OneGIG Directory Sync: Entra Setup

For SENAAT IT (Entra administrators). Time required: about 10 minutes.

What: OneGIG (giginsulation.app) reads user profiles from the GIG Entra tenant through Microsoft Graph, to keep the staff directory current.

Access: read-only, application permission User.Read.All. Nothing is written back to Entra.

Deliverable: 3 values: Tenant ID, Client ID, Client secret.

1. Register the app

  1. Open Entra admin center > App registrations > New registration.
  2. Name: OneGIG Directory Sync. Account type: Single tenant. Redirect URI: none. Click Register.
  3. From the app's Overview, copy the Application (client) ID and Directory (tenant) ID.

Reference: Register an application

2. Grant Graph permission

  1. In the app: API permissions > Add a permission > Microsoft Graph > Application permissions.
  2. Select User.Read.All and click Add permissions.
  3. Click Grant admin consent for <tenant>. The status must show a green check.

Reference: User.Read.All ยท Grant admin consent

3. Create a client secret

  1. In the app: Certificates & secrets > Client secrets > New client secret.
  2. Description: OneGIG. Expiry: 24 months maximum. Copy the Value right away, because it is shown only once.
  3. Record the expiry date and set a reminder to renew it 30 days before.

Reference: Add a client secret

4. Hand over the values

ValueWhere to find itOneGIG setting
Directory (tenant) IDApp OverviewGRAPH_TENANT_ID
Application (client) IDApp OverviewGRAPH_CLIENT_ID
Client secret valueCertificates & secretsGRAPH_CLIENT_SECRET

Send the values to the OneGIG administrator (Khaled Alghamdi) through a secure channel, such as a password manager share or an encrypted message. Do not send the secret by plain email.

5. Optional settings

SettingPurposeExample
GRAPH_FILTERLimit which users are readaccountEnabled eq true and userType eq 'Member'
GRAPH_ENTITY_MAPMap companyName to GIG / AFICO / SRW / BCOMS{"Gulf Insulation Group":"GIG","AFICO":"AFICO"}
GRAPH_ATTR_NAME_AR, GRAPH_ATTR_TITLE_AR, GRAPH_ATTR_ENTITYArabic name, Arabic title and company from directory extension attributes (format extension_<appId>_name)extension_1a2b..._nameAr

Reference: Directory extensions. On-premises extensionAttribute1-15 are not read at present.

6. Test

  1. OneGIG admin: Admin console > Directory > Test connection, then Sync now.
  2. Check the result in Entra sign-in logs (Service principal sign-ins) for OneGIG Directory Sync.

Fields read

displayName, givenName, surname, jobTitle, department, companyName, mail, userPrincipalName, mobilePhone, businessPhones, officeLocation, accountEnabled, plus any extension attributes set above. Records are matched by email. Users who are no longer returned are deactivated in OneGIG.

Troubleshooting

ErrorFix
AADSTS700016Wrong Client ID or Tenant ID.
AADSTS7000215 / invalid_clientWrong or expired secret. Use the secret Value, not its ID.
Authorization_RequestDenied / 403Admin consent for User.Read.All is missing (step 2).
0 users syncedGRAPH_FILTER is too strict.

Revoke access

Delete the client secret, or delete the app registration in App registrations. The sync stops immediately.