Microsoft Entra ID
The Microsoft Entra ID block manages users and groups in Microsoft Entra ID (formerly Azure Active Directory) from your workflow — create accounts, manage group memberships, and query your directory automatically.
Identity Automation: Automate onboarding and offboarding — when HR approves a new hire, create their account, set a temporary password, and add them to the right department group in one run.
Microsoft Entra ID is not available on the Free plan. Upgrade your workspace plan to use this block.
Key Features
- User Management: Create, get, update, and delete user accounts
- Group Management: Create, get, update, and delete Microsoft 365 (
Unified) orSecuritygroups - Membership Control: Add and remove users from groups
- Directory Queries: List users or groups with an OData filter and a result limit
- Response Mapping: Save IDs, names, and results into workflow variables
Operations
Group operations
| Operation | Main fields |
|---|---|
| Create Group | Display name, mail nickname, group type (Unified / Security), description, visibility (Public / Private / HiddenMembership) |
| Get Group | Group ID |
| Get Many Groups | Max results (1–999, default 50), OData filter |
| Update Group | Group ID + fields to change (name, description, mail nickname, visibility) |
| Delete Group | Group ID |
User operations
| Operation | Main fields |
|---|---|
| Create User | Display name, user principal name (e.g. jane@yourorg.com), mail nickname, password, force password change on first sign-in (default on), job title, department, mobile phone, office location |
| Get User | User ID |
| Get Many Users | Max results (1–999, default 50), OData filter |
| Update User | User ID + fields to change (display name, job title, department, phone, office location) |
| Delete User | User ID |
Membership operations
| Operation | Main fields |
|---|---|
| Add User to Group | User ID, Group ID |
| Remove User from Group | User ID, Group ID |
Configuration
| Parameter | Type | Required | Description |
|---|---|---|---|
| Microsoft account | Credential | Yes | A connected account with directory admin rights |
| Action | Select | Yes | One of the 12 operations above |
| Action fields | Varies | Per action | Each action shows only its own fields; all accept variables |
| Response mapping | Value → Variable | No | Save response values into workflow variables |
The filter field on Get Many Users / Get Many Groups takes an OData expression, e.g. startswith(displayName,'Sales').
Setting up the credential
- In the block settings, click Continue with Microsoft.
- Sign in with a Microsoft 365 account that has directory admin privileges.
- Approve the requested directory permissions (user and group read/write).
- The credential is created automatically and appears in the dropdown.
Directory write scopes are high-privilege. Your Microsoft 365 administrator may need to grant consent for the organization before the connection succeeds.
Example: new-hire onboarding
- A Webhook Trigger receives the new hire's details from your HR system.
- An Entra ID block with Create User creates
{{first}}.{{last}}@yourorg.comwith a temporary password and "force change" enabled, mapping Id to a variable. - A second Entra ID block with Add User to Group puts the new user into the department's group.
- A Send Email block mails the manager a confirmation.
Output
Use Response mapping to extract values into variables:
| Value | Description |
|---|---|
Id | The created or fetched object's ID |
Display Name | The user's or group's display name |
Email | The user's email / UPN |
Mail Nickname | The mail nickname |
Users / Groups | The result arrays for Get Many operations |
Count | How many objects were returned |
Success | Whether the operation succeeded |
Full Data | The complete raw API response |