.ai
All integrations

Available integration

Microsoft Entra ID

Collects account security, access policy, administrator, and activity evidence from Microsoft Entra ID.

AvailableRead-only collection

What vCISO.ai observes

  • Conditional Access and security defaults
  • MFA registration report
  • User security inventory
  • Active administrator assignments
  • Sign-in and directory audit activity

Authorization and permissions

Microsoft Entra delegated OAuth

  • User.Read.All
  • AuditLog.Read.All
  • Policy.Read.All
  • RoleManagement.Read.Directory
  • openid, profile, and offline_access for the authorized connection

Setup path

Setup remains administrator-controlled inside the authenticated workspace.

  1. Authorize the Entra organization
  2. Grant the listed read permissions
  3. Complete the first read-only directory collection
  4. Review the checks and proposed evidence

Collection limitations

A limited or failed read stays visible and never becomes a passing result.

  • Collection reflects only data exposed by the granted tenant permissions
  • Directory pagination and activity windows follow supported collection limits
  • Permission-limited reads remain visibly incomplete

Disconnect and deletion behavior

An administrator can disconnect the integration. Stored access and refresh tokens are removed locally and connector-derived evidence is expired. Provider-side revocation depends on Microsoft account controls.

  • Existing historical records remain available as review history
  • Connector-derived evidence is marked expired when the source is disconnected
  • Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Microsoft Entra ID does not automatically verify a control, complete a framework, or produce an audit conclusion.

Start with the roadmap

Put Microsoft Entra ID into a prioritized readiness plan.

Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.