Connect Microsoft Entra
This page walks you through the one-time setup — click by click. Afterwards Mango Inventory maintains your user list by itself: whoever is in the chosen Microsoft groups joins automatically; whoever leaves them is deactivated. You need no IT knowledge for this, only a Microsoft account with administrator rights. Plan for 10 to 15 minutes.
What the sync does in general is on the overview page Directory sync.
Prerequisites
Section titled “Prerequisites”- Premium plan in Mango Inventory — single sign-on and directory sync are part of it. Details on the pricing page.
- Owner role in Mango Inventory — only owners see the Settings → Single sign-on page.
- A Microsoft account with the “Global Administrator” role in your organization. That is the account used to manage users and licences in Microsoft 365. It doesn’t have to be you — you can hand steps 2 to 5 to your IT.
- Microsoft Entra is the directory service behind Microsoft 365. If your staff sign in to Outlook or Teams with an address of your organization, you have Entra — even if you have never heard the name.
Setting it up
Section titled “Setting it up”Microsoft shows these pages in the language of your Microsoft account. The pictures below come from a test run — the sign-in screen in step 3 appears in German there, steps 4 and 5 in English. Only the wording changes, not the order of the screens.
-
Open the setup page in Mango Inventory. Sign in at
app.mangoinventory.comand go to Settings → Single sign-on. At the top of the “Connect your directory” card there is a row of provider tabs — click “Microsoft Entra”.
-
Open the consent link. Under step 1, click “Open the admin consent page” — it opens in a new tab. If you are not a Microsoft administrator yourself, click “Copy” instead and send the link to your IT. It is the same link:
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=0c3379d1-8021-43ae-8cdd-1b24a4fb9a38&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&redirect_uri=https%3A%2F%2Fapp.mangoinventory.com%2Fsettings%2Fsso -
Sign in with the administrator account. Microsoft asks for the email address and password — use the account with the “Global Administrator” role, not your personal one. An ordinary user account is turned away here.

-
Confirm the permissions. Microsoft shows four lines with what Mango Inventory gets — all of them read permissions: read group memberships, read users’ basic profiles (name and email address), read profile photos, and the sign-in itself. Confirm with “Accept” at the bottom right.

You then land back on
app.mangoinventory.com. If an error appears instead, the account was not a global administrator — in that case your IT takes over this step. -
Copy the tenant ID. The tenant ID is your organization’s reference number at Microsoft — think of it as a customer number. It is not a secret. Open entra.microsoft.com, sign in and stay on the “Overview” start page: under “Basic information” it shows “Tenant ID” with a string in the form
00000000-0000-0000-0000-000000000000. Click the copy icon next to it.
-
Enter the tenant ID in Mango Inventory. Back on the “Connect your directory” card: paste the copied value into the “Entra tenant ID” field and click “Connect Microsoft Entra”. Connecting doesn’t sync anyone yet — you pick the groups first.

-
Pick the groups. The page now shows two cards. Under “Sync settings”, open “Groups to sync” and select the directory groups whose people should use Mango Inventory — “Operations” and “Technical”, say. Check “Synced users join as” below it: that is the role everyone joining from now on receives (default: Member).

-
Look at the preview — then sync. Click “Preview changes”. The preview lists who would join, be updated or deactivated; nothing is changed yet. If the list looks right, click “Sync now” at the bottom.
Done — what happens now
Section titled “Done — what happens now”- The synced people appear in the user list right away, marked “Not signed in yet” at first. With their first sign-in via “Continue with Microsoft” they become full users — no invitation email, no new password.
- Every night Mango Inventory reconciles the chosen groups automatically. In between you can do it by hand any time: ”⋯” at the top right of the “Directory sync” card → “Sync now”.
- Whoever is removed from every chosen group is deactivated at the next run: no more sign-in, but the history stays fully intact. Nothing is ever deleted. If the person returns to the group, their access comes back. Owners are never deactivated by the directory.
- People outside your directory you keep inviting by hand — see SSO & users.
If something doesn’t work
Section titled “If something doesn’t work”- The first sync reports an error (“403” or “Authorization_RequestDenied”). That is normal right after the consent: Microsoft needs a few minutes until the approval is known everywhere. Wait five minutes and click “Sync now” again.
- The card shows “Needs reconnecting”. The consent was revoked in Entra or is no longer valid. Open the consent link on the card once more, confirm again, and sync afterwards.
- The group list stays empty. Then the tenant ID is wrong or the consent is missing. Check the ID on the overview page in the Entra admin center and walk steps 2 to 4 again.
- Individual people stay on “Not signed in yet”. Usually their directory account has no email address — see the note below.
- More than 500 people cannot be synced by one connection. Pick narrower groups in that case, or get in touch with us.