Learn how to set up an Entra ID directory in the Cloud Identity Engine.
| Where Can I Use This? | What Do I Need? |
|
| The Cloud Identity Engine service is free; however, the
enforcement points utilizing directory data may require specific
licenses. Click here for more
information. |
Configure Microsoft Entra ID (formerly Azure AD) in the Cloud Identity Engine to
allow the Cloud Identity Engine to collect directory data for policy rule
enforcement and user visibility.
To configure directory sync with an Entra ID tenant using
the Cloud Identity Engine Enterprise app, you must be an Entra ID Global
Administrator or have a Global Administrator available to complete the app
registration using the onboarding URL.
As an alternative, you can
configure the SCIM connector to select and
synchronize the Entra ID attribute data you want to collect with the Cloud Identity
Engine.
To further reduce sync time and minimize the amount of data collected by the Cloud
Identity Engine, you can configure the Cloud Identity Engine to sync only specific
groups from your directory by filtering the groups. Because SCIM is most suitable
for small and frequent data requests, Microsoft restricts directory update intervals
to once every 40 minutes. If you filter the groups instead, directory updates can
occur as often as every 5 minutes. Choose the best option for your deployment based
on your organizational and regulatory requirements.
The Cloud Identity Engine retrieves updates from your Entra ID tenant using the
following schedule:
- Users, Groups, and Devices—When the Cloud Identity Engine syncs
changes.
- Apps—Every x hours (where x is either a
maximum of 3 hours or the duration necessary to complete the previous apps
sync).
- Role Assignments—Every x hours (where x is
either a maximum of 24 hours or the duration necessary to complete the previous
role assignment sync).
When you configure Entra ID for the Cloud
Identity Engine, log in, and grant the necessary permissions, Microsoft
automatically onboards the Cloud Identity Engine Enterprise App into Entra ID.