Overview
The Entra AD integration enables ThreatAware to collect read-only data from your Azure AD/Entra AD directory, providing comprehensive visibility into identity management, enterprise applications, and access control configurations.Connection Method: OAuth Authorization
Setup Time: 15 minutes
Access Required: Global Administrator or Company Administrator account
Data collected
The Entra AD integration provides:- User and group directory information
- Enterprise application registrations and configurations
- Conditional access policies and security settings
- Device enrollment and compliance status
- Directory role and permission assignments
Use cases
Application Management
Monitor enterprise applications registered in Entra AD
Identity Governance
Track users, groups, and permission assignments
Security Policy Validation
Verify conditional access and security policies are properly configured
Compliance Assurance
Demonstrate compliance with identity management controls
Setup instructions
1
Log in to Azure AD Portal
Access the Azure AD Portal using an account with Global Administrator or Company Administrator permissions.
2
Review Enterprise Applications
Verify your Entra AD environment:
- Navigate to Enterprise Applications in the Azure AD Portal
- Check if ThreatAware Azure Connector is already registered (if upgrading from existing integration)
- If not present, you will register it during the authorization process
3
Return to ThreatAware
In ThreatAware:
- Navigate to Integrations and select Entra AD
- Click the Authorize button to begin the integration process
4
Complete OAuth Authorization
Follow the authorization flow:
- You will be redirected to Azure AD to confirm permissions
- Log in using your Global Administrator or Company Administrator account
- Review the permissions being requested by ThreatAware
- Click Accept to authorise ThreatAware to access your Entra AD
- You will be redirected back to ThreatAware after successful authorization
5
Verify Successful Integration
After authorization completes:
- ThreatAware will notify you of successful integration
- Check that ThreatAware Azure Connector now appears in your Enterprise Applications
- The integration should automatically begin collecting data
6
Monitor Initial Data Sync
Allow time for data collection:
- Wait 60 minutes for the first data synchronization cycle
- Navigate to Integrations in ThreatAware to verify Active status
- Confirm directory and application data is appearing in ThreatAware
Required permissions
Administrator Account Requirements
Administrator Account Requirements
Global Administrator or Company AdministratorOnly the following roles can authorise this integration:
- Global Administrator: Full tenant-wide permissions
- Company Administrator: Tenant-wide administrative access
Application Permissions
Application Permissions
ThreatAware Azure Connector PermissionsAfter authorization, ThreatAware’s registered application will have the following permissions in Entra AD:
- Read user profiles and directory information
- Read group memberships and organisational structure
- Read enterprise application information
- Read conditional access policies
- Read device and compliance information
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Integrations in ThreatAware
- Confirm Entra AD shows Active status
- Check the last sync timestamp
-
Verify in Azure Portal
- Log in to the Azure AD Portal
- Go to Enterprise Applications and search for ThreatAware Azure Connector
- Verify the application is present and enabled
-
Verify Data Collection
- Wait up to 60 minutes for initial data synchronization
- Search for known users or applications in ThreatAware
- Verify the directory information matches your Entra AD environment
-
Test Queries
- Create test queries to filter users or applications from Entra AD
- Verify identity management data is being collected correctly
Troubleshooting
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify your network connectivity is stable and allows access to Azure
- Check firewall rules allow HTTPS (443) traffic to Microsoft Graph API
- Confirm Entra AD service is operational and not under maintenance
- Try re-authorising the integration
- Check if your region has specific cloud restrictions (government or sovereign cloud)
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no user or application data appearsSolutions:
- Verify there are users and applications in Entra AD to collect
- Check if the authorised admin account was recently disabled or removed
- Review conditional access policies that might affect the integration
- Verify the ThreatAware connector application hasn’t been removed from Enterprise Applications
- Wait for the next sync cycle (typically hourly)
- Review ThreatAware integration logs for error messages
Additional resources
Azure AD Portal
Access your Azure AD Portal
Azure AD Permissions Documentation
Official Azure AD documentation and permissions reference
ThreatAware Support
Contact ThreatAware support for integration assistance