OneGIG Directory Sync: Entra Setup
For SENAAT IT (Entra administrators). Time required: about 10 minutes.
What: OneGIG (giginsulation.app) reads user profiles from the GIG Entra tenant through Microsoft Graph, to keep the staff directory current.
Access: read-only, application permission User.Read.All. Nothing is written back to Entra.
Deliverable: 3 values: Tenant ID, Client ID, Client secret.
1. Register the app
- Open Entra admin center > App registrations > New registration.
- Name:
OneGIG Directory Sync. Account type: Single tenant. Redirect URI: none. Click Register. - From the app's Overview, copy the Application (client) ID and Directory (tenant) ID.
Reference: Register an application
2. Grant Graph permission
- In the app: API permissions > Add a permission > Microsoft Graph > Application permissions.
- Select
User.Read.Alland click Add permissions. - Click Grant admin consent for <tenant>. The status must show a green check.
Reference: User.Read.All ยท Grant admin consent
3. Create a client secret
- In the app: Certificates & secrets > Client secrets > New client secret.
- Description:
OneGIG. Expiry: 24 months maximum. Copy the Value right away, because it is shown only once. - Record the expiry date and set a reminder to renew it 30 days before.
Reference: Add a client secret
4. Hand over the values
| Value | Where to find it | OneGIG setting |
|---|---|---|
| Directory (tenant) ID | App Overview | GRAPH_TENANT_ID |
| Application (client) ID | App Overview | GRAPH_CLIENT_ID |
| Client secret value | Certificates & secrets | GRAPH_CLIENT_SECRET |
Send the values to the OneGIG administrator (Khaled Alghamdi) through a secure channel, such as a password manager share or an encrypted message. Do not send the secret by plain email.
5. Optional settings
| Setting | Purpose | Example |
|---|---|---|
GRAPH_FILTER | Limit which users are read | accountEnabled eq true and userType eq 'Member' |
GRAPH_ENTITY_MAP | Map companyName to GIG / AFICO / SRW / BCOMS | {"Gulf Insulation Group":"GIG","AFICO":"AFICO"} |
GRAPH_ATTR_NAME_AR, GRAPH_ATTR_TITLE_AR, GRAPH_ATTR_ENTITY | Arabic name, Arabic title and company from directory extension attributes (format extension_<appId>_name) | extension_1a2b..._nameAr |
Reference: Directory extensions. On-premises extensionAttribute1-15 are not read at present.
6. Test
- OneGIG admin: Admin console > Directory > Test connection, then Sync now.
- Check the result in Entra sign-in logs (Service principal sign-ins) for
OneGIG Directory Sync.
Fields read
displayName, givenName, surname, jobTitle, department, companyName, mail, userPrincipalName, mobilePhone, businessPhones, officeLocation, accountEnabled, plus any extension attributes set above. Records are matched by email. Users who are no longer returned are deactivated in OneGIG.
Troubleshooting
| Error | Fix |
|---|---|
AADSTS700016 | Wrong Client ID or Tenant ID. |
AADSTS7000215 / invalid_client | Wrong or expired secret. Use the secret Value, not its ID. |
Authorization_RequestDenied / 403 | Admin consent for User.Read.All is missing (step 2). |
| 0 users synced | GRAPH_FILTER is too strict. |
Revoke access
Delete the client secret, or delete the app registration in App registrations. The sync stops immediately.