> For the complete documentation index, see [llms.txt](https://docs.p0.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.p0.dev/integrations/directory-integrations/microsoft-entra-id-legacy.md).

# Microsoft Entra ID (legacy)

{% hint style="info" %}
This page refers to an older version of our Microsoft Entra ID integration. For the latest setup guide and features, please visit the new integration page: [Microsoft Entra ID](/integrations/directory-integrations/microsoft-entra-id.md)
{% endhint %}

### Before you begin

Make sure you have the ability to grant application consent requests. This ability is granted by the Global Administrator role.

### Setting up Entra ID

1. Navigate to "Integrations" on [p0.app](https://p0.app), then select "Entra ID (Legacy)":

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-ce7e30eec95ea13c226ca110619702ab29f87987%2Fimage.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

2. Enter your directory's tenant ID, then click "Begin installation":

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-58700c4761bbc1aaecd5c9abaaf961bbb90582f8%2Fimage.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

3. Click "Install integration". This will take you to Microsoft's site and present you with a consent screen. Required permissions:

<div align="center"><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-caa25f391584d724f71cc7a47d14e283147d18cf%2FScreenshot%202025-09-12%20at%209.40.34%E2%80%AFAM.png?alt=media" alt=""></div>

4. Check all items, and click accept. After a moment, P0 will read your directory and display the number of connected groups.

{% hint style="danger" %}
If you do not grant all scopes to P0, the installation may succeed, but certain functionality will fail at a later time.
{% endhint %}

| Scope                              | Description                                |
| ---------------------------------- | ------------------------------------------ |
| AuditLog.Read.All                  | Read all audit log data                    |
| Group.Read.All                     | Read all groups                            |
| GroupMember.Read.All               | Read all group memberships                 |
| GroupMember.ReadWrite.All          | Read and write all group memberships       |
| Reports.Read.All                   | Read all usage reports                     |
| RoleManagement.ReadWrite.Directory | Read and write all directory RBAC settings |
| User.Read.All                      | Read all users' full profiles              |

### Configuring Entra ID

1. Select the directory field that contains each user's email address:

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-d348f8b948b69ff3be963e94a121dff00133ea49%2Fimage.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>
