Microsoft Entra ID connector
Set up the Microsoft Entra ID connector in Kaivo: authentication, configuration, the 10 BigQuery tables it syncs, and answers to common questions.
Written By Lauri Raivio
Last updated 16 days ago
Kaivo is a fully managed data platform that syncs your Microsoft Entra ID data into a Google BigQuery warehouse and keeps it up to date automatically. There is no pipeline to build and no infrastructure to run, so you can spend your time analysing your data from Microsoft Entra ID instead of moving it.
What is the Microsoft Entra ID connector
Sync your Microsoft Entra ID data into BigQuery with Kaivo to audit users, groups, and access across your directory.
Getting started with the Microsoft Entra ID connector
- Sign up for Kaivo and create a workspace.
- Connect your Microsoft Entra ID account.
- Choose which tables to sync.
- Wait for the initial sync to finish.
- Query your data in BigQuery or your favourite AI or BI tool.
Authenticating Microsoft Entra ID
Authenticate with your Client Secret.
Configuring the Microsoft Entra ID connector
When you set up the connector, you provide:
Tables and columns synced from Microsoft Entra ID
Kaivo syncs 10 tables from Microsoft Entra ID into a dedicated dataset in your BigQuery warehouse. Click any table to see its columns and types.
adminconsentrequestpolicy (8 columns)
adminconsentrequestpolicy (8 columns)
Subtable: adminconsentrequestpolicy__reviewers
applications (17 columns)
applications (17 columns)
Subtable: applications__add_ins
Subtable: applications__api__known_client_applications
Subtable: applications__api__oauth2_permission_scopes
Subtable: applications__api__pre_authorized_applications
Subtable: applications__app_roles
Subtable: applications__identifier_uris
Subtable: applications__key_credentials
Subtable: applications__parental_control_settings__countries_blocked_for_minors
Subtable: applications__password_credentials
Subtable: applications__public_client__redirect_uris
Subtable: applications__required_resource_access
Subtable: applications__required_resource_access__resource_access
Subtable: applications__spa__redirect_uris
Subtable: applications__tags
Subtable: applications__web__redirect_uri_settings
Subtable: applications__web__redirect_uris
directoryaudits (14 columns)
directoryaudits (14 columns)
Subtable: directoryaudits__additional_details
Subtable: directoryaudits__target_resources
Subtable: directoryaudits__target_resources__modified_properties
directoryroles (6 columns)
directoryroles (6 columns)
directoryroletemplates (5 columns)
directoryroletemplates (5 columns)
groups (11 columns)
groups (11 columns)
Subtable: groups__creation_options
Subtable: groups__group_types
Subtable: groups__on_premises_provisioning_errors
Subtable: groups__proxy_addresses
Subtable: groups__resource_behavior_options
Subtable: groups__resource_provisioning_options
Subtable: groups__service_provisioning_errors
identityproviders (3 columns)
identityproviders (3 columns)
Subtable: identityproviders__value
serviceprincipals (16 columns)
serviceprincipals (16 columns)
Subtable: serviceprincipals__add_ins
Subtable: serviceprincipals__alternative_names
Subtable: serviceprincipals__app_roles
Subtable: serviceprincipals__app_roles__allowed_member_types
Subtable: serviceprincipals__key_credentials
Subtable: serviceprincipals__notification_email_addresses
Subtable: serviceprincipals__oauth2_permission_scopes
Subtable: serviceprincipals__password_credentials
Subtable: serviceprincipals__reply_urls
Subtable: serviceprincipals__resource_specific_application_permissions
Subtable: serviceprincipals__service_principal_names
Subtable: serviceprincipals__tags
user_owned_deleted_items (21 columns)
user_owned_deleted_items (21 columns)
Subtable: user_owned_deleted_items__add_ins
Subtable: user_owned_deleted_items__api__known_client_applications
Subtable: user_owned_deleted_items__api__oauth2_permission_scopes
Subtable: user_owned_deleted_items__api__pre_authorized_applications
Subtable: user_owned_deleted_items__api__resource_specific_application_permissions
Subtable: user_owned_deleted_items__app_roles
Subtable: user_owned_deleted_items__identifier_uris
Subtable: user_owned_deleted_items__key_credentials
Subtable: user_owned_deleted_items__parental_control_settings__countries_blocked_for_minors
Subtable: user_owned_deleted_items__password_credentials
Subtable: user_owned_deleted_items__public_client__redirect_uris
Subtable: user_owned_deleted_items__required_resource_access
Subtable: user_owned_deleted_items__required_resource_access__resource_access
Subtable: user_owned_deleted_items__spa__redirect_uris
Subtable: user_owned_deleted_items__tags
Subtable: user_owned_deleted_items__web__redirect_uri_settings
Subtable: user_owned_deleted_items__web__redirect_uris
users (8 columns)
users (8 columns)
Subtable: users__business_phones
How the Microsoft Entra ID sync works
After the first load, Kaivo keeps your BigQuery warehouse up to date for you. Where Microsoft Entra ID supports it, each sync pulls only new and changed records so it stays fast; otherwise it refreshes the whole table. Every record keeps its original ID, so you won't get duplicate rows.
Frequently asked questions
How long does the initial sync take for Microsoft Entra ID?
It depends on how much history is in your Microsoft Entra ID account. Most initial syncs finish within minutes, while large accounts can take a few hours. After that, syncs only fetch new and changed records, so they're much faster.
Can I sync only some tables or columns?
Yes. You pick which tables to sync when you set up the connection and can change the selection later. Tables you don't select are never copied to your warehouse.
What happens when Microsoft Entra ID's schema changes?
New fields are never added automatically. You choose which fields to sync, so data you haven't selected (sensitive personal data, for example) never lands in your warehouse. When a new field appears, it becomes available for you to add. What happens to removed or renamed fields depends on a table's sync mode: full-refresh tables always match what's currently in Microsoft Entra ID, so dropped fields disappear, while incremental tables keep their existing columns and history, so an old field stays and newly added fields fill in over time.
How do I handle GDPR or data deletion requests?
Your data lives in your own Kaivo-managed BigQuery warehouse, so the most direct option is to delete or anonymise specific records right in BigQuery. If you delete data in Microsoft Entra ID instead, full-refresh tables drop it on the next sync, while incremental tables keep it, so you would remove the row in BigQuery or ask us to run a full refresh. To remove everything, delete the Microsoft Entra ID connector in Kaivo and all of its synced data is deleted with it.
Common use cases for Microsoft Entra ID data
Access review
Use users, groups, and directoryroles to review who has access to what.
Audit trail
Use directoryaudits to track directory changes over time.
Application inventory
Join applications with serviceprincipals to document app access.
Use Microsoft Entra ID data in your AI and BI tools
Once Microsoft Entra ID data lands in your Kaivo-managed BigQuery warehouse, you can explore it with AI tools or any BI tool that connects to BigQuery. Here's how the most common destinations work with Microsoft Entra ID data.
Claude
Use Kaivo's MCP server to give Claude secure, workspace-scoped access to your data. Setup guide →
Power BI
Microsoft's BI tool with a native BigQuery connector. Supports direct query and scheduled refresh. Setup guide →
Data Studio
Free Google BI tool with native BigQuery support. One-click connection to your Kaivo warehouse; great for SMB teams on Google Workspace. Setup guide →
Tableau
The premium analytics standard, with native BigQuery integration. Setup guide →
Google Sheets
Use Connected Sheets to query BigQuery directly from a spreadsheet, with no SQL. Setup guide →
Excel
Connect via Power Query's BigQuery connector. Setup guide →
Metabase
Open-source BI tool with strong BigQuery support. Setup guide →
See our pricing page for Microsoft Entra ID connector pricing and plan details.
Related connectors
Was this helpful?
Still need help? Share an idea