Connect Microsoft Entra ID with Siit
Integrate Siit with Microsoft Entra ID for seamless IT service management through automatic employee data import, reducing errors and enhancing efficiency in onboarding and off boarding processes.
⚠️ App discovery from SSO sign-ins requires a Microsoft Entra ID P1 or P2 licence on your tenant. Every other part of the integration works on any Entra tier.
How does it work?
Step 1: Look for EntraID from the Apps & Integrations
Step 2: click on "Connect Now"
Step 3: Confirm you are an admin in EntraID.
⚠️ the email address used for the integration needs to be the same between Siit and EntraID
Step 4: Enter your Microsoft Tenant ID following the instructions

Here is how to find your Tenant ID

Step 5: Review your permissions and click on Next to finish the set up

🎉 Your're all set!
Enable app discovery from SSO sign-ins
By default, Siit lists the users assigned to each Entra application. To also list the users who reach an application through SSO without being assigned to it, grant Siit permission to read your sign-in logs.
- In Siit, go to Settings → Integrations → Microsoft Entra ID.
- Open the permissions section of the integration.
- Enable AuditLog.Read.All.
- Confirm. You are redirected to Microsoft to grant admin consent for the added permission.
- Open any app in Siit and check the Active Users tab. Users discovered from sign-in activity appear alongside assigned users, with Microsoft Entra Actions in the Sources column.

Frequently asked questions
Why does someone appear on an app's Active Users list when I never assigned them to it?
They signed in to that app through Entra SSO. Siit treats a successful SSO sign-in as evidence of use, so the person is listed as a user of the app even without a direct or group assignment.
Do users discovered this way stay on the list forever?
No. A membership that comes only from sign-in activity expires once the person stops signing in. If they also hold an assignment or a Siit App Access grant, they stay listed through that source instead.
I connected Entra ID but no extra users appeared. What is wrong?
Check two things. Your tenant needs a Microsoft Entra ID P1 or P2 licence, because Microsoft does not expose application sign-in logs on the free tier. And AuditLog.Read.All must be granted on the integration.
Does removing someone from an app in Siit sign them out of the app?
No. The Active Users list reflects access as your connected systems report it. To remove access, run the matching action in Siit or in Entra ID.
Does this work with Okta, Google Workspace, or JumpCloud?
Sign-in based app discovery is available for Microsoft Entra ID.
