Microsoft Entra ID
SSO, account state, MFA methods, sign-ins, guarded resets.
Reviewed capabilities
Section titled “Reviewed capabilities”- Add a person to a group (live). The directory.manage permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Assign or remove an identity licence (live). The identity.license.manage permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Change demonstration licences (demo-only). Explicitly enable built-in demo data. Fictional directory records only. These legacy actions do not read or change the school’s real directory.
- Change demonstration mailbox delegates (demo-only). Explicitly enable built-in demo data. Fictional directory records only. These legacy actions do not read or change the school’s real directory.
- Create an identity account (live). The identity.account.manage permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Enable or disable a demonstration account (demo-only). Explicitly enable built-in demo data. Fictional directory records only. These legacy actions do not read or change the school’s real directory.
- Enable or disable an identity account (live). The identity.account.manage permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Find licences on disabled accounts (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Issue a temporary access pass (live). The identity.mfa.reset permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Manage Exchange mailbox delegation (live). The identity.mailbox.delegate permission, fresh multifactor verification, confirmation of the target and an audit record. Separately enabled mailbox delegation, an Exchange certificate and reviewed Exchange RBAC. The validated setup uses five commands: Get/Add/Remove-MailboxPermission and Get/Remove-RecipientPermission. Add-RecipientPermission is excluded. Identity information and privileged identity actions are never simulated in demo mode. The earlier six-command setup allowed an out-of-scope Send As grant in two live pilots, despite the recipient-scope lookup excluding that mailbox. That Send As credential boundary was not accepted; a healthy connection does not validate scope.
- Move an account to another organisational unit (unsupported). The directory.manage permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode. This provider returns an explicit unsupported result; a registered handler does not establish live support.
- Publish an approved booking or event to a calendar (live). Calendar API application consent or delegated service-account access; each target mailbox/calendar must be explicitly listed in the connector calendar allowlist. Creates or updates an event on an allowlisted calendar only when calendar publishing is enabled in connector settings. Provider access must cover that calendar.
- Read a demonstration directory user (demo-only). Explicitly enable built-in demo data. Fictional directory records only. These legacy actions do not read or change the school’s real directory.
- Read a group’s members (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Read a person’s manager (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Read Conditional Access policies (live). The identity.policy.view permission and the provider’s consent/licence requirements for this read. Suitable Microsoft licensing and Graph application consent; missing access is reported rather than treated as an empty result. Identity information and privileged identity actions are never simulated in demo mode.
- Read directory groups (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Read identity account status (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Read multifactor registration (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Read organisation licence totals (live). The identity.view permission and the provider’s consent/licence requirements for this read. Identity information and privileged identity actions are never simulated in demo mode.
- Read room or staff calendar availability (live). Calendar API application consent or delegated service-account access; each target mailbox/calendar must be explicitly listed in the connector calendar allowlist. Availability is read from the selected provider; a failed or unsupported response does not establish that a room is free.
- Read sign-in history (live). The identity.signins.view permission and the provider’s consent/licence requirements for this read. Suitable Microsoft licensing and Graph application consent; missing access is reported rather than treated as an empty result. Identity information and privileged identity actions are never simulated in demo mode.
- Remove a person from a group (live). The directory.manage permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Reset a demonstration password (demo-only). Explicitly enable built-in demo data. Fictional directory records only. These legacy actions do not read or change the school’s real directory.
- Reset an identity password (live). The identity.password.reset permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Reset multifactor methods (live). The identity.mfa.reset permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Revoke sign-in sessions (live). The identity.session.revoke permission, fresh multifactor verification, confirmation of the target and an audit record. Identity information and privileged identity actions are never simulated in demo mode.
- Search the demonstration directory (demo-only). Explicitly enable built-in demo data. Fictional directory records only. These legacy actions do not read or change the school’s real directory.
- Send a workflow notification to Teams or Google Chat (live). A configured Teams Workflows or Google Chat incoming webhook, sealed with the existing directory connector credentials. Sends to the configured channel webhook only. This is not a general Teams or Google Chat conversation mirror.
Requirements
Section titled “Requirements”- An enabled connector, a compatible vendor service and appropriate Plugboard permissions. Live handlers require real configuration and provider access.
- Provider credentials and permissions must be configured by the school’s administrator. Never paste credentials into documentation.
This is a source capability reference, not evidence of a successful connection to your vendor account. Check the connector and version available in your deployment.
Next steps
Section titled “Next steps”For an available connector, open Admin → Connectors and check its configuration fields, requirements and permissions. Use Test connection before relying on synced records.
See connector configuration for shared setup concepts and the capability reference for reviewed support and limitations.