The Microsoft Entra ID integration creates and updates user accounts in your Microsoft Entra tenant directly from Humaans. When you add someone in Humaans, their Entra account can be provisioned automatically, kept in sync with their Humaans profile, and deactivated when they're offboarded.
The integration covers account provisioning, data syncing, and deprovisioning.
Before you begin
To set up the integration, you need:
A Humaans Growth or Enterprise plan.
The Owner or Admin role in Humaans, or a custom role with permission to manage integrations. To learn more, visit Managing permissions and roles.
A Microsoft Entra administrator who can grant admin consent for your organisation and manage users. This is typically a Global Administrator. Microsoft's role documentation explains which roles can grant consent.
Connect Microsoft Entra ID
An administrator connects the integration once for your organisation.
Click Integrations in the main menu.
Locate Microsoft Entra ID, then click Configure.
In the Connection tab, click Sign in with Microsoft Entra ID.
Sign in to Microsoft as an Entra administrator.
Review the requested permissions, then accept them to grant admin consent.
Humaans returns to the Integrations page and shows the connection as active. The account you sign in with authorises Humaans to manage users on its behalf, so it's important to keep it active.
Connect multiple Microsoft Entra tenants
If your organisation manages more than one Microsoft Entra tenant, you can connect each tenant to Humaans and control which people sync to which tenant. This suits organisations that run separate tenants for different legal entities, brands, or regions.
Connecting more than one tenant, and routing people by space, requires our Spaces feature. To learn more, visit Split your people directory into spaces.
Add another tenant
In the Home menu, click Integrations.
Locate Microsoft Entra ID, then click Configure.
Click Add another connection.
Sign in as an administrator of the tenant you want to add.
Review the requested permissions, then accept them to grant admin consent.
The tenant appears in your list of connections. Each connection lists its domain, tenant name, and the space it provisions from.
Route people to a tenant with spaces
Each connection provisions people either from all of Humaans or from a single space, so you can send different groups of people to different tenants.
In the list of connections, select the tenant to configure.
Open the Routing tab.
From the Humaans Space dropdown, select the space to provision people from, or select All spaces.
Click Save.
Configure each tenant separately
Every connected tenant keeps its own settings across the Connection, Routing, Provisioning, Syncing, Deprovisioning, and Logs tabs. Set provisioning rules, field mappings, and deprovisioning for each tenant independently.
In the Routing tab, you can select which space's configuration you want to view.
Choose when accounts are created
To configure your provisioning rules in the Provisioning tab:
Enable Provision Microsoft Entra ID users by toggling it on.
Under When to provision, select one of these options:
As soon as the employee is created: Humaans creates the Entra account when you add the person.
Employment start date: Humaans creates the account relative to the start date. Pick the offset: on the day, one day before, one week before, two weeks before, or one month before.
Choose an option for When to send invite with password:
As soon as the account is provisioned
Employment start date
Never - invite will be sent manually
Toggle on or off the option to immediately activate users in Microsoft Entra ID when they are provisioned.
Click Save.
When it creates an account, Humaans sets the display name, the user principal name (work email), and a temporary password which the person changes at first sign-in.
Invitations go to the person's personal email. If the employee doesn't have one on file, provisioning is skipped when invitations are enabled to send.
Note: People are provisioned once they become active members in Humaans. This doesn't include new hires.
Choose which fields sync
In the Syncing tab, choose which data maps from an employee's user profile in Humaans to Microsoft Entra ID fields. First name, last name, and work email always sync and can't be toggled off because they identify the account.
Here's a list of the available fields for mapping:
Humaans profile | Microsoft Entra ID |
First name | First name |
Last name | Last name |
Work email | User principal name |
Personal email | Other emails |
Job title | Job title |
Department* | Department |
Place of work* | Office location |
Employee ID | Employee ID |
Work phone | Business phone |
Personal phone | Mobile phone |
Profile photo | Photo |
Full address** | Address |
Manager | Manager |
*Entra’s Department and Office location fields support custom mapping in Humaans. Instead of syncing the default Humaans fields, use the dropdown next to them to choose one of your own custom fields as the source. Humaans will sync that custom field's value into the corresponding Entra ID Department field.
The custom fields available as sources come from your Basics, Employment, and Job role sections.
For Entra's Office location field, you can also select from the built-in fields place of work, place of work city, and place of work country as well as your custom fields.
**Full address maps to five separate Entra fields, and the country is converted to its standard country code.
Add custom field mappings
Beyond the standard fields, you can map Humaans fields, including your own custom fields, to additional Microsoft Entra ID attributes. To do this, follow these steps in the Syncing tab of Configuration:
Click Add mapping.
Under the source column, select the Humaans field to sync from.
Under the destination column, select the Microsoft Entra ID attribute to sync into.
Click Save.
To remove a mapping, click the delete icon at the end of its row.
Source fields you can use
The source can be any of your custom fields from the Basics, Employment, and Job role sections, along with built-in Humaans fields that aren't in the default list, such as pronouns, nationality, contract type, teams, employment start and end dates, and whether the person is a manager.
Entra ID attributes you can map to
Available destinations in Entra include extension attributes (1–15), directory extension properties defined in your Entra tenant, and standard attributes such as employee type, company name, and employee hire and leave dates.
Keep data in sync
By enabling Keep data in sync, changes made to employees in Humaans will be reflected in their Microsoft Entra ID profile. If this setting isn't enabled, mapped fields are used only when an account is first provisioned.
Syncing is one-way: changes made in Humaans updates Entra, but not vice versa.
Sync existing employees
New accounts and updates sync from the time you set up the integration. To apply your settings to people who were already in Humaans, click Sync all users in the Syncing tab.
Deactivate accounts when people leave
If you enable Deprovision Microsoft Entra ID users in the Deprovisioning tab, when someone is offboarded in Humaans, their Entra account is deactivated and sign-in is disabled. Humaans runs a final sync before disabling the account.
Deprovisioning deactivates accounts, it doesn't delete them. Delete the account, and reassign any licenses or data, in Microsoft Entra.
Reprovisioning isn't automatic. Once an account is deprovisioned, provision it again manually in Microsoft Entra.
To plan offboarding, visit Offboarding users and deleting profiles.
Review activity and errors
The Logs tab records provisioning, syncing, and deprovisioning activity, including any errors. Check it to confirm accounts were created, or to investigate a sync that didn't complete.
Reconnect the integration
If the connection expires, or the connecting administrator's access changes, the integration on Humaans' side shows "An authentication issue has occurred. Please reconnect to continue syncing Microsoft Entra with Humaans." To restore syncing:
Open the Microsoft Entra ID integration.
In the Connection tab, click Sign in with Microsoft Entra ID.
Sign in as an Entra administrator and accept the permissions.
If the administrator who connected the integration is offboarded, reconnect it with another administrator.







