Using API-Based Integration with Entra ID
This feature is currently available only to customers participating in a private preview. If you'd like to participate to be among the first to try this feature, ask our support or account team for details.
This documentation provides a detailed guide for integrating Entra ID with the Delinea Platform. The integration enables the Delinea Platform to use Microsoft APIs directly to access your Entra ID users and groups.
Instead of using Entra ID as a Registered App (native integration) as described in this topic, you can use an Integrating Entra ID. But you cannot use both features simultaneously with the same domains. If your Delinea Platform has an existing Entra ID federation configuration, adding a new native Entra ID-registered app with the same domains will not succeed.
The integration supports the following:
-
Log-in and authentication using Entra ID credentials.
-
Browsing and searching for Entra ID users and security groups. Distribution lists (groups) are not supported.
-
Direct use of Entra ID groups on the platform without mapping them to platform groups.
-
Pre-assignment of Entra ID users to groups, roles, identity policies, and sharing secrets.
-
Inviting/adding Entra ID users directly to the platform.
This topic walks you through the following steps to set up Entra ID on the Delinea Platform:
-
Registering an App in Azure:
-
Generating a Client Secret: Create a client secret, copy its value, and note the expiration date.
-
Configuring Token Claims: Add the required claims for the Platform.
-
Setting API Permissions: Assign the necessary Microsoft Graph permissions and grant admin consent.
-
-
Registering an App on the Delinea Platform: Enter the app credentials, permissions and domains.
-
Testing Integration: Verify the integration by logging into the Platform with an Entra ID user.
The following procedures require copying and pasting information between Azure Portal and the Delinea Platform. We recommend opening both applications before you begin and keeping both open until you are finished.
Prerequisites
-
On the Delinea Platform, you must be a Platform Admin.
-
In Azure, you must be able to create an app registration and manage API permissions. Roles that satisfy these requirements are:
-
Global Administrator
-
Privileged Role Administrator
-
Create an Azure Application Registration
-
Go to the Azure portal and log in.
-
Select (or search for) App registrations.
-
Click New registration.
-
In the Name field, enter a name for your application registration. (Under Supported account types, only Single tenant is supported).
-
Click Register. The application registration's overview page opens.
-
From the left navigation menu, under Manage, click Certificate & secrets.
-
Click New client secret to create a secret for authenticating to this Entra ID tenant with this application registration.
-
(Optional): Complete the Description field for the new client secret.
-
Update the Expires field to set the credentials expiration date.
-
Click Add.
-
Copy and save the Client secret's Value and its Expiration date because you will need them later when configuring the Delinea Platform. If you leave this page without saving the information, you may lose access the client secret Value and you will need to generate a new secret.
-
From the left navigation menu, click Token configuration.
-
Click Add optional claim.
-
In the Add optional claim dialog, select ID under Token type.
-
Select the following claims:
-
email
-
upn
-
-
Click Add.
-
In the dialog box that opens, select Turn on the Microsoft Graph email, profile permission (required for claims to appear in token).
-
Click Add. This will add the optional claims to the app registration token.
-
From the left navigation menu, click API Permissions. API Permissions include all permissions required for the platform.
-
These three permissions will be on the Configured permissions list:
-
Click Add a permission.
-
Click Microsoft Graph.
-
Click Application permissions and select the following:
-
AuditLog.Read.All
-
Group.Read.All
-
GroupMember.Read.All
-
Member.Read.Hidden
-
User.Read.All
-
-
Click Add permissions.
-
Click Grant admin consent for <azure directory name> for the API permissions you just added.
-
In the Grant admin consent confirmation dialog, click Yes.
You are now ready to create a registered app on the Delinea Platform in the next section.
Create a Registered App on the Delinea Platform
-
On the Delinea Platform, navigate to Settings > Registered apps.
-
Click Add. The Add registered app page opens.
-
Complete the following fields:
Delinea Platform field name | Description | Location in Azure App |
---|---|---|
Name | A unique identifier for the registered app in the Delinea Platform. | User-defined; choose a descriptive name when configuring in Delinea Platform. |
Description | Optional field to add details or context about the registered app. | User-defined; optional entry in Delinea Platform. |
Directory (tenant) ID | The unique identifier for your Azure AD tenant. | Found on the Azure App Registration → Overview page under "Directory (tenant) ID". |
Application (client) ID | The unique identifier for the Azure app being registered. | Found on the Azure App Registration → Overview page under "Application (client) ID". |
Client Secret Value | The value of the client secret generated for the app, used for authentication. | Generated in Azure App Registration → Certificates & Secrets. Copy the value immediately when creating the client secret. |
Credential Expiration Date | The expiration date of the client secret used for authentication. | Found in Azure App Registration → Certificates & Secrets under "Expires". Match this value in Delinea Platform. |
4. Select all of the following settings:
Delinea Platform field name | Description |
---|---|
State | Indicates whether the integration is active. Ensure this is set to Enabled to allow seamless operation |
Entra ID - Read | Grants the platform the ability to query Entra ID users and groups. This permission is Azure tenant-wide and can only be granted once per platform tenant. |
Log-in to Entra ID | Allows the creation of a Federation Provider within the Delinea Platform. This enables users to log in to the Delinea Platform using their Entra ID credentials. If needed, you can create multiple registered apps with Log-in permissions, each associated with a unique domain. When this option is selected, specifying the domains becomes mandatory. |
Provision Directory Services |
This setting is required when creating the registered app to ensure that the directory service and federation provider settings are created. This setting will be deprecated in future releases. |
5. Domain Names: Add at least one domain, including the primary domain for your Microsoft Entra organization and any custom domains your users will use to log in.
6. Click Save.
Once the registered app is saved, the platform generates an OIDC federation configuration that can be viewed under Settings > Federation Providers, which gives Directory Services access to the Entra ID directory. To enable user login with Entra ID credentials, add the Platform Callback URL to the Azure app registration as described in the next section.
Update the Azure App Registration with the Platform Callback URL
Add the Platform Callback URL from the generated Federation configuration to the Azure app registration. The URL will be generated after you save the registered app.
-
On the Delinea Platform, navigate to Settings > Registered apps.
-
Select the registered app.
-
Copy the Platform Callback URL.
-
Navigate to the Azure portal.
-
From the app registration Overview page, select Redirect URIs and click Add a Redirect URL.
-
In the Platform configurations section, click Add a platform.
-
Select Web.
-
In the Redirect URIs field, enter the Platform callback URL that you copied and saved.
-
Click Configure.
The Delinea Platform is now fully integrated with Entra ID, enabling a seamless, streamlined user management experience. You can now browse Entra ID users and groups directly on the platform, pre-assign permissions, add users instantly, and allow users to log in with their Entra ID credentials.
Automating Entra ID Integration Setup
You may streamline the Entra ID provisioning process by leveraging the automation script available in the Delinea XPM GitHub repository. This script provides a simple and repeatable setup experience by automating the creation of the necessary Azure and Delinea Platform application objects. For more details and usage instructions, refer to the Entra ID App Registration Automation Script repository.
Test the API-based Entra ID Integration
Create a test user in the Azure Portal and use the account to verify user login to the Delinea Platform.
-
Go to the Azure portal and log in.
-
Select or search for Users.
-
Click New user > Create new user.
-
Add the following:
-
User principal name
-
Display name
-
-
Copy the generated Password because you will need it to log on to the Delinea Platform.
-
Click Next > Properties.
-
Add Email.
-
Click Review + create.
-
Click Create.
Test User Log-on to the Delinea Platform
-
On the Delinea Platform, navigate to Settings > Federation providers.
-
Select the generated OIDC federation configuration.
-
Select Federation console.
-
Click Start Debug Log.
-
From a private browser window, navigate to your tenant and log on with the test user credentials.
The test user should be able to log on to the platform. If the user cannot log on, the Debug Log can help diagnose and resolve issues by capturing detailed information about the communication between the Platform and the Identity Provider (IdP). It provides insights into federation messages, claims, and potential misconfigurations, making it easier to pinpoint errors or inconsistencies in the authentication process.