Entra ID
  • 21 Nov 2024
  • 3 Minutes to read
  • Dark
    Light
  • PDF

Entra ID

  • Dark
    Light
  • PDF

Article summary

This guide will teach you how to set up the connector between Entra ID (formerly Azure Active Directory) and Clarity Security.
Estimated time to complete: 15 minutes
If you run into any problems, please contact your support team or support@claritysecurity.io.


Before you begin
  • An admin will need to Grant Consent to the API permissions in Step 13.
  • If you are using Entra Privileged Identity Management, please refer to this article for additionally required scopes: PIM/PAM Entitlement Considerations

How to Setup the Connector

Step 1: Log in to Azure

https://portal.azure.com

Step 2: Search for Entra ID

ALTTEXT

Step 3: Navigate to App Registrations

ALTTEXT

Step 4: Click New Registration

Click New Registration while on the App registrations page.

ALTTEXT

Step 5: Configure the Application and Register

Fill out the App registration form using the information below.

  • Name: Choose a descriptive name, such as "Clarity-App-Connector"
  • Supported account types: Accounts in this organizational directory only
  • Redirect URI: Web > https://your-tenant.claritysecurity.io/application/oauthProcessCode/microsoft-entra-id

ALTTEXT

Step 6: Collect details from the Application Overview

Copy the Application (client) ID and Directory (tenant) ID on the Application Overview screen. You will use these values in Step 19.

ALTTEXT

Step 7: Click on Certificates & secrets

ALTTEXT

Step 8: Click New Client secret

Enter a description for the client secret.

ALTTEXT

Step 9: Copy the Client Secret Value into a secure location

ALTTEXT

Step 10: In the App, click on View API permissions

ALTTEXT

Step 11: Select Microsoft Graph

ALTTEXT

Step 12: Click Application Permissions

ALTTEXT

Step 13: Search for and assign all of the following API Permissions Click> Add Permissions

  • App Catalog - AppCatalog.Read.All
  • Application - Application.ReadWrite.All
  • Directory - Directory.ReadWrite.All
  • Group - Group.Create, Group.ReadWrite.All
  • Group Member - GroupMember.ReadWrite.All
  • Offline - offline_access
  • Role Management - RoleManagement.ReadWrite.Directory
  • User - User.Read.All, User.ReadWrite.All
  • Administrative Units - AdministrativeUnit.ReadWrite.All
Additional Read Only Scopes for PIM
  • PrivilegedEligibilitySchedule.Read.AzureADGroup
  • PrivilegedAssignmentSchedule.Read.AzureADGroup
  • PrivilegedAccess.Read.AzureADGroup
  • PrivilegedAccess.Read.AzureResources
  • PrivilegedAccess.Read.AzureAD

PIM/PAM Entitlement Considerations

Step 14: Verify the API/Permissions match the below screenshot

An admin will need to click Grant admin consent to apply the permissions.

ALTTEXT

Step 15: Locate and copy your Tenant ID

The Tenant ID will be on the landing page of Entra ID. Copy the Tenant ID to a secure location, you will use this value in Step 19.

ALTTEXT
ALTTEXT

Step 16: Log in to Clarity

Step 17: Select Applications and click on Marketplace

ALTTEXT

Step 18: Search for Entra ID and click Connect

ALTTEXT

Step 19: Fill out the Connect App form

ALTTEXT
Details for fields common to all applications can be found in the following article: Common App Configuration Steps

Step 20: Fill out the App Settings form

image.png

Details for fields common to all applications can be found in the following article: Common App Configuration Steps

Step 21: Fill out the User Settings form

image.png

Details for fields common to all applications can be found in the following article: Common App Configuration Steps

Step 22: Validate Your Selections and Save

Save

Clicking the Save button will trigger the first full sync for your application (even if you selected Manual syncing). This includes Service Users, Entitlements, Service User Entitlements, Service User Attributes.


Need help?

If you have any problems, contact your customer success team. You can also get in touch with our general support via email, open a support ticket. Our general support team is available Monday - Friday from 8:00 AM - 6:30 PM CST.


Was this article helpful?

What's Next
Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.