Skip to content
Technical documentationMicrosoft Entra ID integration guidelines

Microsoft Entra ID integration guidelines

Action Audit uses a vendor-managed Microsoft Entra ID multi-tenant application.

The customer is not required to create a separate App Registration or provide client credentials.

Information required before activation

  • Company name
  • Primary Entra tenant domain
  • Additional sign-in email/UPN domains (if any)
  • Customer Entra administrator contact (for consent/approval)
  • Action Audit administrator contact(s)
  • Initial test users:
    • one administrator
    • one standard user
  • Exact Microsoft sign-in address for each test user (for example: [email protected])

Entra administrative access is typically needed only for the initial Microsoft application approval. Ongoing Action Audit user and structure administration can be handled by a business owner such as a Continuous Improvement Manager or Quality Manager, and IT administrator privileges are not required.

⚠️

Email/UPN values must be exact and normalized. Hidden whitespace or copy/paste artifacts can break account matching.

Entra activation by customer

An adequately privileged customer Entra administrator should:

  1. Open Action Audit.
  2. Select Sign in with Entra ID.
  3. Complete Microsoft consent if prompted.

If Microsoft blocks sign-in or consent, the exact error message or screenshot should be captured and provided.

Provisioning and authorization behavior

When a new Entra user signs in and no account exists yet, Action Audit creates the user from Microsoft identity data (email, first name, last name).

For security, newly created users are assigned:

  • Role: No permissions
  • Organizational cell: Import

If the Import cell does not exist yet, Action Audit creates it on the first Entra sign-in. The Import cell can be customized in the Action Audit interface.

This enforces the rule: authentication confirms identity, but administrators control access.

Customer administration responsibilities

Customer administrators should:

  • Review newly provisioned users
  • Move users from Import to the correct organizational cell
  • Assign the correct role
  • Review blocked/inactive accounts
  • Remove obsolete accounts when required

We recommend at least two customer administrators.

Sign-in policy and offboarding

Standard users should use Sign in with Entra ID.

Administrative accounts may keep a local recovery login depending on configuration; if enabled, local admin login requires Action Audit 2FA.

Removing a user in Entra does not automatically delete the Action Audit account. Access is blocked during authentication checks, and customer administrators can remove the account manually.

Initial validation checklist

Before broad rollout, validate with the two test users:

  • Entra sign-in succeeds
  • Required consent is completed
  • Existing-user identity mapping is correct
  • New user is created with No permissions in Import
  • New user cannot access operational data before role/cell assignment
  • Customer administrator can assign cell and role
  • User can sign in again after assignment