Integrating with Microsoft allows a full data transfer and removes any manual error since the data is synced automatically once a day from Shapes.
Set up an App Registration in Microsoft Entra
In the Microsoft Entra admin center, go to "App registrations"
In the "App registrations" tab, create a "New registration"
Fill out the name, leave the rest as default and click "Register"
Make a note of your Application (client) ID and Directory (tenant) ID - you will need these later when integrating from the Shapes side
Go to the "Certificates & Secrets" tab
Click on "New client secret"
Fill out the description and expiration (note the expiration will need to be replaced manually). Click "Add" and make a note of your secret value (also required when integrating from the Shapes side)
Under the "API permissions" tab, click on "Add a permission"
Click on "Application permissions"
Check the boxes called User.Read.All, User.ReadWrite.All and User-Phone.ReadWrite.All, and click on "Add permissions"
Repeat the process for Directory.Read.All and Directory.ReadWrite.All
In the configured permissions, click "Grant admin consent for Shapes"
The status is now changed to granted and you have the permissions!
All Super Admins can integrate data from Shapes with Microsoft Azure.
Connect the integration from Shapes
Enter Shapes' account settings -> Integrations -> Microsoft
Click on the "Connect" button
Fill out the Directory (tenant) ID, Application (client) ID and Secret Value, and click "Connect"
What data from Shapes is automatically synced to EntraID?
Shapes Field name | EntraID Field name |
Email address | userPrincipalName, mailNickname |
First name | givenName |
Last name | surname |
Job | jobTitle |
Phone number | mobilePhone |
Team | Department |
Reports to | manager |
First name +last name | displayname |
Office | Office |
You can contact support@shapes.co to choose which fields you'd like to sync and/or enable any additional filters.
Troubleshooting: Provisioning Fails Silently
Most common provisioning trap: Microsoft Entra requires a usage location to be set on new users before licenses can be assigned. If this isn't configured, provisioning can fail without a visible error — the employee simply never shows up in Entra, with nothing in Shapes flagging why. If a new hire isn't appearing in Entra after being created in Shapes, this is the first thing to check with your Microsoft admin.

















