docs/integrations/app-connections/azure-entra-id.mdx
Infisical's Azure Entra ID Connection lets you authenticate with Microsoft Entra ID (formerly Azure Active Directory) using Client Secrets.
Prerequisites:
For SCIM Token Secret Sync:
Your App Registration must have the following Microsoft Graph API Application permissions:
Application.ReadWrite.All — Required to read and update synchronization secrets (SCIM tokens) on enterprise application service principals.Synchronization.ReadWrite.All — Required to list synchronization jobs on service principals and to write SCIM provisioning tokens.<Note>If you want to configure automatic client secret rotation for this App Connection, you also need to grant either Application.ReadWrite.OwnedBy or Application.ReadWrite.All permissions.</Note>
</Accordion>

</Step>
<Step title="Create Connection">
Fill in the following fields with the credentials from your Azure App Registration:
- **Tenant ID**: The Directory (Tenant) ID of your Azure Entra ID tenant.
- **Client ID**: The Application (Client) ID of your registered application.
- **Client Secret**: A client secret generated for your registered application.
Click **Connect** to create the connection.

<Tip>
You can optionally enable **Automatic Credential Rotation** for this connection. See the [Automatic Credential Rotation](#automatic-credential-rotation) section below for details.
</Tip>
</Step>
<Step title="Connection Created">
Your **Azure Entra ID Connection** is now available for use with features such as the Azure Entra ID SCIM Secret Sync.
</Step>
</Steps>
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/app-connections/azure-entra-id \
--header 'Content-Type: application/json' \
--data '{
"name": "my-azure-entra-id-connection",
"method": "client-secret",
"credentials": {
"tenantId": "your-tenant-id",
"clientId": "your-client-id",
"clientSecret": "your-client-secret"
}
}'
```
### Sample response
```json Response
{
"appConnection": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-azure-entra-id-connection",
"description": null,
"version": 1,
"orgId": "6f03caa1-a5de-43ce-b127-95a145d3464c",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"isPlatformManagedCredentials": false,
"app": "azure-entra-id",
"method": "client-secret",
"credentials": {}
}
}
```
Infisical can automatically rotate the Client Secret of your Azure application on a recurring schedule. When enabled, Infisical will immediately generate a new Client Secret on connection creation and revoke the original one, ensuring that no external party retains access using the credentials you provided.
<Steps> <Step title="Locate the Key ID of your Client Secret"> Before enabling rotation, you'll need the **Key ID** of the Client Secret you are using to authenticate. Navigate to your App Registration in the Azure Portal, then go to **Certificates & secrets**. Copy the **Secret ID** (Key ID) of the secret you are providing to Infisical. 
</Step>
<Step title="Enable Automatic Credential Rotation">
When creating or editing your connection, toggle on the **Automatic Credential Rotation** switch.

</Step>
<Step title="Provide the Client Secret Key ID">
Enter the **Key ID** you copied in the previous step into the **Client Secret Key ID** field. Infisical uses this to revoke your original secret after generating a new one.

</Step>
<Step title="Configure the Rotation Schedule">
Set the **Rotation Interval** (in days) to define how often the credential should be rotated, and set **Rotate At** to the local time of day at which the rotation should occur.
- **Rotation Interval** - How many days between each rotation.
- **Rotate At** - The local time of day at which the rotation will be triggered.

</Step>