Workflows
Blocks
Integrations
Microsoft Entra ID

Microsoft Entra ID

The Microsoft Entra ID block manages users and groups in Microsoft Entra ID (formerly Azure Active Directory) from your workflow — create accounts, manage group memberships, and query your directory automatically.

Identity Automation: Automate onboarding and offboarding — when HR approves a new hire, create their account, set a temporary password, and add them to the right department group in one run.

⚠️

Microsoft Entra ID is not available on the Free plan. Upgrade your workspace plan to use this block.

Key Features

  • User Management: Create, get, update, and delete user accounts
  • Group Management: Create, get, update, and delete Microsoft 365 (Unified) or Security groups
  • Membership Control: Add and remove users from groups
  • Directory Queries: List users or groups with an OData filter and a result limit
  • Response Mapping: Save IDs, names, and results into workflow variables

Operations

Group operations

OperationMain fields
Create GroupDisplay name, mail nickname, group type (Unified / Security), description, visibility (Public / Private / HiddenMembership)
Get GroupGroup ID
Get Many GroupsMax results (1–999, default 50), OData filter
Update GroupGroup ID + fields to change (name, description, mail nickname, visibility)
Delete GroupGroup ID

User operations

OperationMain fields
Create UserDisplay name, user principal name (e.g. jane@yourorg.com), mail nickname, password, force password change on first sign-in (default on), job title, department, mobile phone, office location
Get UserUser ID
Get Many UsersMax results (1–999, default 50), OData filter
Update UserUser ID + fields to change (display name, job title, department, phone, office location)
Delete UserUser ID

Membership operations

OperationMain fields
Add User to GroupUser ID, Group ID
Remove User from GroupUser ID, Group ID

Configuration

ParameterTypeRequiredDescription
Microsoft accountCredentialYesA connected account with directory admin rights
ActionSelectYesOne of the 12 operations above
Action fieldsVariesPer actionEach action shows only its own fields; all accept variables
Response mappingValue → VariableNoSave response values into workflow variables

The filter field on Get Many Users / Get Many Groups takes an OData expression, e.g. startswith(displayName,'Sales').


Setting up the credential

  1. In the block settings, click Continue with Microsoft.
  2. Sign in with a Microsoft 365 account that has directory admin privileges.
  3. Approve the requested directory permissions (user and group read/write).
  4. The credential is created automatically and appears in the dropdown.
⚠️

Directory write scopes are high-privilege. Your Microsoft 365 administrator may need to grant consent for the organization before the connection succeeds.


Example: new-hire onboarding

  1. A Webhook Trigger receives the new hire's details from your HR system.
  2. An Entra ID block with Create User creates {{first}}.{{last}}@yourorg.com with a temporary password and "force change" enabled, mapping Id to a variable.
  3. A second Entra ID block with Add User to Group puts the new user into the department's group.
  4. A Send Email block mails the manager a confirmation.

Output

Use Response mapping to extract values into variables:

ValueDescription
IdThe created or fetched object's ID
Display NameThe user's or group's display name
EmailThe user's email / UPN
Mail NicknameThe mail nickname
Users / GroupsThe result arrays for Get Many operations
CountHow many objects were returned
SuccessWhether the operation succeeded
Full DataThe complete raw API response
Indite Documentation v1.7.1
PrivacyTermsSupport