Skip to content
  • There are no suggestions because the search field is empty.

Connect Microsoft Entra ID with Siit

Integrate Siit with Microsoft Entra ID for seamless IT service management through automatic employee data import, reducing errors and enhancing efficiency in onboarding and off boarding processes.

 

⚠️ App discovery from SSO sign-ins requires a Microsoft Entra ID P1 or P2 licence on your tenant. Every other part of the integration works on any Entra tier.


 

How does it work?

 

Step 1: Look for EntraID from the Apps & Integrations

Step 2: click on "Connect Now"

Step 3: Confirm you are an admin in EntraID.

⚠️ the email address used for the integration needs to be the same between Siit and EntraID

Capture d’écran 2025-03-03 à 15.23.18

 

Step 4: Enter your Microsoft Tenant ID following the instructions

Capture d’écran 2025-03-03 à 15.23.27

Here is how to find your Tenant ID

 

Step 5: Review your permissions and click on Next to finish the set up

Capture d’écran 2025-03-03 à 15.23.23

🎉 Your're all set!

Enable app discovery from SSO sign-ins

By default, Siit lists the users assigned to each Entra application. To also list the users who reach an application through SSO without being assigned to it, grant Siit permission to read your sign-in logs.

  1. In Siit, go to Settings → Integrations → Microsoft Entra ID.
  2. Open the permissions section of the integration.
  3. Enable AuditLog.Read.All.
  4. Confirm. You are redirected to Microsoft to grant admin consent for the added permission.
  5. Open any app in Siit and check the Active Users tab. Users discovered from sign-in activity appear alongside assigned users, with Microsoft Entra Actions in the Sources column.

CleanShot 2026-09-10 at 11.52.11@2x

Frequently asked questions

Why does someone appear on an app's Active Users list when I never assigned them to it?

They signed in to that app through Entra SSO. Siit treats a successful SSO sign-in as evidence of use, so the person is listed as a user of the app even without a direct or group assignment.

Do users discovered this way stay on the list forever?

No. A membership that comes only from sign-in activity expires once the person stops signing in. If they also hold an assignment or a Siit App Access grant, they stay listed through that source instead.

I connected Entra ID but no extra users appeared. What is wrong?

Check two things. Your tenant needs a Microsoft Entra ID P1 or P2 licence, because Microsoft does not expose application sign-in logs on the free tier. And AuditLog.Read.All must be granted on the integration.

Does removing someone from an app in Siit sign them out of the app?

No. The Active Users list reflects access as your connected systems report it. To remove access, run the matching action in Siit or in Entra ID.

Does this work with Okta, Google Workspace, or JumpCloud?

Sign-in based app discovery is available for Microsoft Entra ID.