Register an app for Klef in your tenant, then add a client secret to it.
2

Grant the permissions

Add the Microsoft Graph application permissions under Permissions and grant admin consent for the tenant.
3

Add Exchange access

Only needed to manage address list visibility. Give the app the Exchange.ManageAsApp role and a certificate to sign in to Exchange Online with.

Settings

Permissions

Minimum permissions the connection requires.

microsoft_entra.user

Fields

Default Account Matching Rules

When Klef adopts an account that already exists in Microsoft Entra ID, it works out whose it is by trying these in order. A connection can override them.

Examples

Employee lifecycle

Stage a Microsoft account before day one, switch on Microsoft 365 and Slack when they start, and shut both down when they leave.

Engineering access

The engineering group, a seat on the GitHub engineering team and the incident channels, with GitHub removed when they leave.

Contractor access

Unlicensed Microsoft, Slack and AWS access for contractors that expires on their end date, with a warning to their manager first.

Leaver offboarding

Ask the manager to plan the handover, then close Microsoft, Slack and GitHub access on the last day and tell security.

Oracle HCM worker provisioning

An Entra mailbox and a nested Oracle Fusion employment record across five stages, with a worker’s assignments expanded one for one.