MyQ X Server
10.3 10.2 8.2 EoL Print Server Central Server English French German Italian Portuguese Spanish
10.3 10.2 8.2 EoL Print Server Central Server English French German Italian Portuguese Spanish

Connect to Microsoft Entra ID

Connect MyQ X to Microsoft Entra ID via Microsoft Graph API to synchronize users and groups and to authenticate MyQ users with their Microsoft identity. The connection can be used for:

  • synchronizing users and groups from Microsoft Entra ID

  • authenticating users against Microsoft Entra ID

  • Sign in with Microsoft

  • Seamless SSO with MyQ Desktop Client

You can create the required Microsoft application automatically from MyQ, or connect MyQ to an application registration that you manage manually.

Microsoft Entra ID, OneDrive for Business, and SharePoint Online can use the same manually registered application. If you plan to use these integrations together, configure the application with the combined permissions required by them.

Create a Microsoft Entra ID Connection

  1. Go to MyQ > Settings > Connections.

  2. Click Add and select Microsoft Entra ID from the list.

    Adding Microsoft Entra ID


  3. Enter a Title for your connection and select your preferred Mode:

    • Create automatically: MyQ X configures the Entra application required for accessing Entra ID user information.

    • Set up manually: Configure the Entra application manually. Select this option if you want to manage all aspects of the integration setup.

  4. Proceed to the corresponding section below.

Create Automatically

During setup, sign in with a Microsoft account that can grant the permissions required to create and configure the connector application.

Automatic setup applies the following temporary permissions:

Permission

API

Type

Purpose

Application.ReadWrite.All

Microsoft Graph

Delegated

Create or update the connector application credential.

Directory.Read.All

Microsoft Graph

Delegated

Read tenant information, including the default domain name.

MyQ creates the connector application and configures it with the runtime permissions required for the selected integration. Complete the Microsoft authorization process and save the connection.

You can also create the corresponding user synchronization source and enable Sign in with Microsoft during setup.

See also: Automatic Microsoft Entra App Registration

Set Up Manually

Select Set up manually if your organization manages Microsoft Entra application registrations directly. You can use the same application registration for Microsoft Entra ID, OneDrive for Business, and SharePoint Online, or a dedicated application for each service. The shared application must contain the permissions required by all integrations that use it.

See Manual Microsoft Entra App Registration

Microsoft Entra ID requires the following runtime permissions:

Permission

API

Type

Purpose

Group.Read.All

Microsoft Graph

Application

Read groups and group membership.

User.Read.All

Microsoft Graph

Application

Read users.

User.Read

Microsoft Graph

Delegated

Sign in and read the signed-in user's profile.

Then enter your Microsoft Entra app information into MyQ and save the connection.

  • Title: a title for the connection.

  • Directory (tenant) ID: the directory ID of your Entra app.

  • Application (client) ID: the application ID of your Entra app.

  • Security key: the Entra app client secret.

entraid-connection-setup.png

Configure User Synchronization

Creating the Entra ID connection does not itself import users.

To synchronize users and groups, create a Microsoft Entra ID synchronization source in MyQ > Settings > User Synchronization and select the connection you created.

See also: Synchronize Users from Microsoft Entra ID

Configure Authentication

To authenticate users with Microsoft Entra ID, configure the corresponding authentication server and associate it with the Entra ID connection.

Depending on your environment, you can also use:

  • Sign in with Microsoft

  • Seamless SSO for MyQ Desktop Client

The required authentication scopes and redirect URIs are listed separately.

See also: Microsoft Entra App Reference

Re-authorizing the Entra ID Connection

Use the Re-authorize option to repeat the Microsoft authorization process for an existing connection.

Reauthorization can:

  • complete administrator consent that was not granted during the initial setup

  • create a new client secret

  • recreate a deleted enterprise application

  • change the connection between automatic and manual configuration

Reauthorization updates the existing enterprise application when it is still present. It does not create a duplicate.

To re-authorize, right-click on the connection. This opens the create connection dialog. You can repeat all the steps to create a new secret for the existing connection.

Re-authorizing Microsoft Entra ID

Multiple Microsoft Entra Tenants

MyQ can connect to multiple Microsoft Entra tenants. Create a separate connection for each tenant and assign the appropriate synchronization source and authentication configuration to each connection.

Next Steps

You are now ready to configure synchronization and authentication through Microsoft Entra ID with Microsoft Graph.