Prerequisites
The user performing the integration must have the Global Reader role assigned
A Reco user with Admin Role
Audit Logging in O365 Enabled
Click on "Start recording user and admin activity"
Integrate MSFT Active Directory with Reco
Login to the Reco Platform
Click on "Configurations" and then "Integrations"
Locate the "Microsoft AD" object, and click on "Add Integration"
You will be redirected to a consent page, Click on "Accept"
If the integration was successful, the Microsoft AD Integration status will become "Active"
click on "Configure"
Choose the required start date for data ingestion, and click on "Start Extraction"
What do we ingest exactly?
Metadata only!
Source | Required Scope | Documentation |
MSFT_USER_API | Directory.Read.All | |
MSFT_USER_MEMBER_OF_API | Directory.Read.All | |
MSFT_GROUPS_API | Directory.Read.All | |
MSFT_GROUP_OWNERS_API | Directory.Read.All | |
MSFT_GROUP_MEMBERS_API | Directory.Read.All | |
MSFT_USER_REGISTRATION_DETAILS_API | AuditLog.Read.All | |
MSFT_SECURE_SCORE_API | SecurityEvents.Read.All | |
MSFT_SECURE_SCORE_CONTROL_PROFILES_API | SecurityEvents.Read.All | |
MSFT_DOMAINS_API | Directory.Read.All | |
MSFT_DIRECTORY_AUDIT_API | AuditLog.Read.All | |
MSFT_OWNERS_API | Directory.Read.All |