Deployment
v1 v2 (BETA) English French German Italian Portuguese Spanish
v1 v2 (BETA) English French German Italian Portuguese Spanish

Automatic Microsoft Entra App Registration

MyQ can automatically create and configure the Microsoft Entra enterprise application required by the following integrations:

  • Microsoft Entra ID (Microsoft Graph)

  • OneDrive for Business

  • SharePoint Online

Automatic registration is the recommended set up method. During automatic registration, MyQ creates the enterprise application, configures its credentials and permissions, and obtains administrator consent through a guided authorization process.


You will need:

  • a Microsoft Entra tenant

  • access to the relevant integration settings in MyQ

  • a Microsoft Entra account with the required administrator role

  • Application Administrator or Cloud Application Administrator can create the service principal in the tenant.

  • Global Administrator is required to grant administrator consent.

The administrator permissions used during setup are separate from the permissions that the resulting enterprise application uses at runtime.

How Automatic Registration Works

Automatic registration consists of three stages:

  1. The administrator signs in to Microsoft Entra ID, and MyQ creates the service principal in the customer’s tenant.

  2. The administrator authorizes MyQ to configure the application.

  3. MyQ assigns the runtime permissions required by the selected integration, and the administrator grants consent.

The service principal is displayed under Enterprise applications in the Microsoft Entra admin center.

The exact runtime permissions depend on the integrations enabled for the connection.

Automatic Registration is recommended for Azure tenants using the default configuration. If your tenant has custom security settings, configure the newly created application manually to request the required permissions (delegated or application permissions), which can then be granted by either end users or an administrator.

Application Credentials

Client secrets created by MyQ during automatic registration are valid for two years.

When a secret is within 30 days of expiration, MyQ reports a Health Check warning. Use Re-authorize before the secret expires to create a new secret for the existing connection.

Credentials created directly for service principals are not displayed in the Microsoft Entra admin center. They can be managed through Microsoft Graph or PowerShell.

Re-authorize a Connection

Use the Re-authorize option to repeat the Microsoft authorization process for an existing connection.

Reauthorization can:

  • complete administrator consent that was not granted during the initial setup

  • create a new client secret

  • recreate a deleted enterprise application

  • change the connection between automatic and manual configuration

Reauthorization updates the existing enterprise application when it is still present. It does not create a duplicate.

To re-authorize, right-click on the connection. This opens the create connection dialog. You can repeat all the steps to create a new secret for the existing connection.

Recreate a Deleted Enterprise Application

If the enterprise application has been deleted from Microsoft Entra ID, use Re-authorize in MyQ. The authorization process creates the service principal again and restores the connection.

Revoke Access

To revoke access for an automatically configured connection, delete its enterprise application in Microsoft Entra ID.

This removes the service principal and its credentials from the tenant. If the connection is later reauthorized in MyQ, MyQ creates the service principal again.

Deleting the enterprise application immediately revokes access and causes the associated MyQ connection to stop working. Before deleting it, verify that the application is not used by any other MyQ connections or services.