Microsoft Entra ID
Nova manages accounts and their group memberships in Microsoft Entra ID. Nova talks to Entra ID through Microsoft Graph (version 1.0).
Connection
Administrators create an app registration with a client secret for Nova in Entra ID. Nova uses it to sign in without a user context (OAuth 2.0 client credentials) and acts with the app's application permissions.
The fields: “Tenant ID”, “Client (App) ID”, “Client Secret” and “UPN domain”. Under “Advanced” are “Authority (optional)”, “Graph endpoint” and “Scopes” (default: https://graph.microsoft.com/.default). “Check status” requests an access token. This confirms the app's credentials, not its Graph permissions.
Accounts
- Create: Nova creates the account enabled, with the account ID as
userPrincipalNameand the part before the “@” asmailNickname; further attributes follow the “Mapping”. If only the name part is entered when creating an account manually, Nova appends the “UPN domain”. - Change and delete via the Graph endpoint
/users. - Lock and unlock via
accountEnabled. Afterwards, Nova reads the state back and reports an error if it cannot be confirmed.
Groups
Nova takes over groups as entitlements with a job of type “Import Entra Groups”. Nova writes direct group memberships; the other members of a group remain untouched. Nova does not manage Entra directory roles.
Nova reads nested groups up to a limit of 500 groups and 32 levels. From this, Nova shows the group structure and, for an account, the section “Effective inherited memberships”. Nova reports cycles and incomplete reads as a notice. Nova does not write inherited memberships; they are not assignments in Nova.
Check after writing
During provisioning and reconciliation, Nova first reads all direct group memberships of the account. Nova then removes the groups to be revoked and adds the new ones. Afterwards, Nova reads the complete list again – across all pages of the Graph response – and compares it with the expected state.
Because Entra ID can make changes visible with a delay, Nova repeats the read for up to 30 seconds. If the state still does not match, the step counts as failed; Nova names missing and unexpected groups.
Last logon
Nova reads signInActivity and takes the most recent point in time from interactive, non-interactive and successful sign-ins. This requires the AuditLog.Read.All permission.
Graph permissions required
For each task, the table names an application permission that Microsoft documents for the calls concerned:
| Task | Graph calls | Permission |
|---|---|---|
| Read accounts | GET /users | User.Read.All |
| Create, change, lock, delete accounts | POST, PATCH, DELETE /users | User.ReadWrite.All |
| Read groups and group structure | GET /groups, …/members, …/memberOf | GroupMember.Read.All |
| Read an account's groups | GET /users/{id}/memberOf | Directory.Read.All |
| Write memberships | POST, DELETE /groups/{id}/members | GroupMember.ReadWrite.All |
| Last logon | GET /users with signInActivity | AuditLog.Read.All |
For setting passwords (passwordProfile), Microsoft requires rights beyond this table; they are described in the Microsoft Graph documentation for “Update user”. Microsoft adjusts permissions from time to time; the current documentation is authoritative.