Azure Entra IDP/HRIS Integration
If your organization uses Azure Entra as an Identity Provider, you can additionally designate it as an IDP/HRIS Integration. Doing so allows Opal to sync your Azure Entra identities and their attributes, on top of syncing and managing access to entitlements (e.g. Azure Entra Security Groups, Azure VMs, Azure DBs, etc).
Getting Started
Before you set up Azure Entra as your IDP, you must first create an Azure Entra App in Opal. To do this, please follow the instructions here.
Next, set up Azure Entra as your IDP by following instructions here:
data:image/s3,"s3://crabby-images/cc82f/cc82fadbbe2015273c4d8457fb262d63feed8e23" alt=""
Custom Attributes
Note: Opal only supports string
type Custom Security Attributes.
- Opal's Azure app must have the
CustomSecAttributeAssignment.ReadWrite.All
Application permission assigned.- Go to
App Registrations
. - In the sidebar, go to
API Permissions
and selectAdd a permission
. ChooseMicrosoft Graph
-> Application Permissions and addCustomSecAttributeAssignment.ReadWrite.All
- Go to
- Opal tags should have the format
<customAttributeSetName>.<attributeName>
. ex.Student.IsFallIntern
in order to properly match the Azure attributes. These are case-sensitive.
Updated 17 days ago