---
title: Connecting Microsoft Entra ID
description: Prelude integrates with multiple Microsoft use-cases/products. This page provides information to configure for a single user-case.  It is recommended however that you configure a single, all-in-one Mi
---

[Skip to content](https://support.preludesecurity.com/docs/entra-id#main-content)

English

Show submenu for translations

[Contact support](https://support.preludesecurity.com/kb-tickets/new?hsLang=en)

![Prelude\_Wordmark\_Black\_Transparent.png\]](https://support.preludesecurity.com/hs-fs/hubfs/Prelude_Wordmark_Black_Transparent.png?height=50&name=Prelude_Wordmark_Black_Transparent.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact support](https://support.preludesecurity.com/kb-tickets/new)
- [Visit the website](https://www.preludesecurity.com/)

[Visit the website](https://www.preludesecurity.com/)

 Find what you're looking for

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.preludesecurity.com/?hsLang=en)
2. [Monitor](https://support.preludesecurity.com/monitor?hsLang=en)
3. [Identity Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#identity-management-integrations)

# Connecting Microsoft Entra ID

*Prelude integrates with multiple Microsoft use-cases/products. This page provides information to configure for a single user-case.  It is recommended however that you configure a single, all-in-one Microsoft App registration for all Microsoft integrations, which can be done [automatically](https://support.preludesecurity.com/microsoft-automated-integration-setup?hsLang=en) with a [single click here](https://support.preludesecurity.com/microsoft-automated-integration-setup?hsLang=en)or  following the instructions [manually here](https://support.preludesecurity.com/docs/microsoft-all?hsLang=en).  Alternatively you can continue below for use-case specific integration instructions.*

To attach a Microsoft Entra ID account to Detect, you will need:

- The Prelude Dashboard / UI ([US1](https://platform.us1.preludesecurity.com/dashboard) | [EU1](https://platform.eu1.preludesecurity.com/dashboard)) or [Prelude CLI](https://support.preludesecurity.com/docs/prelude-cli?hsLang=en)
- An Azure user with Global Administrator role

### In Azure

### Create an App Registration

1. Navigate to the [App registrations section](https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationsListBlade) in the **Azure Portal**.
2. Select "**+ New registration**" toward the top of the page.
3. Enter a name for your application
4. Choose **Single tenant** as the supported account type (*Accounts in this organizational directory only*). Click Register.
5. Leave **Redirect URI (optional)** as it is.
6. After registration: 
     1. Copy/Save the **Application (client) ID** and **Directory (tenant) ID** from the app's **Overview page**.
7. In the left menu, expand the **Manage** section and select **Certificates & secrets** and create a **new Client Secret**: 
     1. Click **New client secret**, enter a description, and set an expiration period.
     2. Copy/Save the generated **Client Secret Value** (you won’t be able to view it later).

The following information are need to be documented/saved for later.

- **APP ID** (*Application (client) ID*) from step 6
- **TENANT ID** (*Directory (tenant) ID*) from step 6
- **APP SECRET** (*Client Secret Value*) from step 7

#### Granting API Permissions

1. In the left menu of the app you created, select **API permissions** and click **Add a permission**
2. Under "**Microsoft APIs**" select **Microsoft Graph**
3. Select Application permissions (not Delegated) and add the following API Permissions. 
     1. `AuditLog.Read.All`
     2. `IdentityRiskyUser.Read.All`
     3. `Policy.Read.All`
     4. `UserAuthenticationMethod.Read.All`
     5. `User.Read.All`
     6. `DeviceManagementConfiguration.Read.All`
     7. `Group.Read.All`

**Note**: After adding the above permissions ensure you select "Grant admin consent for " as show in the screenshot below:

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/bb45d76b14f5e436491948793b3c9855e37e7e7c2f15cedb590452e374137827-image.png)

### Granting Global Reader role

**Note:** There is [an alternative process](https://support.preludesecurity.com/how-to-connect-m365-and-entra-without-global-reader?hsLang=en) that can be used in place of granting Global Reader and instead uses the lesser privileged "View-Only Recipients" and "Security Reader" roles, but does require running a powershell script.  

1. Navigate to [Entra ID](https://portal.azure.com/#view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/Overview) in the **Azure portal**
2. Expand **Manage** and select "**Roles and Administrators**" on the left hand side
3. Search for the "**Global Reader**" role and click on it
4. On the next screen, select **Add Assignment**
5. In the "Search" field, enter the **whole** App ID (it often won't match partial App IDs, only Partial names/groups) and assign it to the Security Reader role:
   
   ![](https://support.preludesecurity.com/hs-fs/hubfs/screenshot_2504-png-1.png?width=688&height=318&name=screenshot_2504-png-1.png)

### In Prelude

#### Attach the partner

You can attach a partner via UI or CLI

#### via UI

- Navigate to your user name in upper right hand corner and select "Integrations"
- Select the "**Connect**" action for **Microsoft Entra ID**
- Fill out Base URL, Tenant ID, APP ID and App Secret to connect 
    - Base URL should be set to `https://api.securitycenter.microsoft.com`. Optionally can be set to hit one of Microsoft's regional endpoints, example `https://api-<REGION>.securitycenter.microsoft.com`

#### via CLI

Ensure you have the [latest version of the CLI](https://support.preludesecurity.com/docs/prelude-cli?hsLang=en)

- run: `prelude partner attach --api https://api.securitycenter.microsoft.com/ --user {TENANT ID} --secret {APP ID}/{APP SECRET} ENTRA` 
    - replace {TENANT ID}, {APP ID} and {APP SECRET} with the values from your [App Registration](https://support.preludesecurity.com/docs/entra-id#create-an-app-registration)
    - `--api` is a *required* field that should be set to `https://api.securitycenter.microsoft.com`. Optionally can be set to hit one of Microsoft's regional endpoints, example `https://api-<REGION>.securitycenter.microsoft.com`

#### Detach the partner

#### via UI

- Navigate to your user name in upper right hand corner and select "Integrations"
- Select the "**Disconnect**" action for **Microsoft Entra ID**

#### via CLI

Ensure you have the [latest version of the CLI](https://support.preludesecurity.com/docs/prelude-cli?hsLang=en)

- run: `prelude partner detach ENTRA`

- [Monitor](https://support.preludesecurity.com/monitor?hsLang=en#main-content)

    - [Introduction to Control Monitor](https://support.preludesecurity.com/monitor?hsLang=en#introduction-to-control-monitor)
    - [Configuration](https://support.preludesecurity.com/monitor?hsLang=en#configuration)
    - [Client Hardware Security Integrations](https://support.preludesecurity.com/monitor?hsLang=en#client-hardware-security-integrations)
    - [Device Discovery Integrations](https://support.preludesecurity.com/monitor?hsLang=en#device-discovery-integrations)
    - [EDR Integrations](https://support.preludesecurity.com/monitor?hsLang=en#edr-integrations)
    - [Email Integrations](https://support.preludesecurity.com/monitor?hsLang=en#email-integrations)
    - [Identity Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#identity-management-integrations)
    - [Endpoint Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#endpoint-management-integrations)
    - [Vulnerability Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#vulnerability-management-integrations)
    - [Reporting](https://support.preludesecurity.com/monitor?hsLang=en#reporting)
    - [Troubleshooting](https://support.preludesecurity.com/monitor?hsLang=en#troubleshooting)
- [Detect](https://support.preludesecurity.com/detect?hsLang=en#main-content)

    - [Basics](https://support.preludesecurity.com/detect?hsLang=en#basics)
    - [Integrations](https://support.preludesecurity.com/detect?hsLang=en#integrations)
    - [Probe deployment](https://support.preludesecurity.com/detect?hsLang=en#probe-deployment)
    - [Security tests](https://support.preludesecurity.com/detect?hsLang=en#security-tests)
    - [Alert suppression](https://support.preludesecurity.com/detect?hsLang=en#alert-suppression)
    - [Assurance](https://support.preludesecurity.com/detect?hsLang=en#assurance)
- [Integrations](https://support.preludesecurity.com/integrations?hsLang=en#main-content)

    - [SASE](https://support.preludesecurity.com/integrations?hsLang=en#sase)
- [Account](https://support.preludesecurity.com/account?hsLang=en#main-content)

    - [SSO](https://support.preludesecurity.com/account?hsLang=en#sso)
- [CLI](https://support.preludesecurity.com/cli?hsLang=en)
- [Release Notes](https://support.preludesecurity.com/release-notes?hsLang=en)

[![Origin Technology Logo](https://support.preludesecurity.com/hs-fs/hubfs/origin_logo_inverse_000000.png?width=5000&height=5000&name=origin_logo_inverse_000000.png "Origin Technology Logo")](http://originhq.com)

Prelude Security Knowledge Base

Copyright © 2026, Origin Technology