Integrate with Microsoft Entra ID to authenticate user access attempts and take action on risky account activity.
ImportantYou cannot configure single sign-on (SSO) from multiple IAMs. Ensure that you
configure the necessary permissions and SSO on the IAM you want to use for
Private Access and Internet Access authentication.
Operations Dashboard and
Zero Trust Secure Access both require data upload permission to
ensure certain features function properly. Revoking data upload permission may prevent
secure
access policy enforcement and risk analysis.
|
Procedure
- Go to .
- To take direct action on risky accounts and authenticate Private Access and
Internet Access rules, grant necessary permissions in the Third-Party Integration app.
- Click Grant permissions next to
Microsoft Entra ID.The Microsoft Entra ID screen opens in a new browser tab.
- Locate one or multiple Microsoft Entra ID tenants that you want to grant the "Read directory data and perform account management actions" permissions on, and then click Grant permissions in the Status column for Zero Trust Secure Access.
- Follow the onscreen instructions to enable the data connection.
- Switch back to the Zero Trust Secure Access browser tab.
- Configure your Microsoft Entra ID SSO settings.
- Click Grant permissions next to
Microsoft Entra ID.
- To configure risk control rules, you must also grant data upload permission for
Microsoft Entra ID in .
- Go to the Data Source panel in Operations Dashboard by clicking Data Source in the information that displays when you hover over in the Data upload permission status column.
- If the required Microsoft Entra ID permissions are not granted yet, click Manage permissions and integration settings in Third-Party Integration to open the Microsoft Entra ID screen of the Third-Party Integration app.
- Locate the Microsoft Entra ID tenants that you want to grant permissions on, and then click Grant permissions in the Status column for Attack Surface Risk Management.
- Switch back to the Microsoft Entra ID Data Source panel and turn on Data upload permission.
- Switch back to the Zero Trust Secure Access browser tab.
Note
Once you have configured Microsoft Entra ID as your data source, data begins syncing after 10 minutes. When the full sync is complete, Microsoft Entra ID syncs updates every 8 hours.