> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Entra ID

## Overview

This guide walks through how to create a Microsoft Entra ID connection and the permissions it requires to be used in Blink's Automated Case Management, across **Ingestion**, **Enrichment**, and **Response** workflows.

<Note>
  Permission requirements can vary by workflow type. See [Required Permissions](#required-permissions) for the full breakdown by connection option.
</Note>

***

## Creating a Connection

You can authenticate to Microsoft Entra ID in one of two ways. Both are supported across every Microsoft integration in Blink's Automated Case Management, so the connection you choose here can be reused elsewhere.

<Tabs>
  <Tab title="Microsoft Graph">
    Recommended if this connection will be reused across other Microsoft integrations in your Automated Case Management setup.

    ### Creating a Connection

    <Card title="Microsoft Graph Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-graph">
      Follow this guide to create a Microsoft Graph connection
    </Card>

    ### Required Permissions

    <Accordion title="Required Permissions for Microsoft Graph">
      | Permissions |
      | - |
      | AuditLog.Read.All |
      | Calendars.ReadBasic |
      | Calendars.ReadWrite |
      | Calendars.ReadWrite.Shared |
      | Channel.Create |
      | ChannelMember.ReadWrite.All |
      | ChannelMessage.ReadWrite |
      | ChannelMessage.Send |
      | ChannelSettings.ReadWrite.All |
      | Chat.Create |
      | Chat.ReadWrite |
      | Chat.ReadWrite.All |
      | ChatMember.ReadWrite |
      | Device.Command |
      | Device.Read.All |
      | DeviceManagementApps.ReadWrite.All |
      | DeviceManagementManagedDevices.PrivilegedOperations.All |
      | DeviceManagementManagedDevices.ReadWrite.All |
      | Directory.AccessAsUser.All |
      | Directory.ReadWrite.All |
      | eDiscovery.ReadWrite.All |
      | Files.ReadWrite |
      | Files.ReadWrite.All |
      | Group.ReadWrite.All |
      | GroupMember.ReadWrite.All |
      | IdentityRiskyUser.Read.All |
      | IdentityRiskyUser.ReadWrite.All |
      | Mail.Read |
      | Mail.ReadBasic |
      | Mail.ReadWrite |
      | Mail.ReadWrite.Shared |
      | Mail.Send |
      | MailboxSettings.ReadWrite |
      | Notes.ReadWrite.All |
      | offline\_access |
      | OnlineMeetings.ReadWrite |
      | SecurityAlert.Read.All |
      | SecurityAlert.ReadWrite.All |
      | SecurityIncident.ReadWrite.All |
      | Sites.Manage.All |
      | Sites.ReadWrite.All |
      | TeamMember.ReadWrite.All |
      | ThreatHunting.Read.All |
      | User.EnableDisableAccount.All |
      | User.ManageIdentities.All |
      | User.Read |
      | User.ReadWrite.All |
      | User.RevokeSessions.All |
      | DeviceLocalCredential.ReadBasic.All |
      | SecurityCopilotWorkspaces.ReadWrite.All |
    </Accordion>
  </Tab>

  <Tab title="Microsoft Entra ID">
    Recommended if this connection will be used for Entra ID only.

    ### Creating a Connection

    <Card title="Microsoft Entra ID Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-entra-id">
      Follow this guide to create a Microsoft Entra ID connection
    </Card>

    ### Required Permissions

    | Least privileged permissions | Higher privileged permissions |
    | - | - |
    | `GroupMember.ReadWrite.All` | `Directory.AccessAsUser.All` |
    | `IdentityRiskyUser.ReadWrite.All` | `Directory.ReadWrite.All` |
    | `Group.Create` | `Group.ReadWrite.All` |
    | `User.ReadWrite.All` | `User.ReadWrite.All` |
    | `Group.ReadWrite.All` | `Directory.Read.All` |
    | `User.Read.All` | `SecurityAlert.ReadWrite.All` |
    | `SecurityAlert.Read.All` | `GroupMember.ReadWrite.All` |
    | `GroupMember.Read.All` | `Group.Read.All` |
    | `LicenseAssignment.ReadWrite.All` | `User.EnableDisableAccount.All` |
    | `User.ManageIdentities.All` | |
    | `Directory.Read.All` | |

    #### Response action permissions

    For the specific identity response actions Blink runs, the minimum required scopes per action are:

    | Response action | Scopes | Notes |
    | - | - | - |
    | Revoke User Session | `User.RevokeSessions.All`, `User.Read.All` | Cloud Entra ID only (not local AD) |
    | Password Reset | `User.Read.All`, `User-PasswordProfile.ReadWrite.All` | |
    | Require re-registration of MFA | `User.Read.All`, `UserAuthenticationMethod.ReadWrite.All` | Deletes all methods to force re-registration |
    | Enable User / Disable User | `User.Read.All`, `User.EnableDisableAccount.All` | |
  </Tab>
</Tabs>

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✓ Yes | Pulls Entra ID sign-in / identity alerts into Blink |
    | Enrichment | ✓Yes | Adds user/identity context to cases |
    | Response | ✓ Yes | Executes identity actions (e.g. revoke session, password reset, enable/disable user, MFA re-registration) |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.