Skip to main content

Overview

The Entra AD integration enables ThreatAware to collect read-only data from your Azure AD/Entra AD directory, providing comprehensive visibility into identity management, enterprise applications, and access control configurations.
Connection Method: OAuth Authorization Setup Time: 15 minutes Access Required: Global Administrator or Company Administrator account

Data collected

The Entra AD integration provides:
  • User and group directory information
  • Enterprise application registrations and configurations
  • Conditional access policies and security settings
  • Device enrollment and compliance status
  • Directory role and permission assignments

Use cases

Application Management

Monitor enterprise applications registered in Entra AD

Identity Governance

Track users, groups, and permission assignments

Security Policy Validation

Verify conditional access and security policies are properly configured

Compliance Assurance

Demonstrate compliance with identity management controls

Setup instructions

1

Log in to Azure AD Portal

Access the Azure AD Portal using an account with Global Administrator or Company Administrator permissions.
2

Review Enterprise Applications

Verify your Entra AD environment:
  • Navigate to Enterprise Applications in the Azure AD Portal
  • Check if ThreatAware Azure Connector is already registered (if upgrading from existing integration)
  • If not present, you will register it during the authorization process
3

Return to ThreatAware

In ThreatAware:
  • Navigate to Integrations and select Entra AD
  • Click the Authorize button to begin the integration process
4

Complete OAuth Authorization

Follow the authorization flow:
  • You will be redirected to Azure AD to confirm permissions
  • Log in using your Global Administrator or Company Administrator account
  • Review the permissions being requested by ThreatAware
  • Click Accept to authorise ThreatAware to access your Entra AD
  • You will be redirected back to ThreatAware after successful authorization
Only Global Administrators or Company Administrators can authorise this integration. Using other account types will result in authorization failure.
5

Verify Successful Integration

After authorization completes:
  • ThreatAware will notify you of successful integration
  • Check that ThreatAware Azure Connector now appears in your Enterprise Applications
  • The integration should automatically begin collecting data
6

Monitor Initial Data Sync

Allow time for data collection:
  • Wait 60 minutes for the first data synchronization cycle
  • Navigate to Integrations in ThreatAware to verify Active status
  • Confirm directory and application data is appearing in ThreatAware

Required permissions

Global Administrator or Company AdministratorOnly the following roles can authorise this integration:
  • Global Administrator: Full tenant-wide permissions
  • Company Administrator: Tenant-wide administrative access
These permissions are necessary to consent to application permissions on behalf of your organisation.
ThreatAware Azure Connector PermissionsAfter authorization, ThreatAware’s registered application will have the following permissions in Entra AD:
  • Read user profiles and directory information
  • Read group memberships and organisational structure
  • Read enterprise application information
  • Read conditional access policies
  • Read device and compliance information
You can review these permissions at any time in Enterprise Applications > ThreatAware Azure Connector.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Integrations in ThreatAware
    • Confirm Entra AD shows Active status
    • Check the last sync timestamp
  2. Verify in Azure Portal
    • Log in to the Azure AD Portal
    • Go to Enterprise Applications and search for ThreatAware Azure Connector
    • Verify the application is present and enabled
  3. Verify Data Collection
    • Wait up to 60 minutes for initial data synchronization
    • Search for known users or applications in ThreatAware
    • Verify the directory information matches your Entra AD environment
  4. Test Queries
    • Create test queries to filter users or applications from Entra AD
    • Verify identity management data is being collected correctly

Troubleshooting

Symptoms: Authorization page shows error or does not completeSolutions:
  • Confirm you are using a Global Administrator or Company Administrator account
  • Verify the account has not been restricted by conditional access policies
  • Check that the account is an owner or member (not a guest) in the tenant
  • Try authorization in a private/incognito browser window
  • Clear browser cookies and cache before retrying
  • Check if your organisation has disabled third-party application consent
Symptoms: Integration shows active but no directory data appearsSolutions:
  • Verify the admin account had appropriate permissions when authorising
  • In the Azure AD Portal, go to Enterprise Applications
  • Search for and select ThreatAware Azure Connector
  • Check that the application permissions are present and not restricted
  • Re-authorise the integration if permissions were recently modified
  • Review Azure AD Permissions Documentation for details
Symptoms: Integration fails to connect or times outSolutions:
  • Verify your network connectivity is stable and allows access to Azure
  • Check firewall rules allow HTTPS (443) traffic to Microsoft Graph API
  • Confirm Entra AD service is operational and not under maintenance
  • Try re-authorising the integration
  • Check if your region has specific cloud restrictions (government or sovereign cloud)
Symptoms: Integration shows active but no user or application data appearsSolutions:
  • Verify there are users and applications in Entra AD to collect
  • Check if the authorised admin account was recently disabled or removed
  • Review conditional access policies that might affect the integration
  • Verify the ThreatAware connector application hasn’t been removed from Enterprise Applications
  • Wait for the next sync cycle (typically hourly)
  • Review ThreatAware integration logs for error messages

Additional resources

Azure AD Portal

Access your Azure AD Portal

Azure AD Permissions Documentation

Official Azure AD documentation and permissions reference

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Authorization Best Practices
  • Use a dedicated Global Administrator account for authorization if possible
  • Document who authorised the integration and when it was authorised
  • Periodically review ThreatAware’s application permissions in Enterprise Applications
  • Monitor ThreatAware access in your Azure AD audit logs
  • Do not disable the admin account used for authorization after completing setup
Security Considerations
  • Verify ThreatAware’s permissions match the minimum required for your use case
  • Regularly audit ThreatAware’s data access in Azure AD activity logs
  • Monitor for unusual or unauthorized data access patterns
  • Use Azure AD conditional access policies to restrict ThreatAware access if needed
  • Follow your organisation’s least privilege principles for application permissions