Microsoft Entra ID
Nova provisions users and group memberships in Microsoft Entra ID through the Microsoft Graph API, so access to Microsoft 365 is governed from the same platform as your on-premises systems.
What Nova does with Microsoft Entra ID
- Creates cloud users including an initial password profile and removes accounts on offboarding
- Assigns and removes Entra group memberships; already-existing or already-removed memberships are handled idempotently instead of raising errors
- Disables and enables accounts via accountEnabled and resets passwords
- Reads actual memberships from the tenant during recertification, resolving nested groups
- Imports existing users and groups through background jobs, paging through large tenants
- Determines the last sign-in from both interactive and non-interactive sign-ins; journaled group changes can be rolled back in a controlled way
Technical integration
Nova connects through Microsoft Graph API v1.0 using OAuth2 client credentials from an app registration; tokens are cached and refreshed automatically. Authority and Graph endpoint are configurable.
In the identity lifecycle
Joiners get their Entra account automatically and leavers are blocked via accountEnabled, ending Microsoft 365 access at offboarding. Access requests are provisioned as group memberships, and recertification reads the actual state from the tenant.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.