← All integrations
Identity · integration
Microsoft Entra ID
MFA, privileged access, conditional access and deprovisioning for Microsoft Entra ID.
ISO 27001SOC 2PCI DSSDPDPARBISEBI CSCRFIRDAI
What ProofLayer proves
Read-only evidence, evaluated against versioned rules.
- Every member and every privileged-role holder has MFA registered; global-admin count is limited
- Conditional Access enforces MFA for admins and blocks legacy auth
- Guest invites and app registrations are restricted; departed people have no active account
Configure in ProofLayer
Live in minutes.
- Connections → New connection → pick this provider and name the account.
- Enter the directory (tenant) ID and either your app registration (client ID + write-only secret) or grant ProofLayer’s multi-tenant app admin consent.
- Click Test connection — ProofLayer verifies read access from the control plane and reports a clear reason if anything is off.
- Set the scan schedule; every run appends to the evidence chain for this account.
- Choose the framework mapping(s) and, optionally, a push target (CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack).
Grant access from your side
Read-only, least-privilege, revocable.
You create the access in your own console and paste a credential ProofLayer stores sealed — it never writes to your systems.
- Register an app with the read-only Graph application permissions (e.g. Directory.Read.All, Policy.Read.All, AuditLog.Read.All) and grant admin consent.
- Create a client secret (pasted write-only), or use ProofLayer’s multi-tenant app so no secret exists at all.
In-account agent option. Run the agent with your app registration in AZURE_* env vars; the secret never leaves your host. The collector posts evidence outbound-only, so ProofLayer holds no credential into your environment.