Skip to content

Microsoft app registrations

Microsoft Graph connectors need an app registration and the appropriate application permissions, approved by a Microsoft administrator. The Enterprise Application is that app’s service principal in the school’s tenant. It is created alongside a school-owned registration, or when the school consents to a multitenant app. See Microsoft’s app and service principal model.

Use a school-owned, single-tenant registration for the installed instance. The connectors use server-side client credentials for background operations; these are separate from a person’s Plugboard SSO sign-in. An SSO registration does not automatically authorize imports.

Connector Configure in Plugboard Start with
Microsoft Intune Tenant ID, client ID and secret DeviceManagementManagedDevices.Read.All application permission for device and optional detected-app inventory; see the Intune setup guide
Microsoft Entra ID Primary domain or tenant ID in tenantDomain, client ID and secret; demo mode off Permissions for the identity sections the school intends to use. User.Read.All allows profile reads; authentication methods, sign-ins, policies and licences require their own permissions
Exchange Full Access Separate certificate and Exchange role/scope configuration Follow the Exchange delegation guide; Graph consent alone is insufficient

Enter credentials in Admin → Connectors. Grant administrator consent in Entra and track credential expiry. A successful connection test proves authentication, not access to every optional feature. Grant only the permissions for enabled workflows; inventory does not require account administration, wipe or mailbox delegation.

A Plugboard-owned multitenant registration could let hosted customers connect through an administrator-consent flow instead of creating their own app. Consent creates an Enterprise Application in each customer tenant; customers still approve its permissions. Microsoft’s cross-tenant setup guide describes that process.

This release does not include that hosted onboarding flow. It needs tenant binding, consent/revocation handling and centrally managed credentials. A shared publisher secret must stay in the hosted service; it must not be distributed to customer-managed installations. Self-hosted instances can continue using their own registration. Microsoft Partner access can support publisher verification, but does not replace each customer’s consent.

The current customer-owned setup therefore remains usable without waiting for a shared app. No shared multitenant application is provisioned by installing this release.