# Integrate CapaOne with Entra ID

> Register an application in Microsoft Entra ID and connect it to CapaOne so your directory users and groups sync.

Source: https://docs.capaone.com/capaone/integrations/integrate-capaone-with-entra-id/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

1. Navigate to <https://portal.azure.com/#home>

2. Click Microsoft Entra ID

![Azure portal home with Microsoft Entra ID highlighted](/attachments/capaone/53bb0ee3-780b-46b1-b180-4419edcba8c6.png)

3. Click App registrations

![Microsoft Entra ID overview with App registrations in the sidebar](/attachments/capaone/42044dfd-3fa1-4890-b58b-f4d117faecc1.png)

4. Click New registration

![App registrations page with the New registration button](/attachments/capaone/728e729d-caa2-4700-b59f-46587ff5eebb.png)

5. Provide a name and select what organizational directory should be synced and click Register at the bottom of the page

![Register an application form with name and supported account types](/attachments/capaone/06d6c472-77e1-4afc-8788-c526ad8fc401.png)

6. Click on Add a certificate or secret

![App registration overview with the Add a certificate or secret link](/attachments/capaone/533cb575-9894-4f91-b214-292646ef2791.png)

7. Click on New client secret

![Certificates and secrets page with the New client secret button](/attachments/capaone/24029d44-1d40-4eba-a454-57506e619118.png)

8. Provide a description (not required) and set an expiration date. We suggest setting it to 24 months. Afterwards click Add at the bottom of the page

![Add a client secret panel with description and a 24-month expiry](/attachments/capaone/debba9db-cc49-430d-8c4f-b6214a3c9761.png)

9. After the client secret is created you need to copy the value and save it in a notepad. If you refresh or leave the page you will have to create a new client secret

![Client secret Value and Secret ID columns ready to copy](/attachments/capaone/58c381bf-b9cc-4db9-ac46-dac66fcaff8a.png)

10.   Click on API permissions in the sidebar and then Add a permission

![App registration sidebar with API permissions and the Add a permission button](/attachments/capaone/385f97a5-70fe-484b-ad72-528979fdb118.png)

11.   Select Microsoft Graph

![Request API permissions panel with Microsoft Graph selected](/attachments/capaone/8972002a-7a0e-4b26-8dfa-351ba50ba44a.png)

12.   Select Application permissions

![Microsoft Graph permission type with Application permissions selected](/attachments/capaone/3e11a9bb-7a69-448e-aa18-8a588a1a87cd.png)

13.   Scroll down and expand Group and set a checkmark in Group.Read.All and then Add permissions at the bottom of the page

![Group permissions expanded with Group.Read.All checked](/attachments/capaone/eb66da90-6498-4007-a046-2e6e225c1876.png)

14.   Go through the same permission steps and set a checkmark in User for User.Read.All and Add permissions

![User permissions expanded with User.Read.All checked](/attachments/capaone/f0e6e71f-4b61-447f-94fd-8a39dd79328f.png)

15.   Go through the same permission steps and set a checkmark in GroupMember for GroupMember.Read.All and Add permissions

![GroupMember permissions expanded with GroupMember.Read.All checked](/attachments/capaone/753d40e9-fda4-4b84-931f-bfcfca6748f8.png)

16.   Click on Grant admin consent for (name of directory)

![API permissions list with the Grant admin consent button](/attachments/capaone/bf85a3ef-6485-4673-a14d-25c16d3ad4b6.png)

17.   Click Yes to the popup

![Grant admin consent confirmation dialog](/attachments/capaone/64d6d118-bdf6-4ab9-a1f1-e06087b2090b.png)

18.   Click on Home in the upper left corner

![Azure portal with the Home link in the upper left corner](/attachments/capaone/74f02595-9314-4f97-bc56-76755f5fe768.png)

19.   Click on Microsoft Entra ID

![Azure portal home with Microsoft Entra ID](/attachments/capaone/8e205352-ef6e-442b-9658-01a4984653e8.png)

20.   Click on App registrations in the left pane

![Microsoft Entra ID with App registrations in the left pane](/attachments/capaone/41fab2c3-b631-444e-82ec-35f66d866718.png)

21.   Copy the Application client ID to your notepad

![App registration overview showing the Application (client) ID](/attachments/capaone/e3e22ded-1301-4c4d-8b17-3499318ad0f1.png)

22.   Click on Properties in the left pane

![App registration sidebar with Properties selected](/attachments/capaone/c72784be-9f88-4290-be84-b4d98deb2618.png)

23.   Copy the tenant ID to your notepad

![Entra ID Properties page showing the Tenant ID](/attachments/capaone/0da6ac0b-064c-46cd-b466-e8840419fd9e.png)

24.   Go to the CapaOne Management portal and select integrations in the left pane

![CapaOne management portal with Integrations in the left pane](/attachments/capaone/42755de8-43d7-4593-a084-38c247e6ff94.png)

25.   Click on New to create a new integration

![CapaOne Integrations page with the New button](/attachments/capaone/beb59c72-bc2d-437d-9ab6-a0ebefc32c24.png)

26.   Provide the following information for the new Entra ID integration

Name

Application Client ID

Tenant ID

Client secret value

(In your notepad you should have Tenant ID, Application ID and Client Value)

Then select a synchronization schedule and click on Create

![New Entra ID integration form with name, client ID, tenant ID, and client secret](/attachments/capaone/08606a71-d06e-4f65-bd5d-1d3b7c707118.png)

27.   If you click on the 3 dots to the right of the newly created integration you can do the following

- Edit
- Sync now
- View integration
- Delete

![Integration action menu with Edit, Sync now, View integration, and Delete](/attachments/capaone/4a0f5397-6bce-4ddc-b194-ee8e1b37eaaf.png)

28.   Click on Sync now

![Integration action menu with Sync now selected](/attachments/capaone/9838d46a-6ebf-4c03-b040-a72b85f14bb0.png)

29.   When the sync is done, click on Users in the left pane and the users from the Entra ID will have a Entra icon to the left of their name

![CapaOne Users list showing an Entra icon beside each synced user](/attachments/capaone/c76dc7cd-689a-45ec-8aad-a203091a2350.png)
