help.nightfall.ai / nightfall_settings / directory_sync / microsoft_entra_id.md
For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending
.mdto page URLs; this page is available as Markdown.
Add Microsoft Entra ID to Nightfall
This document explains the process of adding your Microsoft Entra ID to Nightfall to enable Directory Sync. Once you add the Microsoft tenant to Nightfall, you can sync users and user groups data from Microsoft to Nightfall. To get an overview of the Directory Sync feature in Nightfall, you can read this article and then proceed with this document.
Prerequisites
- You must have a Microsoft Entra ID (formerly known as Microsoft Azure Active Directory) account.
- A Microsoft Entra user account for Nightfall with one of the following roles:
- Global Administrator or Privileged Role Administrator, for granting consent for apps requesting any permission, for any API.
- Cloud Application Administrator or Application Administrator, for granting consent for apps requesting any permission for any API, except Microsoft Graph app roles (application permissions).
- A custom directory role that includes the permission to grant permissions to applications, for the permissions required by the application.
- For more information, refer to the Microsoft documentation here.
Configure Microsoft Entra ID
- Click the Settings button on the Nightfall console (bottom-left).
- Click the Directory Sync tab.
- Click Add Directory.
- Select Azure Entra as the identity provider.
- Click Connect.
- Enter Email or phone number associated with your Microsoft Azure account.
- Click Next.
- Enter your password and click Sign In.
When you sign in as an Azure admin, you can consent the installation of Nightfall IDP yourself. You can view the following screen. You must click Accept.
<figure><!--kb:media-unavailable--><figcaption></figcaption></figure>Once you approve the request, the installation proceeds. Once the installation is completed, you can see the following screen. You must click Setup Complete.
<figure><!--kb:media-unavailable--><figcaption></figcaption></figure>After the setup is complete, the first sync may take 15 to 30 min to complete. While the first sync is in progress you would see "pending" under status. Once the sync is complete, the status would transition from "pending" to "synced" and you can view the number of active users, inactive users and groups discovered.
<figure><!--kb:media-unavailable--><figcaption></figcaption></figure>{% hint style="info" %} Active users in Azure are the users who actively log in to Azure and perform various tasks.
Inactive users are dormant users who have not logged in to their Azure account for a while. You can refer to this Microsoft document to learn more about managing inactive users. {% endhint %}
Nightfall syncs with your Identity and Access Provider every four hours. Also, you can manually sync once every hour. To sync data manually, click the ellipsis menu and select Refresh.
<figure><!--kb:media-unavailable--><figcaption></figcaption></figure>Currently, once registered you cannot unregister an Identity and Access Provider from Nightfall. If you do wish to unregister your Identity and Access Provider, please contact Nightfall support.
Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.
Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.
Perform an HTTP GET request on the current page URL with the ask query parameter, and the optional goal query parameter:
GET https://help.nightfall.ai/nightfall_settings/directory_sync/microsoft_entra_id.md?ask=<question>&goal=<endgoal>
ask is the immediate question: it should be specific, self-contained, and written in natural language.
goal is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.
Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.