About this integration
Manage Microsoft Entra ID users, groups, and directory objects via Graph.
There are 3 triggers, 6 search modules and 11 actions available. The integration connects via oauth or oauth authentication.
How to connect
The credential form asks for Microsoft - Tenant, Microsoft - Client ID, Microsoft - Client Secret, and Microsoft - Tenant.
OAuth asks you to approve User.Read, User.ReadBasic.All, and User.Read.All before access is granted.
Sign in and approve access — your password is never shared with WEXTL®, and you can revoke access from the provider at any time.
You’ll be redirected to sign in and approve access — your password is never shared with WEXTL.
You’ll be redirected to sign in and approve access — your password is never shared with WEXTL.
Connecting Microsoft Entra ID to WEXTL®
| Field | Type | Help |
|---|---|---|
Microsoft - TenantRequired | select | Go to |
Microsoft - Client IDRequired | text | Register your application in the Microsoft Entra admin center, then copy the Application (client) ID from the app's Overview page |
Microsoft - Client SecretRequired | password | In your app registration, go to Certificates & secrets → Client secrets, create a new client secret, and copy its value immediately after it's generated. |
- User.Read
- User.ReadBasic.All
- User.Read.All
- User.ReadWrite
- User.ReadWrite.All
- User.Export.All
- User.Invite.All
- User.EnableDisableAccount.All
- User.DeleteRestore.All
- User-Mail.Read
- User-Mail.ReadWrite.All
- User-Phone.ReadWrite.All
- User-PasswordProfile.ReadWrite.All
- Directory.Read.All
- Directory.ReadWrite.All
- Group.Read.All
- Group.ReadWrite.All
- GroupMember.Read.All
- GroupMember.ReadWrite.All
- Group.Create
- Group.SelectedPermissions.Read.All
- Group.SelectedPermissions.ReadWrite.All
- Application.Read.All
- Application.ReadWrite.All
- Application.ReadWrite.OwnedBy
- Application-RemoteDesktopConfig.ReadWrite.All
- AppRoleAssignment.ReadWrite.All
| Field | Type | Help |
|---|---|---|
Microsoft - TenantRequired | select | Go to |
Microsoft - Client IDRequired | text | Go to the Microsoft Entra admin center → Entra ID → App registrations and select New registration. → enter a description and expiration → Add, then immediately copy your Client ID |
Microsoft - Client SecretRequired | password | Copy you client Secret from the previously created app |
- User.Read
- User.ReadBasic.All
- User.Read.All
- User.ReadWrite
- User.ReadWrite.All
- User.Export.All
- User.Invite.All
- User.EnableDisableAccount.All
- User.DeleteRestore.All
- User-Mail.Read
- User-Mail.ReadWrite.All
- User-Phone.ReadWrite.All
- User-PasswordProfile.ReadWrite.All
- Directory.Read.All
- Directory.ReadWrite.All
- Group.Read.All
- Group.ReadWrite.All
- GroupMember.Read.All
- GroupMember.ReadWrite.All
- Group.Create
- Group.SelectedPermissions.Read.All
- Group.SelectedPermissions.ReadWrite.All
- Application.Read.All
- Application.ReadWrite.All
- Application.ReadWrite.OwnedBy
- Application-RemoteDesktopConfig.ReadWrite.All
- AppRoleAssignment.ReadWrite.All
Use it in workflow automation
Start with Watch Applications, then add Change a User Password.
The canvas below runs Watch Applications into Change a User Password — watch the video, then drop a node onto the canvas.
Select the Watch Users trigger and the workflow fires automatically when the event occurs — no polling required.
Then add Change a User Password as the next node. Branch, filter, or hand off to other integrations from there.
The integration includes 14 ready-made modules for developer tools work — each run logs its inputs and outputs for debugging.
Microsoft Entra ID workflow on the canvas: Watch Users then Change a User Password
Triggers, searches and actions
Open any Microsoft Entra ID trigger, search, or action to see its inputs and outputs — 3 triggers, 6 searchs, 11 actions.
Triggers
Use one of 3 triggers to kick off a workflow as soon as an event occurs in the app.
- Watch Applications
- Watch Groups
- Watch Users
Searches
This integration includes 6 search modules for looking data up mid-run.
- List Applications
- List Groups
- List Users
- Retrieve a Group
- Retrieve an Application
Actions
Take action during a run with 11 available modules that write data back into the app.
- Change a User Password
- Create a Group
- Create an Application
- Create a User
- Delete a Group
Explore the fields available for each Microsoft Entra ID trigger, search, and action.
Triggers
| Field | Type |
|---|---|
Add ins | array |
API | object |
@odata type | text |
App ID | text |
Application template ID | text |
App roles | array |
Authentication behaviors | object |
@odata type | text |
Certification | object |
@odata type | text |
Created date time | date |
Created by app ID | text |
Deleted date time | date |
Disabled by microsoft status | text |
Display name | text |
Group membership claims | text |
ID | text |
Identifier uris | array |
Info | object |
@odata type | text |
Is device only auth supported | boolean |
Is disabled | text |
Is fallback public client | boolean |
Key credentials | array |
| Field | Type |
|---|---|
ID | text |
Deleted date time | date |
Classification | text |
Created date time | date |
Description | text |
Display name | text |
Expiration date time | date |
Group types | array |
Is assignable to role | text |
Mail | |
Mail enabled | boolean |
Mail nickname | text |
Membership rule | text |
Membership rule processing state | text |
On premises last sync date time | text |
On premises security identifier | text |
On premises sync enabled | text |
Preferred data location | text |
Preferred language | text |
Proxy addresses | array |
| Field | Type |
|---|---|
About me | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | object |
@odata type | text |
Birthday | date |
Business phones | array |
City | text |
Cloud licensing | object |
@odata type | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Custom security attributes | object |
@odata type | text |
Deleted date time | date |
Department | text |
Display name | text |
Searches
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
Add ins | array |
API | object |
@odata type | text |
App ID | text |
Application template ID | text |
App roles | array |
Authentication behaviors | object |
@odata type | text |
Certification | object |
@odata type | text |
Created date time | date |
Created by app ID | text |
Deleted date time | date |
Disabled by microsoft status | text |
Display name | text |
Group membership claims | text |
ID | text |
Identifier uris | array |
Info | object |
@odata type | text |
Is device only auth supported | boolean |
Is disabled | text |
Is fallback public client | boolean |
Key credentials | array |
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
ID | text |
Deleted date time | date |
Classification | text |
Created date time | date |
Description | text |
Display name | text |
Expiration date time | date |
Group types | array |
Is assignable to role | text |
Mail | |
Mail enabled | boolean |
Mail nickname | text |
Membership rule | text |
Membership rule processing state | text |
On premises last sync date time | text |
On premises security identifier | text |
On premises sync enabled | text |
Preferred data location | text |
Preferred language | text |
Proxy addresses | array |
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
About me | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | object |
@odata type | text |
Birthday | date |
Business phones | array |
City | text |
Cloud licensing | object |
@odata type | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Custom security attributes | object |
@odata type | text |
Deleted date time | date |
Department | text |
Display name | text |
| Field | Type |
|---|---|
Group IDRequired | choice |
| Field | Type |
|---|---|
ID | text |
Deleted date time | date |
Classification | text |
Created date time | date |
Description | text |
Display name | text |
Expiration date time | date |
Group types | array |
Is assignable to role | text |
Mail | |
Mail enabled | boolean |
Mail nickname | text |
Membership rule | text |
Membership rule processing state | text |
On premises last sync date time | text |
On premises security identifier | text |
On premises sync enabled | text |
Preferred data location | text |
Preferred language | text |
Proxy addresses | array |
| Field | Type |
|---|---|
Application Object IDRequired | choice |
| Field | Type |
|---|---|
@odata context | text |
ID | text |
Deleted date time | date |
Is fallback public client | text |
App ID | text |
Application template ID | text |
Identifier uris | array |
Created date time | date |
Display name | text |
Is device only auth supported | text |
Group membership claims | text |
Optional claims | text |
Add ins | array |
Publisher domain | text |
Saml metadata URL | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
App roles | array |
| Field | Type |
|---|---|
User Principal NameRequired | choice |
| Field | Type |
|---|---|
About me | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | object |
@odata type | text |
Birthday | date |
Business phones | array |
City | text |
Cloud licensing | object |
@odata type | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Custom security attributes | object |
@odata type | text |
Deleted date time | date |
Department | text |
Display name | text |
Actions
| Field | Type |
|---|---|
User Principal NameRequired | choice |
Current PasswordRequired | text |
New PasswordRequired | text |
| Field | Type |
|---|---|
Display NameRequired | text |
Mail Nickname | text |
Security Enabled | boolean |
Visibility | choice |
Allow External Senders | boolean |
Auto Subscribe New Members | boolean |
Welcome Message Enabled | boolean |
Description | text |
Preferred Data Location | text |
Unique Name | text |
Assigned Labels | array |
Writeback Configuration | object |
Is Enabled | boolean |
On Premises Group Type | choice |
| Field | Type |
|---|---|
ID | text |
Deleted date time | date |
Classification | text |
Created date time | date |
Description | text |
Display name | text |
Expiration date time | date |
Group types | array |
Is assignable to role | text |
Mail | |
Mail enabled | boolean |
Mail nickname | text |
Membership rule | text |
Membership rule processing state | text |
On premises last sync date time | text |
On premises security identifier | text |
On premises sync enabled | text |
Preferred data location | text |
Preferred language | text |
Proxy addresses | array |
| Field | Type |
|---|---|
Display NameRequired | text |
Sign-In AudienceRequired | choice |
Sign-In Audience Restrictions | object |
Is Home Tenant AllowedRequired | boolean |
Allowed Tenant IDsRequired | array |
Password Credentials | array |
| Field | Type |
|---|---|
@odata context | text |
ID | text |
Deleted date time | date |
Is fallback public client | text |
App ID | text |
Application template ID | text |
Identifier uris | array |
Created date time | date |
Display name | text |
Is device only auth supported | text |
Group membership claims | text |
Optional claims | text |
Add ins | array |
Publisher domain | text |
Saml metadata URL | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
App roles | array |
| Field | Type |
|---|---|
User Principal NameRequired | text |
Password ProfileRequired | object |
Force Change Password Next Sign-In | boolean |
Password | text |
Account EnabledRequired | boolean |
Display NameRequired | text |
Mail Nickname | text |
On-Premises Immutable ID | text |
Identity Parent ID | text |
| Field | Type |
|---|---|
About me | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | object |
@odata type | text |
Birthday | date |
Business phones | array |
City | text |
Cloud licensing | object |
@odata type | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Custom security attributes | object |
@odata type | text |
Deleted date time | date |
Department | text |
Display name | text |
| Field | Type |
|---|---|
Group IDRequired | choice |
| Field | Type |
|---|---|
Application Object IDRequired | choice |
| Field | Type |
|---|---|
User Principal NameRequired | choice |
| Field | Type |
|---|---|
URLRequired | text |
MethodRequired | choice |
Headers | array |
Header | object |
Query String | array |
Parameter | object |
Body | text |
| Field | Type |
|---|---|
Body | text |
Headers | object |
Status code | number |
| Field | Type |
|---|---|
Group IDRequired | choice |
Display Name | text |
Mail Nickname | text |
Security Enabled | boolean |
Visibility | choice |
Allow External Senders | boolean |
Auto Subscribe New Members | boolean |
Welcome Message Enabled | boolean |
Description | text |
Preferred Data Location | text |
Unique Name | text |
Assigned Labels | array |
Writeback Configuration | object |
Is Enabled | boolean |
On Premises Group Type | choice |
| Field | Type |
|---|---|
ID | text |
Deleted date time | date |
Classification | text |
Created date time | date |
Description | text |
Display name | text |
Expiration date time | date |
Group types | array |
Is assignable to role | text |
Mail | |
Mail enabled | boolean |
Mail nickname | text |
Membership rule | text |
Membership rule processing state | text |
On premises last sync date time | text |
On premises security identifier | text |
On premises sync enabled | text |
Preferred data location | text |
Preferred language | text |
Proxy addresses | array |
| Field | Type |
|---|---|
Application Object IDRequired | choice |
Display Name | text |
Sign-In Audience | choice |
Sign-In Audience Restrictions | object |
Is Home Tenant Allowed | boolean |
Allowed Tenant IDs | array |
Password Credentials | array |
| Field | Type |
|---|---|
@odata context | text |
ID | text |
Deleted date time | date |
Is fallback public client | text |
App ID | text |
Application template ID | text |
Identifier uris | array |
Created date time | date |
Display name | text |
Is device only auth supported | text |
Group membership claims | text |
Optional claims | text |
Add ins | array |
Publisher domain | text |
Saml metadata URL | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
App roles | array |
| Field | Type |
|---|---|
User Principal NameRequired | choice |
Account Enabled | boolean |
Display Name | text |
Password Profile | object |
Password | text |
Force Change Password Next Sign-In | boolean |
Force Change Password Next Sign-In with MFA | boolean |
Usage Location | text |
User Principal Name | |
Age Group | choice |
Assigned Licenses | array |
Birthday | date |
Business Phones | array |
Phone Number | text |
City | text |
Company Name | text |
Consent Provided For Minor | choice |
Country | text |
Department | text |
Employee ID | text |
Employee Type | text |
Given Name | text |
Employee Hire Date | date |
Employee Leave Date Time | date |
| Field | Type |
|---|---|
About me | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | object |
@odata type | text |
Birthday | date |
Business phones | array |
City | text |
Cloud licensing | object |
@odata type | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Custom security attributes | object |
@odata type | text |
Deleted date time | date |
Department | text |
Display name | text |



