Supported Features

The Microsoft Entra SaaS connector supports the following features:

Account and Identity Management

Feature

Description

Account Management for User, User in Federated Domain, Guest User (B2B), and External Member (B2B)

Aggregate, create, update, enable, disable, and delete accounts for standard users, federated domain users, B2B guest users and external members.

Account Management for Local User (B2C)

Aggregate and manage lifecycle operations for local B2C user accounts.

Service Principal Account Management

Aggregate and provision enterprise application service principals as accounts.

Azure Mail Contact Management

Aggregate Azure mail contacts as read-only accounts in Identity Security Cloud.

Last Login for Accounts

Collect last sign-in timestamps for accounts during aggregation.

Managed Identity Management

Manage Azure managed identities, including User-Assigned Managed Identities Management and System-Assigned Managed Identities identities.

Service Plan Management (Managing Licenses)

Assign and remove Microsoft 365 and other service plan licenses for user accounts.

Group, Role, and Entitlement Management

Feature

Description

Account - Group Management

Aggregate Microsoft Entra groups and manage group membership for accounts.

Group Hierarchy Information

Aggregate nested group relationships and hierarchy data.

Microsoft Entra Role Management

Aggregate built-in and custom Microsoft Entra directory roles and manage role assignments.

Administrative Units

Aggregate and manage administrative units and scoped role assignments.

Access Package Management

Aggregate and manage Entitlement Management access packages and assignments.

Custom Security Attributes

Manage custom security attributes defined in Microsoft Entra ID.

Custom (Extension) Attributes

Manage extended attributes registered on the Azure client application.

Privilege Classification

Classify privileged access for Microsoft Entra entitlements in Identity Security Cloud.

Privileged Access and Azure Cloud Governance

Feature

Description

Azure Privileged Identity Management (PIM)

Manage Privileged Identity Management for Microsoft Entra roles (Azure PIM for Roles) and groups, including eligible and active assignments (Azure PIM for Groups).

Azure Cloud Object Management

Aggregate Azure management groups, subscriptions, resource groups, and role assignments.

Important
You must have a SailPoint Cloud Infrastructure Entitlement Management (CIEM) license to enable cloud governance features. Contact your SailPoint Customer Success Manager to request access.

Azure Government Endpoint Configuration

Configure Azure Resource Manager endpoints for cloud object aggregation and governance.

Security, Authentication, and Compliance

Feature

Description

Multi-Factor Authentication (MFA) Management

Manage MFA attributes such as phone numbers, email addresses, and Microsoft Authenticator settings.

OAuth 2.0 Authentication

Authenticate using OAuth 2.0 grant types supported by the connector (client credentials and refresh token).

Continuous Access Evaluation

Support continuous access evaluation for real-time access revocation scenarios.

Risky User Alert Feature

Surface risky user detections from Microsoft Entra ID Identity Protection.

Risky Service Principal Alert Feature

Surface risky service principal detections for workload identities in your tenant.

Activity Insights

Collect account activity data from Microsoft Entra ID for Activity Insights.

Microsoft 365 and Collaboration

Feature

Description

Exchange Online Management

Manage Exchange Online mailbox settings and attributes for Microsoft Entra user accounts.

Microsoft Teams

Aggregate and manage Microsoft Teams as entitlements.

Channel Management

Aggregate and manage Microsoft Teams channels as entitlements.

Aggregation Performance

The Microsoft Entra SaaS connector includes built-in parallel aggregation. It uses paging and processes retrieved accounts in parallel to improve account aggregation performance. For more information, refer to Aggregation and Filter Settings.

Machine Identity Governance

Important
Your organization must have SailPoint Agentic Fabric license to use this feature. Contact your Customer Success team for more information. For more information, refer to SailPoint Agentic Fabric.

Feature

Description

Machine Identity Governance

  • Govern non-human identities such as AI agents and service accounts within Identity Security Cloud.

  • Activate and deactivate governed agents in Identity Security Cloud.

Azure AI Foundry Agents Management

  • Aggregate Microsoft Foundry agents, tools, and access relationships through dataset aggregation.

  • Activate and deactivate new Azure AI Foundry agents.

Microsoft Copilot Studio Agents Management

  • Aggregate Copilot Studio agents, tools, knowledge bases, file attachments, connected agents, and access relationships.

  • Activate and deactivate Microsoft Copilot Studio agents.

Microsoft Agent 365 Catalog Management

  • Aggregate Microsoft 365 Agent Catalog packages and their service principal relationships.

  • Activate and deactivate Microsoft Agent 365 agents.

SailPoint Non-Human Identity (NHI) Discovery

Discover Microsoft non-human identities and AI agents, including app registrations, SAML certificates, hybrid and cloud Entra users, Copilot chats, and secrets stored in Azure Key Vault. For more information, refer to Additional Permissions for SailPoint Non-Human Identity (NHI) Discovery.

Exposed Secret Scanning

Continuously scan Microsoft Teams, SharePoint, and OneDrive for exposed secrets.

Service Principal Posture Analysis

Detect posture issues and anomalous behavior in service principals.