Skip to content

Connect Microsoft Entra

This page walks you through the one-time setup — click by click. Afterwards Mango Inventory maintains your user list by itself: whoever is in the chosen Microsoft groups joins automatically; whoever leaves them is deactivated. You need no IT knowledge for this, only a Microsoft account with administrator rights. Plan for 10 to 15 minutes.

What the sync does in general is on the overview page Directory sync.

  • Premium plan in Mango Inventory — single sign-on and directory sync are part of it. Details on the pricing page.
  • Owner role in Mango Inventory — only owners see the Settings → Single sign-on page.
  • A Microsoft account with the “Global Administrator” role in your organization. That is the account used to manage users and licences in Microsoft 365. It doesn’t have to be you — you can hand steps 2 to 5 to your IT.
  • Microsoft Entra is the directory service behind Microsoft 365. If your staff sign in to Outlook or Teams with an address of your organization, you have Entra — even if you have never heard the name.

Microsoft shows these pages in the language of your Microsoft account. The pictures below come from a test run — the sign-in screen in step 3 appears in German there, steps 4 and 5 in English. Only the wording changes, not the order of the screens.

  1. Open the setup page in Mango Inventory. Sign in at app.mangoinventory.com and go to Settings → Single sign-on. At the top of the “Connect your directory” card there is a row of provider tabs — click “Microsoft Entra”.

    The "Connect your directory" card in Mango Inventory with the "Microsoft Entra" tab active: step 1 with the consent link, step 2 with the "Entra tenant ID" field and the "Connect Microsoft Entra" button

  2. Open the consent link. Under step 1, click “Open the admin consent page” — it opens in a new tab. If you are not a Microsoft administrator yourself, click “Copy” instead and send the link to your IT. It is the same link:

    https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=0c3379d1-8021-43ae-8cdd-1b24a4fb9a38&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&redirect_uri=https%3A%2F%2Fapp.mangoinventory.com%2Fsettings%2Fsso
  3. Sign in with the administrator account. Microsoft asks for the email address and password — use the account with the “Global Administrator” role, not your personal one. An ordinary user account is turned away here.

    The Microsoft sign-in page in the browser, opened via the consent link

  4. Confirm the permissions. Microsoft shows four lines with what Mango Inventory gets — all of them read permissions: read group memberships, read users’ basic profiles (name and email address), read profile photos, and the sign-in itself. Confirm with “Accept” at the bottom right.

    The Microsoft consent page with the requested read permissions and the confirm button

    You then land back on app.mangoinventory.com. If an error appears instead, the account was not a global administrator — in that case your IT takes over this step.

  5. Copy the tenant ID. The tenant ID is your organization’s reference number at Microsoft — think of it as a customer number. It is not a secret. Open entra.microsoft.com, sign in and stay on the “Overview” start page: under “Basic information” it shows “Tenant ID” with a string in the form 00000000-0000-0000-0000-000000000000. Click the copy icon next to it.

    The overview page in the Microsoft Entra admin center, cropped to the "Tenant ID" row and its copy icon

  6. Enter the tenant ID in Mango Inventory. Back on the “Connect your directory” card: paste the copied value into the “Entra tenant ID” field and click “Connect Microsoft Entra”. Connecting doesn’t sync anyone yet — you pick the groups first.

    The filled "Entra tenant ID" field and the "Connect Microsoft Entra" button

  7. Pick the groups. The page now shows two cards. Under “Sync settings”, open “Groups to sync” and select the directory groups whose people should use Mango Inventory — “Operations” and “Technical”, say. Check “Synced users join as” below it: that is the role everyone joining from now on receives (default: Member).

    The "Sync settings" card with selected groups and the "Synced users join as" picker

  8. Look at the preview — then sync. Click “Preview changes”. The preview lists who would join, be updated or deactivated; nothing is changed yet. If the list looks right, click “Sync now” at the bottom.

  • The synced people appear in the user list right away, marked “Not signed in yet” at first. With their first sign-in via “Continue with Microsoft” they become full users — no invitation email, no new password.
  • Every night Mango Inventory reconciles the chosen groups automatically. In between you can do it by hand any time: ”⋯” at the top right of the “Directory sync” card → “Sync now”.
  • Whoever is removed from every chosen group is deactivated at the next run: no more sign-in, but the history stays fully intact. Nothing is ever deleted. If the person returns to the group, their access comes back. Owners are never deactivated by the directory.
  • People outside your directory you keep inviting by hand — see SSO & users.
  • The first sync reports an error (“403” or “Authorization_RequestDenied”). That is normal right after the consent: Microsoft needs a few minutes until the approval is known everywhere. Wait five minutes and click “Sync now” again.
  • The card shows “Needs reconnecting”. The consent was revoked in Entra or is no longer valid. Open the consent link on the card once more, confirm again, and sync afterwards.
  • The group list stays empty. Then the tenant ID is wrong or the consent is missing. Check the ID on the overview page in the Entra admin center and walk steps 2 to 4 again.
  • Individual people stay on “Not signed in yet”. Usually their directory account has no email address — see the note below.
  • More than 500 people cannot be synced by one connection. Pick narrower groups in that case, or get in touch with us.