MyQ X Server

Connect to Microsoft Entra ID (Graph API)

Connect MyQ X to Microsoft Entra ID to synchronize users and groups and to authenticate MyQ users with their Microsoft identity. The connection can be used for:

  • synchronizing users and groups from Microsoft Entra ID

  • authenticating users against Microsoft Entra ID

  • Sign in with Microsoft

  • Seamless SSO with MyQ Desktop Client

You can create the required Microsoft application automatically from MyQ, or connect MyQ to an application registration that you manage manually.

Microsoft Entra ID, OneDrive for Business, and SharePoint Online can use the same manually registered application. If you plan to use these integrations together, configure the application with the combined permissions required by them.

Create a Microsoft Entra ID Connection

  1. Go to MyQ > Settings > Connections.

  2. Click Add and select Microsoft Entra ID from the list.

    Adding Microsoft Entra ID


  3. Enter a Title for your connection and select your preferred Mode:

    • Create automatically: MyQ X configures the Azure application required for accessing Entra ID user information.

    • Set up manually: Configure the Azure application manually. Select this option if you want to manage all aspects of the integration setup.

  4. Proceed to the corresponding section below.

Create the connection automatically

During setup, sign in with a Microsoft account that can grant the permissions required to create and configure the connector application.

Permission

API

Type

Purpose

Application.ReadWrite.All

Microsoft Graph

Delegated

Create or update the connector application credential.

Directory.Read.All

Microsoft Graph

Delegated

Read tenant information, including the default domain name.

MyQ creates the connector application and configures it with the runtime permissions required for the selected integration. Complete the Microsoft authorization process and save the connection.

You can also create the corresponding user synchronization source and enable Sign in with Microsoft during setup.

Connect a manually registered application

Select Set up manually if your organization manages Microsoft Entra application registrations directly.

Before configuring MyQ, register a Microsoft Entra application for MyQ X, and configure the application with the required API permissions.

For an Entra ID-only integration, configure the permissions identified for Microsoft Entra ID. If the same application is also used for OneDrive for Business or SharePoint Online, add the permissions required by those integrations.

Grant administrator consent where required.

Required Permissions

Permission

API

Type

Purpose

Group.Read.All

Microsoft Graph

Application

Read groups and group membership.

User.Read.All

Microsoft Graph

Application

Read users.

User.Read

Microsoft Graph

Delegated

Sign in and read the signed-in user's profile.

Then enter the following values from the application registration in MyQ:

  • Application (client) ID

  • Directory (tenant) ID

  • Client secret

Save the connection.

MS Entra connection properties

Configure user synchronization

Creating the Entra ID connection does not itself import users.

To synchronize users and groups, create a Microsoft Entra ID synchronization source in MyQ > Settings > User Synchronization and select the connection you created.

See also: Synchronize Users from Microsoft Entra ID

Configure authentication

To authenticate users with Microsoft Entra ID, configure the corresponding authentication server and associate it with the Entra ID connection.

Depending on your environment, you can also configure:

  • Sign in with Microsoft

  • Seamless SSO for MyQ Desktop Client

The required authentication scopes and redirect URIs are listed separately.

See also: Microsoft Entra Application Reference

Re-authorizing the Entra ID Connection

The automatic connection to Entra ID can be changed or switched to manual after it has been created. By right-clicking on the connection, the Re-authorize option will be available in the context menu.

Re-authorizing Microsoft Entra ID

Multiple Microsoft Entra tenants

MyQ can connect to multiple Microsoft Entra tenants. Create a separate connection for each tenant and assign the appropriate synchronization source and authentication configuration to each connection.

Next Steps

You are now ready to configure synchronization and authentication through Microsoft Entra ID with Microsoft Graph.