Microsoft Entra ID icon

CONNECT APP

Build with Microsoft Entra ID

Safeguard your organization with a cloud identity and access management solution that connects employees, customers, and partners to their apps, devices, and data.

Security

  • OAuth

MCP

Give your agent Microsoft Entra ID tools

Every Microsoft Entra ID action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Microsoft Entra ID account for each tool call — you store no tokens.

// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": "{project_id}",
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "microsoft_entra_id",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// e.g. run Add Member To Group:
const result = await mcp.callTool({
  name: "microsoft_entra_id-add-member-to-group",
  arguments: {
    groupId: "Group",
    userId: "User",
  },
})

API PROXY

Call the Microsoft Entra ID API directly

For an endpoint with no pre-built tool, the Connect proxy forwards your request to the Microsoft Entra ID API with the connected user's credentials attached. You store no tokens and write no refresh logic.

const resp = await pd.proxy.get({
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  accountId: "apn_xxxxxxx",
  url: "https://graph.microsoft.com/v1.0/me",
})

// Any allowed Microsoft Entra ID endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.

SDK

Run Microsoft Entra ID actions from your backend

Connect a user's Microsoft Entra ID account once, then run Add Member To Group on their behalf from your own code — TypeScript, Python, or plain HTTP.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "microsoft_entra_id-add-member-to-group",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    microsoft_entra_id: { authProvisionId: "apn_xxxxxxx" },
    groupId: "Group",
    userId: "User",
  },
})

TOOLS

Microsoft Entra ID actions

On-demand operations your product or agent can configure and run on behalf of a connected user.

EVENTS

Microsoft Entra ID triggers

Event sources your backend can deploy for users and receive through a webhook.

No Microsoft Entra ID triggers are available yet.

REFERENCE

App details

Reference metadata for the Microsoft Entra ID connector in the Pipedream registry.

App slug
microsoft_entra_id
Authentication
OAuth
Categories
Security
Actions
12
Triggers
0
API proxy
Available

OAuth scopes

These are the scopes Pipedream's managed Microsoft Entra ID OAuth client requests when one of your users connects an account. Supply your own OAuth client to request a different set.

  • openid
  • profile
  • email
  • offline_access
  • https://graph.microsoft.com/User.Read
  • https://graph.microsoft.com/User.ReadWrite
  • https://graph.microsoft.com/Directory.ReadWrite.All
  • https://graph.microsoft.com/Group.ReadWrite.All