Directory management
Configure the provider you use in Admin → Connectors: Microsoft Entra ID, Google Workspace (Directory), or Active Directory. These are distinct connector instances. See directory accounts for the exact provider and action matrix.
Capabilities
Section titled “Capabilities”The legacy directory.* search and administration workflow uses fixtures only.
The person-profile identity.* handlers provide live Entra and Google reads and
the supported guarded writes. Active Directory does not implement the identity
pane. LDAP authentication and kiosk resets are separate.
Demo mode
Section titled “Demo mode”demoMode defaults to false. With it on, legacy directory actions use fixtures
and identity reads and writes refuse. With it off, legacy directory actions
refuse and supported identity handlers use the configured provider.
Live identity actions (Entra only)
Section titled “Live identity actions (Entra only)”This older section link is retained for existing bookmarks. Live identity now also supports Google account state, sign-in and licence information, enable / disable and session revocation. Entra additionally supports Conditional Access reads, MFA reset, licence changes and password reset. The 0.12.0-rc.3 Exchange delegation extension is described in its own guide.
Registering the application (Entra, for the live identity actions)
Section titled “Registering the application (Entra, for the live identity actions)”Register a school-owned Entra application, record its application ID, and supply
the client secret value, not its identifier. Grant admin consent only for
the Microsoft Graph operations you intend to use. Typical read permissions are
User.Read.All, AuditLog.Read.All, Policy.Read.All,
UserAuthenticationMethod.Read.All and Organization.Read.All.
Write permissions are separate and powerful. Review Microsoft’s current Graph permission reference for the selected operation and any required directory role, particularly for password resets and privileged target accounts. A successful connection test does not prove every read or write permission is present.
Configuring it in Plugboard
Section titled “Configuring it in Plugboard”Entra uses tenantDomain, clientId and clientSecret. Leave demoMode off for
live identity data. Mailbox delegation adds a separate opt-in setting and PFX
credential; the Graph client secret remains in use for Graph.
Google uses a service account with domain-wide delegation, clientEmail and
privateKey, plus the Workspace administrator to impersonate in adminEmail.
customerId defaults to my_customer. Authorise only the OAuth scopes required
by the operations you use in your Google Admin console. See Google’s
domain-wide delegation guide.
Auditing and permissions
Section titled “Auditing and permissions”Live writes need their individual identity.* permission, step-up, typed target
confirmation and a reason. Audit intent is saved before the external call. The
permission matrix and timeout handling are on directory accounts.
Troubleshooting
Section titled “Troubleshooting”| Symptom | Check |
|---|---|
| Legacy directory operation refuses | Expected outside demo mode; use supported person-profile actions |
| Identity pane says demo mode | Turn demo mode off and configure real provider credentials |
| A section says unsupported | The provider does not implement that capability |
| Data is unavailable or a write is refused | Check the specific provider scope, consent, target role and connector configuration |
| An action is absent | Check Directory module and the action’s individual permission |