website/docs/add-secure-apps/providers/entra/configure-entra.md
For more information about using an Entra ID provider, see the Entra ID Overview documentation.
Your Entra ID tenant must be configured before you create a Entra ID provider.
This involves creating an app registration, generating a secret, and configuring the required API permissions.
:::warning Email domains
When the default authentik default Microsoft Entra Mapping: User property mapping is used, authentik checks whether each user's email domain is verified in your Entra ID tenant.
In which case, you must configure each user's email domain as a verified custom domain in Entra ID; otherwise, provisioning fails. The tenant's default onmicrosoft.com domain (e.g., @<tenant name>.onmicrosoft.com), is considered a verified domain.
Alternatively, if you need to provision users with email domains that you don't control, refer to Email handling for more information. :::
authentik Entra Provider)Group.CreateGroup.ReadWrite.AllGroupMember.ReadWrite.AllUser.ReadWrite.AllNow that you have configured your Entra ID tenant, you are ready to create an Entra ID provider.