Microsoft Entra
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. Connecting Entra ID to Harmony enables automated user provisioning, intelligent license management, and seamless access control across your Microsoft 365 ecosystem and integrated applications.
What the Microsoft Entra ID integration enables
User Provisioning
Automate user lifecycle management across Microsoft 365 services
License Management
Track and optimize Microsoft 365 licenses to reduce costs
Group Management
Sync security and distribution groups for access control
Application Discovery
Identify all enterprise applications and their assignments
Automation Workflows
Build custom workflows using Microsoft Graph API
Login Event Tracking
Monitor Entra sign-in activity directly within Harmony
OOO Calendar Sync
Automatically reroute tickets when agents are out of office
Prerequisites
Before connecting Microsoft Entra ID to Harmony, ensure you have:
Microsoft 365 Global Administrator access
A Harmony account with admin privileges
Connect Microsoft Entra ID
Navigate to Integrations
Log into your Harmony dashboard
Navigate to Settings → Integrations
Find Microsoft Entra ID under Identity Provider
Click Connect

Navigate to Microsoft Entra ID integration in Harmony dashboard Authorize Entra ID
You'll be redirected to Microsoft to authorize the connection
Sign in with your Microsoft 365 admin account
Review the requested permissions
Click Accept to authorize
You'll be redirected back to Harmony

Microsoft Entra ID authorization dialog Verify Connection
Confirm that Microsoft Entra ID shows Connected status in your Harmony integrations page.
Enable Password Reset
Resetting a user's password through Harmony requires an additional Entra role assignment on top of the API permissions already granted to the Harmony application. The Privileged Authentication Administrator role must be assigned to the Harmony Entra ID enterprise application.
How to assign the role
In the Microsoft Entra admin center, go to Roles and administrators
Search for Privileged Authentication Administrator and open the role

Privileged Authentication Administrator role in Entra Roles and Administrators Click Add assignments
In the search panel, search for Harmony and select Harmony Entra ID (Enterprise application)

Add assignments panel with Harmony Entra ID selected Click Add to confirm the assignment
Once assigned, Harmony can reset passwords for users in your Entra ID directory.
What Harmony Syncs from Entra ID
Once connected, Harmony automatically syncs:
Users
User profiles (name, email, job title)
User Principal Name (UPN)
User status (enabled, disabled) - reflected as Active, Inactive, or Terminated
Department and office location
Manager relationships
Member/Guest type
Last sign-in activity (requires Microsoft Entra Premium license; left empty for non-Premium accounts)
Assigned licenses
Groups
Security groups
Microsoft 365 groups
Distribution lists
Group memberships
All assigned group types per group (a single group can belong to multiple types simultaneously, such as Security and Microsoft 365)
Applications
Enterprise applications, including all associated Entra groups
App registrations
User and group assignments
OAuth permissions
Application inventory synced automatically to your Harmony software catalog
Login Events
Harmony captures and normalizes Entra sign-in activity into a consistent event format. For each sign-in event, Harmony records:
Login timestamp - when the sign-in occurred, reflecting the actual time of the action rather than when Harmony's polling process picked it up
IP address - the network source of the login
Device information - the device used during sign-in
Location metadata - geographic context for the login event
Harmony syncs data every 24 hours by default.
Configure Custom Field Mapping
By default, Harmony maps standard Entra ID fields to employee attributes automatically. If your organization uses non-standard or custom Entra fields to store employee information, you can configure custom field mapping overrides.
For example, if your organization stores employee location in a custom Entra attribute rather than the default field, you can map Harmony's location attribute to that custom field instead.
How field mapping overrides work:
Map any supported employee attribute (such as location) to a custom Entra field of your choice
Override keys are validated against known field mappings, so only supported fields can be remapped
Custom mappings take effect on the next sync cycle
To configure field mapping, navigate to your Microsoft Entra ID integration settings in Settings → Integrations and look for the Field Mapping configuration options.
Outlook Calendar OOO Sync
For organizations on Microsoft 365, Harmony can detect out-of-office (OOO) events directly from Outlook Calendar via the Microsoft Entra integration and update each agent's availability status in real time - no manual status changes needed.
How it works:
Harmony reads OOO events from Outlook Calendar and marks agents as unavailable for the duration of the event
Tickets are automatically rerouted when an agent is marked out of office, preventing ticket stranding
Availability status is updated in real time as OOO events are detected
This brings full parity with the existing Google Calendar OOO integration and extends it to cover automatic ticket dispatch.
To enable Outlook Calendar OOO sync, ensure your Microsoft Entra integration is connected and navigate to your availability settings in Harmony.
Entra User Management in Workflows
You can automate common Microsoft Entra identity management tasks directly from Harmony Workflows using dedicated Entra workflow blocks - no need to switch between tools or trigger manual processes outside of Harmony.
Available workflow blocks
User management blocks:
Create Entra User - provision a new user in your Microsoft Entra directory as part of a workflow, useful for onboarding and provisioning automation
Get Entra User - retrieve an existing user's details from Entra to use in downstream workflow steps
Assign Entra Manager - set or update a user's manager in Entra, enabling automated org hierarchy management
Group ownership blocks:
Add Entra Group Owner - assign an owner to a Microsoft Entra group as part of onboarding or access management workflows
Remove Entra Group Owner - revoke group ownership during offboarding or access review workflows
These blocks connect seamlessly with other workflow actions, conditions, and triggers already available in Harmony.
Azure Management API support
The Entra request block in Harmony Workflows also supports Azure Management API endpoints, enabling richer integrations with Azure's management plane alongside existing Entra capabilities.
Reliable app access assignment
Harmony checks whether an Entra app has direct assignment configured before offering it as an access provisioning option in a workflow. If an app does not support direct assignment, that option is automatically blocked - preventing workflows from failing mid-execution. This means access request workflows for Entra apps only present assignment methods that are actually supported by the app's configuration.
AI Agent Support for Entra Account Status
Harmony's AI agent can handle account status and access issues for employees managed in Microsoft Entra ID. The agent intelligently distinguishes between different account states and guides employees or IT staff to the right next step:
Suspended accounts - the agent escalates to a human IT team member, since these require manual intervention
Locked accounts (Smart Lockout detected) - the agent recognizes when an Entra Smart Lockout has triggered and recommends a password reset to resolve the issue
Active accounts with login issues - the agent gathers more context to help diagnose the problem
This allows your team to resolve common Entra account issues faster through the AI agent without requiring manual triage for every request.
Troubleshooting
Best Practices
Need help? Contact support@harmony.io for assistance with your Microsoft Entra ID integration.
Data & Privacy
Last updated
Was this helpful?
