QUESTION
How do I update my Active Directory Azure integration to use the MS Graph API?
ANSWER We have the instructions you need!
NOTE For new AD Azure configurations, please use our WAAD configuration supplement.
We've updated our AD Azure integration to leverage the MS Graph API in preparation for Microsoft's deprecation of the Azure Active Directory Graph API in June of 2022.
Please follow the steps below to update your existing configuration to ensure that the integration continues to work!
-
Log in to Microsoft Azure as an administrator and select the relevant Azure directory.
-
Select Azure Active Directory in the side bar.
-
Select the App Registrations option.
-
Choose the existing app you have set up for your Workplace Azure Active Directory integration.
-
Click API Permissions under the Manage menu.
-
Add Microsoft Graph delegated permissions:
-
Click Add a Permission.
-
Click MS Directory Graph:
-
Click Delegated Permissions.
-
Select the User.Read and the Directory.AccessAsUser.All options. Hint: Use the filter feature to help you locate the correct options.
-
Click Add Permissions.
-
-
Add Microsoft Graph application permissions:
-
On the API Permission view, click Add a permission.
-
Click MS Directory Graph.
-
Click Application permissions and select the Directory.Read.All option. Hint: Use the filter feature to help you locate the correct options.
-
Remove Azure Active Directory Graph permissions:
-
Click Add Permissions.
-
On the API Permissions view, click Grant admin consent for {Company Name}, then click Yes when prompted to confirm.
-
Click Active Directory Graph and Remove all permissions. Right-click on User.Read,Directory.Read.All and Directory.AccessAsUser.All and remove the permissions.
-
Click Update permissions.
-
-
Go to Workplace > Configuration and click the sync icon on the AD tile (or click Manage and then the Sync button).