What this connection does
The Entra ID connector gives EmDash a verified directory context for your tenant. It supports identity-aware administration and security workflows without exposing a tenant’s directory data to another customer.
Entra ID is separate from the Microsoft 365 mailbox connector. Connect both when you need directory context as well as message analysis.
Prerequisites
- An active EmDash tenant and a user with
integrations:manage(usually a Tenant Global Admin or Integration Administrator) to make changes. Users withintegrations:readcan view status. - The Microsoft Entra tenant ID (GUID) or a verified tenant domain.
- A Microsoft Entra Global Administrator, or another administrator who can approve the requested enterprise application permissions.
- The tenant must be active and the browser must be able to return to EmDash after consent.
Configure Entra ID
- In the tenant portal, open Settings → Integrations.
- Select Entra ID. Confirm that your role has integration-management access.
- Enter the Tenant ID or domain. Use the GUID from the Entra admin center or a verified domain such as
example.com. - Select Generate consent link and copy/open the link in the administrator’s browser session.
- Review the EmDash application name and requested permissions. The administrator must approve consent for the correct directory.
- Return to EmDash. The callback records the provider tenant and runs a connection probe; do not close the tab until it returns to the integration page.
- Confirm the page shows Connected, the expected tenant identity, and a recent successful test. If the link expires, generate a new one rather than reusing an old URL.
After connecting
Review the connection again after a few minutes and before troubleshooting a downstream workflow. A successful consent callback proves that consent was recorded, while the status probe confirms that the application can actually use the connection. If a domain has more than one directory, use the GUID to avoid selecting the wrong tenant.
Permissions and data boundaries
The connector requests only the directory permissions needed by the enabled EmDash workflows, such as AuditLog.Read.All and User.Read.All; optional identity-risk or group permissions may appear when a supported capability requires them. The exact consent screen is authoritative for your tenant.
EmDash does not ask for or display a reusable access token. Tenant isolation and role/module gating continue to apply, and Entra ID consent does not grant mailbox-body access. Mailbox analysis requires the separate Microsoft 365 connector and ICES entitlement.
Troubleshooting
- Consent link expired: generate a fresh link from the integration page.
- Wrong directory: disconnect or correct the tenant ID/domain, then repeat consent with the intended directory administrator.
- Connected but probe failed: check the last test status and provider request time, then run the test again after correcting administrator consent.
- Access denied: ask a Tenant Global Admin to grant your user
integrations:manage; direct navigation is intentionally gated. - A module or role is unavailable: module entitlements and roles are independent. See Modules and access and Roles and permissions.
For a connection that remains unavailable, capture the sanitized status shown in EmDash and open support. Do not include credentials or tokens in a ticket.