Integrating with Microsoft allows a full data transfer and removes any manual error since the data is synced automatically once a day from Shapes.
Set up an App Registration in Microsoft Entra
In the Microsoft Entra admin center, go to "App registrations"
In the "App registrations" tab, create a "New registration"
Fill out the name, leave the rest as default and click "Register"
Make a note of your Application (client) ID and Directory (tenant) ID - you will need these later when integrating from the Shapes side
Go to the "Certificates & Secrets" tab
Click on "New client secret"
Fill out the description and expiration (note the expiration will need to be replaced manually). Click "Add" and make a note of your secret value (also required when integrating from the Shapes side)
Under the "API permissions" tab, click on "Add a permission"
Click on "Application permissions"
Check the boxes called User.Read.All, User.ReadWrite.All and User-Phone.ReadWrite.All, and click on "Add permissions"
Repeat the process for Directory.Read.All and Directory.ReadWrite.All
In the configured permissions, click "Grant admin consent for Shapes"
The status is now changed to granted and you have the permissions!
All Super Admins can integrate data from Shapes with Microsoft Azure.
Connect the integration from Shapes
Enter Shapes' account settings -> Integrations -> Microsoft
Click on the "Connect" button
Fill out the Directory (tenant) ID, Application (client) ID and Secret Value, and click "Connect"
What data from Shapes is automatically synced to EntraID?
Shapes Field name | EntraID Field name |
Email address | userPrincipalName, mailNickname |
First name | givenName |
Last name | surname |
Job | jobTitle |
Phone number | mobilePhone |
Team | Department |
Reports to | manager |
First name +last name | displayname |
Office | Office |
Editing the field mapping
See Editing a Field Mapping in Integrations Overview for how to edit this mapping yourself. Applying specific sync filters still requires Shapes Support.
Microsoft Entra sync settings
The Settings step of the Microsoft integration controls how the sync behaves: when accounts are activated and deactivated, and whether Shapes creates new users. These settings don't change which fields are synced - that's handled by the field mapping above.
To find them, go to Shapes' account settings -> Integrations -> Microsoft, and open step 3, Settings.
Activate accounts on a date field
By default, Shapes creates new Microsoft Entra accounts disabled (Entra's Account Enabled value is set to false), so new hires can't sign in before they start.
Select a Shapes date field - for most companies, the employee's start date - and Shapes enables the account on that date (Account Enabled goes from false to true), so it's ready on their first day.
Note: If no field is selected, or the selected field is empty for an employee, their account stays disabled until an admin enables it manually in Microsoft Entra.
Deactivate accounts using a date field
By default, Shapes deactivates the Microsoft Entra account when the employee is terminated in Shapes.
To deactivate on a specific date instead - for example, the employee's Last Working Day - select a date field. Only date fields can be selected.
Important: While a date field is selected, terminating an employee in Shapes no longer deactivates their account. An employee with no date in the selected field keeps their Microsoft Entra account.
Never create new users
Turn this on if you only want Shapes to update and deactivate users who already exist in Microsoft Entra. Shapes won't create any new accounts, and employees without a matching Microsoft Entra user are skipped.
Troubleshooting: Provisioning Fails Silently
Most common provisioning trap: Microsoft Entra requires a usage location to be set on new users before licenses can be assigned. If this isn't configured, provisioning can fail without a visible error — the employee simply never shows up in Entra, with nothing in Shapes flagging why. If a new hire isn't appearing in Entra after being created in Shapes, this is the first thing to check with your Microsoft admin.

















