> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Entra ID Directory

> This guide outlines the necessary configurations to successfully integrate your Microsoft Entra ID directory with the TruU platform. By establishing this connection, your organization can synchronize user data and maintain consistent identity management across both environments.

Before beginning, ensure that you have:

1. Administrative permissions for both the Microsoft Entra admin center and the TruU Admin Console
2. Both portals open in separate browser tabs to facilitate the transfer of credentials.

### Microsoft Entra ID Configuration

1. Navigate to your Microsoft Entra ID admin center and select the **App Registrations** tab under the *Applications* drop down menu

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/6be32041-ad81-4ea6-881b-259c55242577.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=d5c6ae4998800a0020bc38312b25510b" alt="" width="1919" height="940" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/6be32041-ad81-4ea6-881b-259c55242577.png" />

2. Go to **New Registration**

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/75488f2d-b45e-43ed-95fa-eb5144cfe1d1.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=caf9ee85ac925eafb82866d2d9806dda" alt="" width="1919" height="940" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/75488f2d-b45e-43ed-95fa-eb5144cfe1d1.png" />

3. Set the user-facing display *TruU* and click **Register** at the bottom when done. Note: This can be changed later.

<img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/9280f63ac9442ea155688123c51fae8b10cd8579a4367bf979a824d10422e768-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=58a7b74e7e79242a4d77133d27b74a47" alt="" width="796" height="391" data-path="images/docs/9280f63ac9442ea155688123c51fae8b10cd8579a4367bf979a824d10422e768-image.png" />

4. Now, navigate back to the Entra ID Admin page and select **API permissions**

<img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/b7bcd60-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=af3ee789e91fd37ae4a391f9ae865f04" alt="" width="1915" height="942" data-path="images/docs/b7bcd60-image.png" />

5. Next, select **Add a permission** and choose **Microsoft Graph**

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/5e398de5-6c6c-4f83-85b5-65b262dc1c3f.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=75fac5e3db3abc6ce94f68a022a2a7ef" alt="" width="1915" height="942" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/5e398de5-6c6c-4f83-85b5-65b262dc1c3f.png" />

6. Select **Application Permissions**

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/fe4c9af3-b8b1-4624-b59a-bc440295a508.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=1630899f0a8401067bc37330677d4a71" alt="" width="1915" height="942" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/fe4c9af3-b8b1-4624-b59a-bc440295a508.png" />

7. Select Application permissions and grant admin consent for the following specific requirements:

* **Device.Read.All**
* **Group.Read.All**
* **Directory.Read.All**
* **User.Read** (User.Read is enabled by default, as **Delegated** , ensure admin consent is granted. If missing, add with Delegated permission.)
* **User.Read.All**
* **UserAuthenticationMethod.Read.All**
* **Application.Read.All**
* **User.AuthenticationMethod.ReadWrite.All.**\*

<Warning>
  Please ensure all Permissions Names, Types, and Status match the following screenshot.
</Warning>

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/240927fd78ebe8be6fb8c68d64a10c37807c9e6d0056e863b7b8f52cf6178818-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=22e93baa89a541efe4e4cb30c4a5f080" alt="" width="1085" height="534" data-path="images/docs/240927fd78ebe8be6fb8c68d64a10c37807c9e6d0056e863b7b8f52cf6178818-image.png" />

8. Navigate to **Certificates & secrets**, select **New client secret**, and enter "TruU" as the description. Set the expiration to your preference; a 12-month duration is recommended.

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/285728a7cecac0f97a8e7980c48e84d24f3374bec9de77a119ea096e0eaef821-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=c8cf171d333b13e4adb4c40a6eb2f3c3" alt="" width="1816" height="889" data-path="images/docs/285728a7cecac0f97a8e7980c48e84d24f3374bec9de77a119ea096e0eaef821-image.png" />

9. After adding the secret, immediately copy the entry in the **Value** column and save it. This value is required for the integration in the TruU Admin Console and will not be accessible again once you leave the page.

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/1f5a5717-9f22-4938-ac69-ba4e1635309c.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=a02250eb541f201064f21ae9b0b6a9a9" alt="" width="1919" height="940" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/1f5a5717-9f22-4938-ac69-ba4e1635309c.png" />

### TruU Admin Console Configuration

1. In the TruU Admin console, go to *Directory*

<img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/aff9d9f0f04f2b84dd6bf9f324e328df2423a08b4a781917ce389ba39d9f504a-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=10199086a5fe61a1814d06064a46f79b" alt="" width="191" height="279" data-path="images/docs/aff9d9f0f04f2b84dd6bf9f324e328df2423a08b4a781917ce389ba39d9f504a-image.png" />

2. On the top left, click the blue '+' option to add a directory.

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/3824e5a98488694f91364dad99657581af675743b97eb7905e76f9f6986eb2fe-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=7185d8116bed00f9f05bd59ffe54eb2f" alt="" width="783" height="121" data-path="images/docs/3824e5a98488694f91364dad99657581af675743b97eb7905e76f9f6986eb2fe-image.png" />

3. Navigate to the drop-down menu and select **Entra ID**.

<img src="https://mintcdn.com/truu-2/m22YLP0oXSNG0U3O/images/docs/8627c114521c6357366074d773be3e8ec85ab6860544c27e1ea9b669238ebb39-image.png?fit=max&auto=format&n=m22YLP0oXSNG0U3O&q=85&s=74915f4f76ca1169bca3914ad81111c9" alt="" width="601" height="691" data-path="images/docs/8627c114521c6357366074d773be3e8ec85ab6860544c27e1ea9b669238ebb39-image.png" />

4. Set a Configuration Name along with the domain name (your Entra ID domain) of the directory that you will be integrating

<img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/c32101ac51f9984aedc72085ef44679eaa8eb2ad12adabafcfa4a7783f73f0a7-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=7d3114a49cfb35e825ee50f38a379cc5" alt="" width="584" height="665" data-path="images/docs/c32101ac51f9984aedc72085ef44679eaa8eb2ad12adabafcfa4a7783f73f0a7-image.png" />

5. Select if all your users have UPN suffixes that end with the domain name

<img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/4c936f50d30410db9c7832c7371b0c8b4ece09d49dbfb4bb4d1523222cca43e1-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=f87b36807be0880ff6113155542a6071" alt="" width="584" height="665" data-path="images/docs/4c936f50d30410db9c7832c7371b0c8b4ece09d49dbfb4bb4d1523222cca43e1-image.png" />

6. Go back to the Entra ID Admin Center and locate the Application (client) ID and the Directory (tenant) ID on the application's overview page. Copy and paste the:

* Directory(Tenant ID)
* Application Client ID
* Application Client Secret Value (copied and saved from Step 9)

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/6f1055b3-bda0-4373-aee9-343ef41a0f3e.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=57d70b286af62610657777e2bcb5ed4b" alt="" width="1919" height="940" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/6f1055b3-bda0-4373-aee9-343ef41a0f3e.png" />

<img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/cf3330c7668a83435d43231bbc679d6e1af3ae6c74dba798eb6891dc881c8404-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=01bb0f1f4795483c8589a5a2fe3774bd" alt="" width="584" height="665" data-path="images/docs/cf3330c7668a83435d43231bbc679d6e1af3ae6c74dba798eb6891dc881c8404-image.png" />

7. Choose True or False to determine if the system should automatically unenroll or remove devices based on user status changes in the directory, then click Save

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/8b206ea8-8483-4906-ad20-3147cb7563b8.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=ddd2d805d8c1c421df1a6ff4c45a4d63" alt="" width="1916" height="942" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/8b206ea8-8483-4906-ad20-3147cb7563b8.png" />

8. You will be prompted with the following pop-up, which will redirect you to the *Global Attributes* Tab. Select **Go Now**

<img src="https://mintcdn.com/truu-2/jJ0QGEHfTe0CfrEY/images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/8753384f-ac7b-495f-bc6a-e45160dbf04f.png?fit=max&auto=format&n=jJ0QGEHfTe0CfrEY&q=85&s=ed75f3959872d1417e5389bfc7dddae8" alt="" width="1916" height="942" data-path="images/docs/a8cfe83b-31f5-4a65-a045-f9a5073b0415/c86baeb9-9952-4d56-a9f2-607ab56d8048/de50b27f-4bd4-43fb-a188-527eff868b73/images/8753384f-ac7b-495f-bc6a-e45160dbf04f.png" />

9. Click on the **Gear icon** on the top right. Select your **Primary User Identifier** (typically "mail") to be used for lookups and diagnostics, then click Save.

<img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/b2baea2-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=c66f21f2c7f98081c1d8cdade13e4bc7" alt="" width="1600" height="738" data-path="images/docs/b2baea2-image.png" />

10. Navigate to **"Identity Servers"**> **Cluster**. Under Directory Connection, select your directory and Click Save.

<img src="https://mintcdn.com/truu-2/0zTsJHKKI2cGP3Gv/images/docs/f830e5f-image.png?fit=max&auto=format&n=0zTsJHKKI2cGP3Gv&q=85&s=c087dbfe2af4122a8e4bc0361867bda8" alt="" width="1600" height="806" data-path="images/docs/f830e5f-image.png" />

**Verification:**

Allow the system 2–3 minutes to run diagnostics. Once the status displays as "Healthy," the integration is complete

<img src="https://mintcdn.com/truu-2/rjjBxA7Z_Wk_-34G/images/docs/ee85be0-image.png?fit=max&auto=format&n=rjjBxA7Z_Wk_-34G&q=85&s=5111020f9ff8f6a261f3a502671d303d" alt="" width="1588" height="736" data-path="images/docs/ee85be0-image.png" />

[Configure User Source Directory Overview](/docs/configure-user-source-directory-overview)

[Entra ID Configuration Automation](/docs/entra-id-configuration-automation)
