Supported Features
The Microsoft Entra SaaS connector supports the following features:
Account and Identity Management
|
Feature |
Description |
|---|---|
|
Account Management for User, User in Federated Domain, Guest User (B2B), and External Member (B2B) |
Aggregate, create, update, enable, disable, and delete accounts for standard users, federated domain users, B2B guest users and external members. |
|
Aggregate and manage lifecycle operations for local B2C user accounts. |
|
|
Aggregate and provision enterprise application service principals as accounts. |
|
|
Aggregate Azure mail contacts as read-only accounts in Identity Security Cloud. |
|
|
Collect last sign-in timestamps for accounts during aggregation. |
|
|
Manage Azure managed identities, including User-Assigned Managed Identities Management and System-Assigned Managed Identities identities. |
|
|
Assign and remove Microsoft 365 and other service plan licenses for user accounts. |
Group, Role, and Entitlement Management
|
Feature |
Description |
|---|---|
|
Aggregate Microsoft Entra groups and manage group membership for accounts. |
|
|
Aggregate nested group relationships and hierarchy data. |
|
|
Aggregate built-in and custom Microsoft Entra directory roles and manage role assignments. |
|
|
Aggregate and manage administrative units and scoped role assignments. |
|
|
Aggregate and manage Entitlement Management access packages and assignments. |
|
|
Manage custom security attributes defined in Microsoft Entra ID. |
|
|
Manage extended attributes registered on the Azure client application. |
|
|
Classify privileged access for Microsoft Entra entitlements in Identity Security Cloud. |
Privileged Access and Azure Cloud Governance
|
Feature |
Description |
|---|---|
|
Manage Privileged Identity Management for Microsoft Entra roles (Azure PIM for Roles) and groups, including eligible and active assignments (Azure PIM for Groups). |
|
|
Aggregate Azure management groups, subscriptions, resource groups, and role assignments. Important
You must have a SailPoint Cloud Infrastructure Entitlement Management (CIEM) license to enable cloud governance features. Contact your SailPoint Customer Success Manager to request access. |
|
|
Configure Azure Resource Manager endpoints for cloud object aggregation and governance. |
Security, Authentication, and Compliance
|
Feature |
Description |
|---|---|
|
Manage MFA attributes such as phone numbers, email addresses, and Microsoft Authenticator settings. |
|
|
Authenticate using OAuth 2.0 grant types supported by the connector (client credentials and refresh token). |
|
|
Support continuous access evaluation for real-time access revocation scenarios. |
|
|
Surface risky user detections from Microsoft Entra ID Identity Protection. |
|
|
Surface risky service principal detections for workload identities in your tenant. |
|
|
Collect account activity data from Microsoft Entra ID for Activity Insights. |
Microsoft 365 and Collaboration
|
Feature |
Description |
|---|---|
|
Manage Exchange Online mailbox settings and attributes for Microsoft Entra user accounts. |
|
|
Aggregate and manage Microsoft Teams as entitlements. |
|
|
Aggregate and manage Microsoft Teams channels as entitlements. |
Aggregation Performance
The Microsoft Entra SaaS connector includes built-in parallel aggregation. It uses paging and processes retrieved accounts in parallel to improve account aggregation performance. For more information, refer to Aggregation and Filter Settings.
Machine Identity Governance
Important
Your organization must have SailPoint Agentic Fabric license to use this feature. Contact your Customer Success team for more information. For more information, refer to SailPoint Agentic Fabric.
|
Feature |
Description |
|---|---|
|
|
|
|
|
|
|
|
|
SailPoint Non-Human Identity (NHI) Discovery |
Discover Microsoft non-human identities and AI agents, including app registrations, SAML certificates, hybrid and cloud Entra users, Copilot chats, and secrets stored in Azure Key Vault. For more information, refer to Additional Permissions for SailPoint Non-Human Identity (NHI) Discovery. |
|
Exposed Secret Scanning |
Continuously scan Microsoft Teams, SharePoint, and OneDrive for exposed secrets. |
|
Service Principal Posture Analysis |
Detect posture issues and anomalous behavior in service principals. |