CONNECT APP
Build with Microsoft Entra ID
Security
- OAuth
MCP
Give your agent Microsoft Entra ID tools
Every Microsoft Entra ID action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Microsoft Entra ID account for each tool call — you store no tokens.
// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "microsoft_entra_id",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// e.g. run Add Member To Group:
const result = await mcp.callTool({
name: "microsoft_entra_id-add-member-to-group",
arguments: {
groupId: "Group",
userId: "User",
},
})# access_token: mint a short-lived token with the Connect SDK — see the MCP guide
headers = {
"Authorization": f"Bearer {access_token}",
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", # any stable ID for this user in your system
"x-pd-app-slug": "microsoft_entra_id",
}
async with streamablehttp_client("https://remote.mcp.pipedream.net/v3", headers=headers) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
# e.g. run Add Member To Group:
result = await session.call_tool("microsoft_entra_id-add-member-to-group", {
"groupId": "Group",
"userId": "User",
})API PROXY
Call the Microsoft Entra ID API directly
For an endpoint with no pre-built tool, the Connect proxy forwards your request to the Microsoft Entra ID API with the connected user's credentials attached. You store no tokens and write no refresh logic.
const resp = await pd.proxy.get({
externalUserId: "{external_user_id}", // any stable ID for this user in your system
accountId: "apn_xxxxxxx",
url: "https://graph.microsoft.com/v1.0/me",
})
// Any allowed Microsoft Entra ID endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.# The path segment is the target URL, URL-safe base64 encoded:
# https://graph.microsoft.com/v1.0/me
curl "https://api.pipedream.com/v1/connect/{project_id}/proxy/aHR0cHM6Ly9ncmFwaC5taWNyb3NvZnQuY29tL3YxLjAvbWU?external_user_id={external_user_id}&account_id=apn_xxxxxxx" \
-H "Authorization: Bearer {access_token}" \
-H "x-pd-environment: production"SDK
Run Microsoft Entra ID actions from your backend
Connect a user's Microsoft Entra ID account once, then run Add Member To Group on their behalf from your own code — TypeScript, Python, or plain HTTP.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "microsoft_entra_id-add-member-to-group",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
microsoft_entra_id: { authProvisionId: "apn_xxxxxxx" },
groupId: "Group",
userId: "User",
},
})from pipedream import Pipedream
pd = Pipedream(
client_id="{oauth_client_id}",
client_secret="{oauth_client_secret}",
project_id="{project_id}",
project_environment="production",
)
result = pd.actions.run(
id="microsoft_entra_id-add-member-to-group",
external_user_id="{external_user_id}", # any stable ID for this user in your system
configured_props={
"microsoft_entra_id": {"authProvisionId": "apn_xxxxxxx"},
"groupId": "Group",
"userId": "User",
},
)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "microsoft_entra_id-add-member-to-group",
"configured_props": {
"microsoft_entra_id": { "authProvisionId": "apn_xxxxxxx" },
"groupId": "Group",
"userId": "User"
}
}'TOOLS
Microsoft Entra ID actions
On-demand operations your product or agent can configure and run on behalf of a connected user.
-
Add Member To Group
actionAdds a member to a group Microsoft Entra ID. See the documentationWritev0.0.7 -
Create Group
actionCreates a new group in Microsoft Entra ID. See the documentationWritev0.0.1 -
Delete Group
actionDeletes a group in Microsoft Entra ID. See the documentationWritev0.0.1 -
Get Manager
actionGet the user's manager information. Returns the user or organizational contact assigned as the user's manager. See the documentationRead-onlyv0.0.2 -
Get MS365 Groups
actionGet the user's Microsoft 365 groups (unified groups). Returns groups the user is a direct member of. See the documentationRead-onlyv0.0.2 -
Get Organization Groups
actionList all groups in the organization (excluding dynamic distribution groups). See the documentationRead-onlyv0.0.2 -
Get Organization Users
actionList all users in the organization. By default returns only enabled accounts. See the documentationRead-onlyv0.0.4 -
Get Profile
actionGet the user's profile information. Returns the signed-in user's profile by default. See the documentationRead-onlyv0.0.2 -
Remove Member From Group
actionRemoves a member from a group Microsoft Entra ID. See the documentationWritev0.0.7 -
Search Groups
actionSearches for groups by name or description. See the documentationRead-onlyv0.0.8 -
Update Group
actionUpdates an existing group in Microsoft Entra ID. See the documentationWritev0.0.1 -
Update User
actionUpdates an existing user in Microsoft Entra ID. See the documentationWritev0.0.8
EVENTS
Microsoft Entra ID triggers
Event sources your backend can deploy for users and receive through a webhook.
No Microsoft Entra ID triggers are available yet.
MULTI-APP
Use Microsoft Entra ID with other popular apps
Most products don't stop at one integration. Pair Microsoft Entra ID with the other apps your users rely on, and ship use cases that span both.
REFERENCE
App details
Reference metadata for the Microsoft Entra ID connector in the Pipedream registry.
- App slug
- microsoft_entra_id
- Authentication
- OAuth
- Categories
- Security
- Actions
- 12
- Triggers
- 0
- API proxy
- Available
OAuth scopes
These are the scopes Pipedream's managed Microsoft Entra ID OAuth client requests when one of your users connects an account. Supply your own OAuth client to request a different set.
- openid
- profile
- offline_access
- https://graph.microsoft.com/User.Read
- https://graph.microsoft.com/User.ReadWrite
- https://graph.microsoft.com/Directory.ReadWrite.All
- https://graph.microsoft.com/Group.ReadWrite.All