Skip to content

Integrate CapaOne with Entra ID

Connect CapaOne to Microsoft Entra ID to sync your directory users to Management → Users. You register an application in Entra ID, give it read permissions for users and groups, and then create an Entra ID integration in CapaOne with the application’s details. The same integration can also be used to upload Company Apps to Intune. See Set Up Intune Permissions for CustomApps Upload.

  1. Navigate to https://portal.azure.com/#home

  2. Click Microsoft Entra ID

Azure portal home with Microsoft Entra ID highlighted

  1. Click App registrations

Microsoft Entra ID overview with App registrations in the sidebar

  1. Click New registration

App registrations page with the New registration button

  1. Provide a name, select Accounts in this organizational directory only under Supported account types, and click Register at the bottom of the page

Register an application form with name and supported account types

  1. Click on Add a certificate or secret

App registration overview with the Add a certificate or secret link

  1. Click on New client secret

Certificates and secrets page with the New client secret button

  1. Provide a description (not required) and set an expiration date. We suggest setting it to 24 months. Afterwards click Add at the bottom of the page

Add a client secret panel with description and a 24-month expiry

  1. After the client secret is created you need to copy the value and save it in a notepad. If you refresh or leave the page you will have to create a new client secret

Client secret Value and Secret ID columns ready to copy

  1. Click on API permissions in the sidebar and then Add a permission

App registration sidebar with API permissions and the Add a permission button

  1. Select Microsoft Graph

Request API permissions panel with Microsoft Graph selected

  1. Select Application permissions

Microsoft Graph permission type with Application permissions selected

  1. Scroll down and expand Group and set a checkmark in Group.Read.All and then Add permissions at the bottom of the page

Group permissions expanded with Group.Read.All checked

  1. Go through the same permission steps and set a checkmark in User for User.Read.All and Add permissions

User permissions expanded with User.Read.All checked

  1. Go through the same permission steps and set a checkmark in GroupMember for GroupMember.Read.All and Add permissions

GroupMember permissions expanded with GroupMember.Read.All checked

  1. Click on Grant admin consent for (name of directory)

API permissions list with the Grant admin consent button

  1. Click Yes to the popup

Grant admin consent confirmation dialog

  1. Click on Home in the upper left corner

Azure portal with the Home link in the upper left corner

  1. Click on Microsoft Entra ID

Azure portal home with Microsoft Entra ID

  1. Click on App registrations in the left pane, and open the application you registered

Microsoft Entra ID with App registrations in the left pane

  1. Copy the Application (client) ID to your notepad

App registration overview showing the Application (client) ID

  1. Click on Properties in the left pane

App registration sidebar with Properties selected

  1. Copy the tenant ID to your notepad

Entra ID Properties page showing the Tenant ID

  1. In CapaOne, go to Management → Integrations

CapaOne left pane with Management expanded and Integrations selected

  1. Click on New to create a new integration

CapaOne Integrations page search field with the New button

  1. Provide the following information for the new Entra ID integration
  • Name – a name for the integration
  • Application (client) ID – from step 21
  • Directory (tenant) ID – from step 23
  • Client secret value – from step 9
  • Client secret expiration date – the expiration date you chose in step 8
  • User Properties – optional. Select extra Entra ID user properties to sync, such as Department, Job Title, or Office Location. The user ID and email are always stored.

Then select a synchronization schedule: Never, Daily, Weekly, or Monthly. Unless you select Never, also select the time of day for the sync. For Weekly and Monthly, select the day as well. Click on Create.

New Entra ID integration form with name, application (client) ID, directory (tenant) ID, client secret value, client secret expiration date, User Properties, and automatic synchronization

  1. If you click on the 3 dots to the right of the newly created integration you can do the following
  • Edit
  • Sync now
  • View integration
  • Delete

Integration action menu with Edit, Sync now, View integration, and Delete

  1. Click on Sync now

Integration action menu with Sync now highlighted

  1. When the sync is done, go to Management → Users. The users from Entra ID have an Entra ID icon to the left of their name

CapaOne Users list showing an Entra ID icon beside each synced user

The client secret expires on the date you set in Entra ID. When it expires, the integration can’t sync users and groups. Renew it before it expires:

  1. In the Azure portal, create a new client secret for the app registration, as in steps 6–9.
  2. In CapaOne, go to Management → Integrations.
  3. Click the options menu (⋮) next to the integration and select Edit. The Integration configuration page opens.
  4. Enter the new secret in Client secret. If you leave the field empty, the current secret is kept.
  5. Update Client Secret Expiration Date to the new expiration date.
  6. Click Save, and then select Sync now to confirm that the sync works.

The integration card on Management → Integrations shows the Secret expiration date. It turns yellow when the secret expires within a month and red when it has expired, so you can see when it’s time to renew. The card also shows the Last sync status. If a sync failed, click the status to open the synchronization log.