Integrating Liceo with Microsoft Entra ID: A Setup Guide
Tutorial
All articles
5 June 2026 5 min read0 comments

Integrating Liceo with Microsoft Entra ID: A Setup Guide

Connect your Entra ID directory to Liceo in under 15 minutes. Map users to licences automatically and keep everything in sync.

Connecting Liceo to Microsoft Entra ID (formerly Azure Active Directory) gives you automatic employee directory sync, real-time licence assignment tracking, and M365 per-app usage data — all without manual data entry.

What You'll Need

To complete this setup you need: Global Administrator or Privileged Role Administrator rights in your Entra ID tenant, and Admin access to your Liceo organisation.

Step 1 — Navigate to Integrations

In Liceo, go to Settings → Integrations → Microsoft Entra ID and click Connect. You'll be redirected to Microsoft's OAuth consent screen.

Step 2 — Grant Permissions

Liceo requests the following Microsoft Graph permissions: User.Read.All (to sync your employee directory), Directory.Read.All (to read group and department information), and optionally Reports.Read.All (to pull M365 per-app usage data). Review and accept the permissions as a tenant administrator.

Step 3 — Initial Sync

After consent, Liceo runs an initial directory sync — typically completing in under two minutes for organisations up to 5,000 users. You'll see employees appear in the People section with their department, job title, and email pre-populated.

Ongoing Sync

Liceo syncs with Entra ID every four hours. New starters appear automatically; departures trigger an offboarding alert so you can action licence revocation promptly.

Using M365 Usage Data in Liceo

If you granted the optional Reports.Read.All permission during setup, Liceo will pull per-user Microsoft 365 application usage data — showing which M365 apps each employee actively uses, and how frequently. This data surfaces immediately actionable insights: employees assigned Business Premium licences who are only using Exchange and Teams are strong candidates for tier downgrades, potentially saving £8–12 per user per month.

The M365 usage data refreshes weekly in Liceo, giving you a rolling 30-day view of actual consumption. Navigate to Tools → Microsoft 365 to see the per-user breakdown and filter by licence tier, department, or last-activity date. Export the results as a CSV to prepare for your next M365 renewal conversation with your Microsoft account manager or reseller.

Mapping Entra ID Groups to Liceo Departments

If your Entra ID is configured with security groups or distribution lists that align to departments or teams, Liceo can import these group memberships to pre-populate its department structure. During or after the initial sync, navigate to Settings → Integrations → Microsoft Entra ID → Group Mapping and select which Entra groups should map to Liceo departments. This ensures cost allocation and utilisation reporting is automatically broken down by the organisational structure that Finance and IT already work with.

Groups that don't have a direct Liceo department equivalent can be mapped to a custom tag, making it easy to report on cross-functional teams or project groups without restructuring your primary department hierarchy.

Troubleshooting Common Sync Issues

The most common sync issue is a permission scope error: the integration was set up without Directory.Read.All, and Liceo can see users but not their department or group memberships. To resolve this, navigate to Settings → Integrations → Microsoft Entra ID, click Re-authorise, and ensure all required permissions are granted. The next sync cycle will backfill the missing data.

If users appear in Liceo without a department assigned, check whether their Entra ID profile has a Department field populated. Liceo reads the Department attribute from the Entra ID user object — if this field is blank in the directory, it will be blank in Liceo. Updating the field in Entra ID will sync to Liceo within four hours.

Share X / Twitter LinkedIn

See Liceo in action

Track every licence, cut waste, and automate renewals — in one platform.

Discussion

Comments are moderated before appearing publicly.

No comments yet. Be the first to share your thoughts.

Leave a comment

Not published. Used for moderation only.

0/3000 characters

Ronke

Liceo product guide · AI assistant

Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?

Ronke shares verified product info only. For custom quotes or contracts, book a demo.