Microsoft Entra ID
Microsoft Entra ID connects through a Microsoft admin-consent screen rather than a sign-in. A tenant administrator approves read-only access once, and from then on Governax reads your directory audit log every ten minutes. No credential of yours is stored.
Before you start#
What you are approving#
The consent screen lists four application permissions on Microsoft Graph. All four are read-only, and each one maps to something Governax actually does:
Governax reads audit records and directory objects only. It never reads mailboxes, files or passwords, and it never writes to your directory.
Connecting#
Open the entity, then Integrations, then Microsoft Entra ID
Click Connect. You are sent to Microsoft.
Sign in as an administrator and accept the consent
Microsoft shows the four permissions above and asks you to accept them on behalf of your organisation. Declining sends you back to Governax with nothing connected.
Governax proves it can authenticate to your tenant
Before anything is saved, Governax requests a token for your tenant using the consent you just granted. A consent that Microsoft accepted but that Governax cannot actually use is refused here, rather than becoming a connection that fails silently on its first background poll.
The baseline snapshot starts
You are returned to the integration page and the connection shows as connected. The snapshot runs in the background so a large tenant does not hold your browser open. The tenant's display name appears once it has resolved; until then the tenant id is shown.
A Microsoft tenant can be connected to one entity at a time. If it is already connected to another organisation the consent is refused outright; if it is connected to another entity in your organisation, disconnect it there first. See Connecting a tool.
Nothing of yours is stored#
Consent is recorded on Microsoft's side, against Governax's own app registration. Governax then mints short-lived, tenant-specific tokens from that registration whenever it needs to read. The only thing stored on the connection is your tenant id, which is not a secret.
The baseline snapshot#
The event stream says what changed. The snapshot says what is true now, which is the question an access review actually asks. Without it, anyone who has held Global Administrator since before you connected would appear nowhere. Two things are captured, as access.baseline_observed events:
Group membership is deliberately not in the snapshot, for volume. Group changes from connect time forward are captured by the event stream.
How polling works#
Events captured#
Actor and subject are recorded by user principal name, which is a real email address, so Entra events need no identity mapping to read.
What is deliberately dropped#
Disconnecting#
Reconnecting later keeps the previous poll position, so a reconnect does not re-import everything.
Troubleshooting#
General connector behaviour is covered in Connecting a tool.