Configure Entra ID Using the CIE Enterprise App
Focus
Focus
Identity

Configure Entra ID Using the CIE Enterprise App

Table of Contents


Configure Entra ID Using the CIE Enterprise App

Learn how to configure Microsoft Entra ID in the Cloud Identity Engine using the CIE Enterprise app.
  1. Copy the Directory ID for your Entra ID tenant.
    1. Log in to the Microsoft Entra admin center or the Azure administrator portal using the credentials of the account you want to use to connect to the Cloud Identity Engine (for example, a service account) and select Overview.
    2. Copy the Directory (tenant) ID and store it in a secure location.
  2. Set up your Entra ID tenant in the Cloud Identity Engine.
    1. In the Cloud Identity Engine app, select Directories, then click Add New Directory.
    2. Set Up an Entra ID Cloud Directory.
  3. (Optional) Select additional information types to collect from Entra ID.
    The CIE Enterprise app automatically requests the privileges necessary to retrieve directory information, user risk information, and any other additional info you choose to collect. If you enable an option that requires additional privileges, you must reconnect the directory. For configurations that use the CIE Enterprise app, use the CIE Enterprise App onboarding URL in step 4.2 to grant the necessary privileges.
    After onboarding the app into Entra ID, you can revoke privileges if they are not necessary for your configuration. Do not revoke privileges for options you select. If you revoke a privilege required for an option you select or for the Cloud Identity Engine by default, the sync cannot complete.
    To restore revoked permissions, edit the directory configuration and complete steps 4.1 through 4.5.
    The following list provides the permissions for each additional information type.
    • Collect user risk information from Entra ID Identity Protection:
      • IdentityRiskyUser.Read.All
      • IdentityRiskEvent.Read.All
      For more information, refer to Create a Cloud Dynamic User Group.
    • Collect Roles and Administrators (Administrative roles): Directory.Read.All or RoleManagement.Read.Directory
    • Collect enterprise applications: Application.Read.All
    • Collect device information: Device.Read.All
    1. Collect user risk information from Entra ID Identity Protection to use in attribute-based Cloud Dynamic User Groups.
    2. Collect Roles and Administrators (Administrative roles) to retrieve roleAssignments attribute information for users and groups.
      Allowing the Cloud Identity Engine to include this information for analysis helps to prevent role-based malicious attacks.
      By default, the Cloud Identity Engine enables this option for tenants who are associated with Cortex XDR.
    3. Collect enterprise applications data so that it displays when you View Directory Data. If you don't want to collect the application data or you don't use application data in your Security policy, deselect the check box to decrease the sync time.
    4. Collect device information.
      This data is used by Cortex XDR and Device Security.
  4. Configure your Entra ID information in the Cloud Identity Engine.
    1. Enter the directory ID you copied in step 1.2 as the Directory ID.
    2. Generate the CIE Enterprise App onboarding URL to register the CIE Enterprise App in your Entra ID tenant.
      Registering the app in Microsoft Entra ID requires the Global Administrator role.
      If you do not have Global Administrator privileges in Entra ID, you must generate the URL and share it with an Entra ID administrator with Global Administrator privileges (Global Administrator role).
      1. Click Generate URL.
      2. Copy the resulting URL.
      3. Depending on your Entra ID role, perform one of the following actions:
        • (Global Administrator) Open the URL in a new tab or window to register the app instantly.
        • (Non-Global Administrator) Share the URL with an Entra ID administrator (Global Administrator) to complete the registration offline, then return to the Cloud Identity Engine.
    3. Enter the email address or phone number for the Global Administrator Role account you use to connect to the Cloud Identity Engine then click Next.
    4. Enter your password and Sign in.
    5. Click Accept to grant the necessary permissions for your Entra ID directory.
      When you accept, Entra ID automatically enables the following required permissions, as well as the additional information type permissions listed in step 3:
      • Device.Read.All—Application, Read all devices
      • Group.Read.All—Application, Read all groups
      • User.Read.All—Application, Read all users' full profiles
      • User.Read—Delegated, Sign in and read user profile
    6. Click Test Connection to confirm that the Cloud Identity Engine can successfully connect to your Entra ID tenant.
    7. (Optional) Enter a custom Directory Name (Optional) to use in the Cloud Identity Engine.
  5. (Optional) Upload a .CSV file to use as a filter for groups.
    1. Click Upload CSV to upload a comma-separated value (CSV) file to use as a filter.
    2. Drag and drop the .CSV file or click Browse files to select the .CSV file you want to use as a filter.
    3. Select the Upload Type for the filter.
      • Update Filters—Update the existing filters with the .CSV data.
      • Replace Existing Filters—Replace the existing filters with the .CSV data.
    4. Select the Attribute Name you want to use for the filter (Name or Unique Identifier).
    5. Click Apply to confirm the changes.
  6. (Optional) Filter Entra ID Groups.
    1. Select the group attribute you want to use as a filter.
      • Name—Filter the groups based on the group name.
      • Unique Identifier—Filter the groups based on the unique identifier for the group.
    2. Select how you want to filter the groups.
      • (for Name attribute only) begins with—Filter the groups based on a partial match for the text you enter.
        The filter supports spaces in the search query.
      • is equal to—Filter the groups based on an exact match for the text you enter.
    3. Enter the search query you want to use to filter the groups (either alphanumeric characters for a name or numeric characters for a unique identifier).
    4. (Optional) Configure an additional filter by clicking Add ORAdd Filter and repeating the previous three steps for each filter you want to include.
      If you select additional attributes as match conditions, the Cloud Identity Engine initially attempts to find a match for the first condition, then continues to match based on the additional conditions you specify.
  7. Submit your changes and verify your directory information when the Directories page displays.