Skip to content

Directory management

Configure the provider you use in Admin → Connectors: Microsoft Entra ID, Google Workspace (Directory), or Active Directory. These are distinct connector instances. See directory accounts for the exact provider and action matrix.

The legacy directory.* search and administration workflow uses fixtures only. The person-profile identity.* handlers provide live Entra and Google reads and the supported guarded writes. Active Directory does not implement the identity pane. LDAP authentication and kiosk resets are separate.

demoMode defaults to false. With it on, legacy directory actions use fixtures and identity reads and writes refuse. With it off, legacy directory actions refuse and supported identity handlers use the configured provider.

This older section link is retained for existing bookmarks. Live identity now also supports Google account state, sign-in and licence information, enable / disable and session revocation. Entra additionally supports Conditional Access reads, MFA reset, licence changes and password reset. The 0.12.0-rc.3 Exchange delegation extension is described in its own guide.

Registering the application (Entra, for the live identity actions)

Section titled “Registering the application (Entra, for the live identity actions)”

Register a school-owned Entra application, record its application ID, and supply the client secret value, not its identifier. Grant admin consent only for the Microsoft Graph operations you intend to use. Typical read permissions are User.Read.All, AuditLog.Read.All, Policy.Read.All, UserAuthenticationMethod.Read.All and Organization.Read.All.

Write permissions are separate and powerful. Review Microsoft’s current Graph permission reference for the selected operation and any required directory role, particularly for password resets and privileged target accounts. A successful connection test does not prove every read or write permission is present.

Entra uses tenantDomain, clientId and clientSecret. Leave demoMode off for live identity data. Mailbox delegation adds a separate opt-in setting and PFX credential; the Graph client secret remains in use for Graph.

Google uses a service account with domain-wide delegation, clientEmail and privateKey, plus the Workspace administrator to impersonate in adminEmail. customerId defaults to my_customer. Authorise only the OAuth scopes required by the operations you use in your Google Admin console. See Google’s domain-wide delegation guide.

Live writes need their individual identity.* permission, step-up, typed target confirmation and a reason. Audit intent is saved before the external call. The permission matrix and timeout handling are on directory accounts.

Symptom Check
Legacy directory operation refuses Expected outside demo mode; use supported person-profile actions
Identity pane says demo mode Turn demo mode off and configure real provider credentials
A section says unsupported The provider does not implement that capability
Data is unavailable or a write is refused Check the specific provider scope, consent, target role and connector configuration
An action is absent Check Directory module and the action’s individual permission