M ManySignal
MS
EI
Integration

Microsoft Entra Id Integration

Identity threat detection across your entire Azure AD estate.

What this integration does

Microsoft Entra ID meets agentic SOC

Microsoft Entra ID (formerly Azure Active Directory) is the identity provider for Microsoft 365, Azure, and thousands of integrated SaaS applications. ManySignal ingests sign-in logs, audit logs, and Identity Protection risk detections, building per-user behavioural models and correlating Entra events with endpoint and cloud activity for comprehensive identity threat detection.

Sign-in log ingestion including interactive and non-interactive sessions

Entra ID Identity Protection risk detection ingestion

Conditional Access policy evaluation result analysis

Data collected

  • Sign-in logs (interactive, non-interactive, service principal)
  • Audit logs (user, group, app, role changes)
  • Identity Protection risk detections
  • Conditional Access evaluation logs
  • Privileged Identity Management (PIM) activation events

Actions supported

  • Block user sign-in
  • Revoke all refresh tokens
  • Require MFA re-registration
  • Assign user to high-risk Conditional Access policy
  • Disable service principal

Getting started

Set up in minutes

  1. 1

    Create an Entra ID app registration

  2. 2

    Grant tenant-wide admin consent

  3. 3

    Configure the connector

  4. 4

    Map risk levels to ManySignal severity

Microsoft Entra Id Integration: frequently asked questions

Does ManySignal ingest PIM activation events?

Yes. Privileged Identity Management role activation, approval, and expiry events are ingested and correlated with subsequent privileged actions in Entra and Azure.

What is the ingestion latency for sign-in logs?

Entra ID sign-in logs are available in the Graph API with a 5–15 minute latency from the sign-in event. ManySignal polls every 2 minutes for near-real-time coverage.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.