---
title: Microsoft Entra ID Setup Guide
description: Single sign-on, user sync and email notifications
---

[Skip to content](https://learn.intranetconnections.com/microsoft-entra-id-setup-guide#main-content)

![New White Logo-1](https://learn.intranetconnections.com/hs-fs/hubfs/New%20White%20Logo-1.png?width=200&height=58&name=New%20White%20Logo-1.png)

Open main navigation

Close main navigation

- [Contact Support](mailto:support@intranetconnections.com)

[Contact Support](mailto:support@intranetconnections.com)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [IC Knowledge Hub](https://learn.intranetconnections.com/?hsLang=en-ca)
2. [Technical Setup & Configuration](https://learn.intranetconnections.com/technical-setup-configuration?hsLang=en-ca)
3. [Advanced Configuration](https://learn.intranetconnections.com/technical-setup-configuration?hsLang=en-ca#advanced-configuration)

# Microsoft Entra ID Setup Guide

## Single sign-on, user sync, and email notifications

### Overview

Intranet Connections 3 (IC3) connects to your Microsoft 365 tenant through an **app registration** in Microsoft Entra ID (formerly Azure Active Directory). Once it's set up, IC3 can:

- Let staff sign in with their Microsoft work account (single sign-on).
- Keep the employee directory up to date by syncing users, groups and group memberships.
- Show SharePoint and OneDrive files that each user can already access.
- Send notification email through Microsoft 365.
- Optionally, bring Outlook calendar events into the IC3 events calendar.

IC3's access is read-only, except for sending email.

Setup has two stages:

1. **Create the app registration in Entra ID** (Part 1). You can do this by hand in the Azure portal, or with the setup script provided by Intranet Connections.
2. **Connect IC3 to it** (Parts 2 to 6).

Before you begin

| **You need** | **Why** |
| --- | --- |
| A Microsoft 365 administrator with the Global Administrator or Privileged Role Administrator role | Only these roles can grant admin consent for the permissions IC3 uses. |
| An IC3 administrator account | To enter the connection details and set up sync and email in IC3. |
| Your IC3 API address, for example [https://intranet-api.example.com](https://intranet-api.example.com) | It's used for the sign-in redirect address. Your Intranet Connections contact can confirm it. |
| Access to IIS on the IC3 web server | Needed once during setup, to restart the two IC3 application pools. If Intranet Connections hosts your intranet, Intranet Connections Support will do this for you. |
| An Entra ID group containing the staff who should appear in IC3, for example Intranet Users | IC3 syncs the members of this group into the employee directory. If you don't have one, create it in Entra ID before you start, or let the setup script create it (Part 1, Option B). |
| A decision on whether you want calendar sync | Calendar sync is optional. |

### Part 1: Create the app registration

Choose **one** of the two options below.

Option A: Create it in the Azure portal

#### A1. Register the application

1. Sign in to the **Microsoft Entra admin center** ([https://entra.microsoft.com](https://entra.microsoft.com)) or the **Azure portal** ([https://portal.azure.com](https://portal.azure.com)).
2. Go to **Microsoft Entra ID \> App registrations** and select **New registration**.
3. Enter a name, for example **\[Organization Name\] Intranet Connections**.
4. Under **Supported account types**, leave **Accounts in this organizational directory only** selected.
5. Under **Redirect URI**, select **Web** and enter your IC3 API address followed by /signin-oidc, for example [https://intranet-api.example.com/signin-oidc](https://intranet-api.example.com/signin-oidc).
6. Select **Register**.
7. On the **Overview** page, copy the **Application (client) ID** and the **Directory (tenant) ID**.

#### A2. Create a client secret

Treat the client secret like a password. Store it securely and don't send it by email, include it in support screenshots, or save it in documentation or ticket notes.

1. Select **Certificates & secrets \> Client secrets \> New client secret**.
2. Enter a description, choose **730 days (24 months)** or your organization's preferred lifetime, and select **Add**.
3. Copy the secret's **Value** straight away. It's only shown once. Make a note of the expiry date (see Maintaining the integration).

#### A3. Add API permissions

1. Select **API permissions \> Add a permission \> Microsoft Graph**.
2. Select **Application permissions**, find and tick each **Application** permission in the table below, then select **Add permissions**.
3. Repeat with **Delegated permissions** for each **Delegated** permission.

| **Permission** | **Type** | **Required?** |
| --- | --- | --- |
| User.Read.All | Application | Yes |
| GroupMember.Read.All | Application | Yes |
| Member.Read.Hidden | Application | Yes |
| Mail.Send | Application | Yes |
| Directory.Read.All | Application | Yes |
| Calendars.Read | Application | Only for Office 365 calendar sync |
| openid | Delegated | Yes |
| profile | Delegated | Yes |
| email | Delegated | Yes |
| offline\_access | Delegated | Yes |
| User.Read | Delegated | Yes |
| Group.Read.All | Delegated | Yes |
| Sites.Read.All | Delegated | Yes |
| Files.Read | Delegated | Yes |

Select **Grant admin consent for \[your organization\]** and confirm. Every permission should now show a green check mark and **Granted for \[your organization\]**.

**Security note:** Mail.Send is an application permission and, when granted through Microsoft Graph, permits IC3 to send mail without a signed-in user. If your organization requires IC3's email access to be restricted to a specific mailbox, your Exchange administrator can use RBAC for Applications in Exchange Online. See Part 5.

You should have **13 permissions**, or **14** with calendar sync. Appendix A explains what each one is used for.

Then continue with **Part 2**.

#### Option B: Use the setup script

The azure.ps1 script, provided by Intranet Connections, creates and configures the app registration, adds the permissions, grants admin consent and creates a client secret. It only creates new app registrations; it never changes or deletes existing ones.

1. Save azure.ps1 to a folder on a Windows 10 or 11 PC with internet access, for example C:\\IC3.
2. Open **Windows PowerShell** and go to that folder:
   
   ```
   cd C:\IC3
   ```
3. Run the script with your IC3 API address:
   
   ```
   .\azure.ps1 -ApiUrl https\://intranet-api.example.com
   ```

- **Recommended:** add -GroupName "Intranet Users" to create the group of staff to sync (or give the name of an existing group). The script adds you to it; add your staff afterwards.
- To include Office 365 calendar sync, add -EnableCalendarSync.
- See Appendix B for all options.

**If PowerShell says that running scripts is disabled**, run this instead:

```
powershell -ExecutionPolicy Bypass -File .\azure.ps1 -ApiUrl https\://intranet-api.example.com
```

1. When the browser opens, sign in with your Global Administrator or Privileged Role Administrator account.
2. Wait for the script to finish (usually a few minutes), then check the **Result** section at the end:

- **READY FOR IC3 CONFIGURATION**: the Microsoft side is done.
- **NOT READY - MANUAL ADMIN CONSENT REQUIRED**: see Troubleshooting.

1. Copy the **Tenant ID**, **Client ID** and **Client Secret** from the summary. They're also saved in ic3\_azure\_credentials.txt in the same folder. Delete that file once you've entered the values in IC3 (Part 2), because it contains the client secret.

If the Azure CLI isn't installed on the PC, the script installs it first. This needs local administrator rights on the PC.

Then continue with **Part 2**.

### Part 2: Turn on Microsoft single sign-on in IC3

1. Sign in to IC3 as an administrator and turn on **Admin Mode**.
2. Go to **Security & Permissions \> Login Authentication**.
3. On the **Microsoft Single Sign-On (SSO)** row, select **Configure**.
4. Turn on **Enable Azure Single Sign On (SSO) as a login provider**.
5. Enter the **Tenant ID**, **Client ID** and **Client secret** from Part 1.
6. Select **Test connection**. When **Connection Successful** appears, select **Confirm**.

**SharePoint integration** is on by default, so users can browse and embed SharePoint content in IC3. Turn it off in the same window if you don't want this. IC3 also uses these connection details to send email through Microsoft 365 (Part 5).

### Part 3: Set up user synchronization

1. Go to **System Config \> Synchronization**.
2. Select **Add Connection \> Azure**. (Azure is only available once single sign-on is turned on in Part 2.)
3. On the **Azure connection** page, fill in:

- **Task name**: any name, for example Azure Sync.
- **Sync from group**: the Entra ID group or groups whose members should appear in your employee directory. **Always choose a group.**
- **Sync frequency**: how often IC3 syncs automatically.
- **Default department**: used for users who have no department in Entra ID.

1. Review **Field mapping**, which shows which Entra ID attribute fills each IC3 profile field.
2. Select **Start Syncing**. IC3 saves the settings and returns to the Login Authentication page.

**Don't leave Sync from group empty.** If no group is selected, IC3 syncs every account in your directory, including guests, service accounts and the accounts behind shared mailboxes and meeting rooms, and they all appear in your employee directory.

IC3 finds sync groups **by name**. Don't rename a sync group in Entra ID, or create another group with the same name, without updating IC3.

### Part 4: Restart IC3, run the first sync and test

1. Restart the two IC3 application pools in IIS: instancename and instancename-api, where instancename is the name of your intranet instance (for example, contoso and contoso-api). In **IIS Manager**, select **Application Pools**, then select each pool and choose **Recycle** (or **Stop**, then **Start**). IC3 reads the sign-in settings and the sync schedule only when it starts, so this step is required. If Intranet Connections hosts your intranet, contact Intranet Connections Support.
2. In IC3, go to **System Config \> Task Manager** and select **Execute** on **Azure User Sync Task**.
3. When the task has finished, check that your users appear in the employee directory.
4. Sign out, then sign in with Microsoft using a **non-administrator** account that was included in the sync. The user should sign in without a consent or "Need admin approval" prompt.

Users can only sign in with Microsoft once the sync has added them to IC3.

### Part 5: Set up email notifications

1. Go to **System Config \> Email Set-up**.
2. Under **Select Email Delivery Method**, choose **Azure**.
3. In **Sender Email Address**, enter a mailbox in your Microsoft 365 tenant, such as a licensed user or a shared mailbox (for example [intranet@example.com](mailto:intranet@example.com)).
4. Select **SEND ME TEST EMAIL** to check delivery, then select **SAVE**.

The Mail.Send permission allows sending as any mailbox in the tenant. To limit IC3 to its sender mailbox, your Exchange administrator can use **RBAC for Applications** in Exchange Online.

### Part 6 (optional): Office 365 calendar sync

Calendar sync needs the **Calendars.Read** permission. If you chose calendar sync in Part 1 (you added Calendars.Read in step A3, or ran the script with -EnableCalendarSync), it's already in place: skip to **Turn on calendar sync in IC3**.

**Add the Calendars.Read permission (if you didn't in Part 1)**

1. In the Microsoft Entra admin center, go to **Microsoft Entra ID \> App registrations** and open the app registration you created in Part 1.
2. Select **API permissions \> Add a permission \> Microsoft Graph \> Application permissions**.
3. Find and tick **Calendars.Read**, then select **Add permissions**.
4. Select **Grant admin consent for \[your organization\]** and confirm. Calendars.Read should show **Granted for \[your organization\]**.

### Turn on calendar sync in IC3

1. Go to **Security & Permissions \> Login Authentication**.
2. Under **Microsoft Single Sign-On (SSO)**, open the menu on the **Directory sync** line and select **Manage Calendar Sync**.
3. On **Manage Synced Calendars**, choose the **Event Calendar** and use **Sync Config** to choose whose calendars to sync.

### Maintaining the integration

| **Task** | **How** |
| --- | --- |
| Renew the client secret before it expires (24 months by default) | In the Entra admin center, open App registrations \> \[your app\] \> Certificates & secrets and create a new client secret. Enter the new value in IC3 (Part 2, steps 2 to 6), then delete the old secret. If the secret expires, sign-in, sync and email stop working. |
| Add calendar sync later | Follow Part 6. It covers adding the Calendars.Read permission to your existing app registration. |
| Add another IC3 site to the same app registration | Add the site's redirect URI (its API address followed by /signin-oidc) under Authentication \> Web. |
| Change who is synced | Change the group in IC3 (System Config \> Synchronization), or change the group's members in Entra ID. |

### Troubleshooting

| **What you see** | **What to do** |
| --- | --- |
| Script: "An app named ... already exists. Nothing was changed." | Use a different name with -AppName. If the app was left by an earlier run that didn't finish, delete it in Entra ID \> App registrations and run the script again. |
| Script: "More than one group named ... exists." | Use a unique name with -GroupName. Nothing was created. |
| Script: "NOT READY - MANUAL ADMIN CONSENT REQUIRED" | The account that signed in isn't a Global Administrator or Privileged Role Administrator. Ask one to open the app in Entra ID \> App registrations \> API permissions and select Grant admin consent. |
| "Connection Failed" when testing the connection in IC3 | Check the Tenant ID, Client ID and Client secret. Make sure you copied the secret's Value, not its Secret ID. |
| Users see "Need admin approval" when signing in | Admin consent is missing for one or more permissions. Select Grant admin consent under API permissions. |
| Single sign-on doesn't work after setup | Restart both IC3 application pools, instancename and instancename-api (Part 4, step 1). |
| A user can't sign in with Microsoft | The user hasn't been synced yet. Check they're in the sync group, then run Azure User Sync Task in Task Manager. |
| Calendar sync shows no users | Check that Calendars.Read (Application) has been added and admin consent granted. |
| The test email fails | Check that the sender is a real mailbox in your tenant and that Mail.Send (Application) has admin consent. |

### Appendix A: Permissions reference

**Application** permissions are used by IC3's server for background tasks (sync and email), with no user signed in. **Delegated** permissions are used on behalf of the signed-in user, who only ever sees what they already have access to.

 

| **Permission** | **Type** | **Used by IC3 for** |
| --- | --- | --- |
| User.Read.All | Application | User sync (profiles, managers, photos) and listing users for calendar sync |
| GroupMember.Read.All | Application | Group and group-member sync |
| Member.Read.Hidden | Application | Syncing members of groups with hidden membership |
| Mail.Send | Application | Sending notification email from the sender mailbox |
| Directory.Read.All | Application | Reading directory data during user and group sync |
| Calendars.Read (optional) | Application | Office 365 calendar sync into the events calendar |
| openid, profile, email | Delegated | Signing users in |
| offline\_access | Delegated | Keeping users signed in (refresh tokens) |
| User.Read | Delegated | Signing in and reading the signed-in user's profile |
| Group.Read.All | Delegated | Reading groups during sign-in |
| Sites.Read.All | Delegated | Documents app, SharePoint browser and search: sites and files the user can access |
| Files.Read | Delegated | The signed-in user's own OneDrive files |

If your app registration was created with an older Intranet Connections script, it may also have **Mail.Read** (Delegated), **Group.Read.All** (Application), **Files.Read.All** (Delegated) or **Mail.Send** (Delegated). IC3 doesn't use these. You can remove them under **API permissions**, then select **Grant admin consent** again.

IC3 uses the standard sign-in flow, so **implicit grant** (the Access tokens and ID tokens options under **Authentication**) doesn't need to be turned on.

### Appendix B: Setup script options

| **Option** | **What it does** |
| --- | --- |
| -ApiUrl (required) | Your IC3 API address. The sign-in redirect URI is this address followed by /signin-oidc. |
| -EnableCalendarSync | Adds Calendars.Read for Office 365 calendar sync. Leave it out if you don't use calendar sync. |
| -GroupName "name" (recommended) | Creates this Entra ID group (or uses it if it already exists) and adds you to it. Add your staff to it, then choose it in Part 3 as the group to sync. |
| -AppName "name" | Name of the app registration. Default: intranetconnections3-app. |
| -SecretName "name" | Name of the client secret. Default: intranetconnections3-secret. |
| -SecretYears 1 or 2 | How long the client secret lasts. Default: 2 years. |
| -TenantId | Signs in to a specific tenant, for example contoso.onmicrosoft.com. Useful if your account can access more than one tenant. |
| -NoOwner | Don't make you an owner of the app registration. By default, the person who runs the script is the owner. |
| -OutputPath | Folder for ic3\_azure\_credentials.txt. Default: the current folder. |

- [FAQs](https://learn.intranetconnections.com/faqs?hsLang=en-ca#main-content)

    - [AI](https://learn.intranetconnections.com/faqs?hsLang=en-ca#ai)
- [Onboarding & Setup](https://learn.intranetconnections.com/onboarding-setup?hsLang=en-ca#main-content)

    - [Migration](https://learn.intranetconnections.com/onboarding-setup?hsLang=en-ca#migration)
    - [Theme & Design](https://learn.intranetconnections.com/onboarding-setup?hsLang=en-ca#theme-design)
    - [Installation](https://learn.intranetconnections.com/onboarding-setup?hsLang=en-ca#installation)
- [Product News](https://learn.intranetconnections.com/product-news?hsLang=en-ca#main-content)

    - [Release Notes](https://learn.intranetconnections.com/product-news?hsLang=en-ca#release-notes)
    - [Product Patches](https://learn.intranetconnections.com/product-news?hsLang=en-ca#product-patches)
- [Reports](https://learn.intranetconnections.com/reports?hsLang=en-ca#main-content)

    - [Intranet Analytics](https://learn.intranetconnections.com/reports?hsLang=en-ca#intranet-analytics)
- [Integrations](https://learn.intranetconnections.com/integrations?hsLang=en-ca#main-content)

    - [SharePoint](https://learn.intranetconnections.com/integrations?hsLang=en-ca#sharepoint)
    - [AI](https://learn.intranetconnections.com/integrations?hsLang=en-ca#ai)
- [Support](https://learn.intranetconnections.com/support?hsLang=en-ca)
- [Technical Setup & Configuration](https://learn.intranetconnections.com/technical-setup-configuration?hsLang=en-ca#main-content)

    - [Intranet Settings](https://learn.intranetconnections.com/technical-setup-configuration?hsLang=en-ca#intranet-settings)
    - [Disaster Recovery](https://learn.intranetconnections.com/technical-setup-configuration?hsLang=en-ca#disaster-recovery)
    - [Advanced Configuration](https://learn.intranetconnections.com/technical-setup-configuration?hsLang=en-ca#advanced-configuration)
- [How To's](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#main-content)

    - [Multilingual](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#multilingual)
    - [Navigation](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#navigation)
    - [Intranet Architecture](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#intranet-architecture)
    - [Security & Permissions](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#security-permissions)
    - [Private Cloud](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#private-cloud)
    - [Feature Requests](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#feature-requests)
    - [Forms & Workflows](https://learn.intranetconnections.com/how-tos?hsLang=en-ca#forms-workflows)
- [Best Practices](https://learn.intranetconnections.com/best-practices?hsLang=en-ca#main-content)

    - [Design](https://learn.intranetconnections.com/best-practices?hsLang=en-ca#design)
    - [Getting Started](https://learn.intranetconnections.com/best-practices?hsLang=en-ca#getting-started)
- [Applications](https://learn.intranetconnections.com/applications?hsLang=en-ca#main-content)

    - [Documents](https://learn.intranetconnections.com/applications?hsLang=en-ca#documents)
    - [Internal Resources](https://learn.intranetconnections.com/applications?hsLang=en-ca#internal-resources)
    - [Announcements](https://learn.intranetconnections.com/applications?hsLang=en-ca#announcements)
    - [Engagement](https://learn.intranetconnections.com/applications?hsLang=en-ca#engagement)
    - [Advertising](https://learn.intranetconnections.com/applications?hsLang=en-ca#advertising)
- [Security](https://learn.intranetconnections.com/security?hsLang=en-ca)
- [Widgets](https://learn.intranetconnections.com/widgets?hsLang=en-ca#main-content)

    - [What's New Feed](https://learn.intranetconnections.com/widgets?hsLang=en-ca#whats-new-feed)
    - [Content & Media Widgets](https://learn.intranetconnections.com/widgets?hsLang=en-ca#content-media-widgets)
    - [Engagement Widgets](https://learn.intranetconnections.com/widgets?hsLang=en-ca#engagement-widgets)

[![ic-chatbot-logo](https://learn.intranetconnections.com/hs-fs/hubfs/Logos%20and%20Icons/ic-chatbot-logo.png?width=100&height=100&name=ic-chatbot-logo.png "ic-chatbot-logo")](https://intranetconnections.com)

<https://www.linkedin.com/company/intranet-connections> <https://www.instagram.com/intranetconnections> <https://www.facebook.com/intranetconnections> <https://www.twitter.com/intranettips>

Copyright © 2025, Intranet Connections