Overview
The Microsoft Entra ID integration (formerly Azure Active Directory) connects to your Microsoft 365 tenant to collect identity and access management evidence for compliance controls. Evidence collected automatically:- User list with roles, licenses, and last sign-in
- MFA registration and enforcement status per user
- Conditional Access policy configuration
- Privileged role assignments (Global Admins, Security Admins)
- Guest user accounts and their access
- Risky sign-ins detected by Entra ID Protection
- Self-service password reset (SSPR) configuration
- Sign-in and audit logs summary
Prerequisites
- Microsoft Entra ID (Azure AD) tenant — included with Microsoft 365 Business or Enterprise plans
- Matproof Admin or Owner role
- Microsoft 365 Global Administrator account to authorize the connection
After initial authorization, Global Admin rights are not needed for ongoing evidence collection. Matproof uses the Microsoft Graph API with application permissions scoped to read-only directory and audit data.
Connecting Microsoft Entra ID
- Go to Settings → Integrations
- Click Connect next to Microsoft Entra ID / Azure AD
- Sign in with a Global Administrator Microsoft 365 account
- Review and grant the requested application permissions (admin consent required)
- Return to Matproof — the integration status will show Connected
Permissions Requested
Matproof registers an application in your Entra ID tenant with the following Microsoft Graph permissions (all read-only, application-level):What Gets Mapped to Which Controls
Conditional Access
Matproof evaluates your Conditional Access policies and reports whether they cover the key scenarios compliance frameworks care about:
Policies that are in Report-only mode are shown but do not count as implemented controls — they must be in Enabled state.
Privileged Role Monitoring
Matproof tracks all users assigned to privileged Entra ID roles:- Global Administrator
- Security Administrator
- Exchange Administrator
- SharePoint Administrator
- User Administrator
- Privileged Role Administrator