Prerequisites
Before you begin, ensure you have:- Microsoft Entra ID administrator access (Global Administrator or Application Administrator role)
- Your Microsoft Entra tenant domain
- Permissions to grant admin consent for applications
Setup guide
Register Ravenna in Microsoft Entra ID
Navigate to integrations
Select Microsoft Entra ID
Start OAuth flow
Grant admin consent
- Read user profiles
- Read group memberships
- Read application assignments
- Manage group memberships (for workflow actions)
- Manage application access (for workflow actions)
Complete setup
Required permissions
Ravenna requests the following Microsoft Graph API permissions:Enable privileged operations
To use the Reset Password, Reset MFA, and Delete User workflow actions, you must assign an admin role to the Ravenna application in Microsoft Entra ID. This is required because Entra enforces role-based access control for sensitive operations.Assign the Privileged Authentication Administrator role
Open Microsoft Entra admin center
Go to Roles and administrators
Find the Privileged Authentication Administrator role
Add assignment
Select the Ravenna application
Confirm the assignment
Role options
Choose the appropriate role based on your security requirements:Troubleshooting
Admin consent required error
Admin consent required error
- Ensure you’re signed in with a Global Administrator or Application Administrator account
- Contact your organization’s administrator to grant consent
- Check your Entra ID role assignments in the Azure portal
Insufficient privileges error
Insufficient privileges error
- Review the permissions requested during OAuth flow
- Ensure admin consent was granted for all requested permissions
- Try disconnecting and reconnecting the integration
- Verify your Entra ID tenant allows third-party app integrations
Password or MFA reset fails with insufficient privileges
Password or MFA reset fails with insufficient privileges
- Follow the steps in Enable password and MFA management to assign the Privileged Authentication Administrator role
- Ensure you’re assigning the role to the Ravenna service principal, not a user account
- If resetting passwords for admin users, you must use Privileged Authentication Administrator (not Password Administrator)
- Role assignments take effect immediately - no restart required
Tenant not found error
Tenant not found error
- Verify your Microsoft Entra tenant domain is correct
- Ensure the tenant is active and accessible
- Check Azure portal for tenant status
- Contact Microsoft support if tenant issues persist
OAuth redirect error
OAuth redirect error
- Ensure pop-ups are not blocked in your browser
- Try clearing browser cache and cookies
- Use a different browser if the issue persists
- Contact Ravenna support if OAuth flow continues to fail
Security considerations
- Token security: OAuth tokens are encrypted at rest and in transit
- Least privilege: Only requested permissions are granted
- Audit trail: All API calls are logged for compliance and security review
- Revocation: You can revoke Ravenna’s access at any time through Azure portal