Microsoft Entra ID integration guidelines
Action Audit uses a vendor-managed Microsoft Entra ID multi-tenant application.
The customer is not required to create a separate App Registration or provide client credentials.
Information required before activation
- Company name
- Primary Entra tenant domain
- Additional sign-in email/UPN domains (if any)
- Customer Entra administrator contact (for consent/approval)
- Action Audit administrator contact(s)
- Initial test users:
- one administrator
- one standard user
- Exact Microsoft sign-in address for each test user (for example:
[email protected])
Entra administrative access is typically needed only for the initial Microsoft application approval. Ongoing Action Audit user and structure administration can be handled by a business owner such as a Continuous Improvement Manager or Quality Manager, and IT administrator privileges are not required.
Email/UPN values must be exact and normalized. Hidden whitespace or copy/paste artifacts can break account matching.
Entra activation by customer
An adequately privileged customer Entra administrator should:
- Open Action Audit.
- Select Sign in with Entra ID.
- Complete Microsoft consent if prompted.
If Microsoft blocks sign-in or consent, the exact error message or screenshot should be captured and provided.
Provisioning and authorization behavior
When a new Entra user signs in and no account exists yet, Action Audit creates the user from Microsoft identity data (email, first name, last name).
For security, newly created users are assigned:
- Role: No permissions
- Organizational cell: Import
If the Import cell does not exist yet, Action Audit creates it on the first Entra sign-in. The Import cell can be customized in the Action Audit interface.
This enforces the rule: authentication confirms identity, but administrators control access.
Customer administration responsibilities
Customer administrators should:
- Review newly provisioned users
- Move users from Import to the correct organizational cell
- Assign the correct role
- Review blocked/inactive accounts
- Remove obsolete accounts when required
We recommend at least two customer administrators.
Sign-in policy and offboarding
Standard users should use Sign in with Entra ID.
Administrative accounts may keep a local recovery login depending on configuration; if enabled, local admin login requires Action Audit 2FA.
Removing a user in Entra does not automatically delete the Action Audit account. Access is blocked during authentication checks, and customer administrators can remove the account manually.
Initial validation checklist
Before broad rollout, validate with the two test users:
- Entra sign-in succeeds
- Required consent is completed
- Existing-user identity mapping is correct
- New user is created with No permissions in Import
- New user cannot access operational data before role/cell assignment
- Customer administrator can assign cell and role
- User can sign in again after assignment