Microsoft Entra Id data extractor

Import a new customer’s Microsoft Entra Id data — adminconsentrequestpolicy, applications, directoryaudits, and directoryroles, and 6 more object types — into your product as normalised, relational tables. Vern handles Microsoft Entra Id’s auth, pagination and rate limits, so onboarding a customer off Microsoft Entra Id doesn’t mean building and maintaining that plumbing yourself.

Objects extracted
10

Every queryable object type

Incremental

Full refresh on each run

Authentication
OAuth

Stored encrypted, never in the transcript

Export coverage

What Vern pulls from Microsoft Entra Id

Know exactly what comes across before you migrate. Every object below is normalised into typed tables with referential keys preserved, so the relationships between a customer's records survive the import.

  • Adminconsentrequestpolicy
  • Applications
  • Directoryaudits
  • Directoryroles
  • Directoryroletemplates
  • Groups
  • Identityproviders
  • Serviceprincipals
  • User owned deleted items
  • Users

Managed by Vern

The parts you'd otherwise build yourself

Authentication

Your customer authorises Vern once through the vendor’s consent screen. Vern stores the resulting tokens encrypted, refreshes them, and attaches them to every request — you never handle the raw credential.

Pagination

Vern detects and handles Microsoft Entra Id's paging model — cursor, page number or offset — internally, and returns one consistent, de-duplicated result set. You import a customer's complete data without ever managing a page token.

Rate limits

API sources rarely publish their real rate ceiling until you hit a 429 mid-import, and many silently cap page size. Vern queues and throttles requests to stay under the limit, so a partial pull never lands a customer in your product with missing data.

Output shape

Normalised JSON per object with referential keys preserved and timestamps in ISO 8601. Delivered as JSON or CSV, pushed to your API or webhook, or loaded straight into your application database.

Schema drift

If Microsoft Entra Id changes what it returns between migrations, the agent notices the difference against what it recorded last time and raises it, rather than importing a customer with a column quietly missing.

What it learns

Everything Vern works out about Microsoft Entra Id's quirks — field formats, enum values, ID and date patterns — is written down against the source and applied automatically to every customer you migrate off it afterwards.

What your customer provides

  • Client ID
  • Client secret
  • Tenant Id
  • User Id

Collected once, stored encrypted in a vault, and attached to every request. Credentials are never written into the agent transcript.

API quickstart

Run a Microsoft Entra Id migration from your own product

Create the migration, let the agent extract and map, then pull the result out — without your customer ever seeing a Vern dashboard.

app.vern.so/api/v1
API=https://app.vern.so/api/v1
KEY="x-api-key: $VERN_API_KEY"
JSON="Content-Type: application/json"

# 1 — create a migration against Microsoft Entra Id
ID=$(curl -sX POST $API/migrations -H "$KEY" -H "$JSON" \
  -d '{"name":"Acme onboarding","source":"Microsoft Entra Id"}' \
  | jq -r .migration.id)

# 2 — hand over the customer's credentials for this run
curl -X POST $API/migrations/$ID/source-connection -H "$KEY" -H "$JSON" \
  -d '{"credentials": { ... }}'

# 3 — the agent extracts, maps and previews, stopping before it writes
curl -X POST $API/migrations/$ID/runs -H "$KEY" -H "$JSON" \
  -d '{"kind":"generate"}'

curl $API/migrations/$ID/preview -H "$KEY"

# 4 — approve, then pull the normalised rows back out
curl -X POST $API/migrations/$ID/runs -H "$KEY" -H "$JSON" \
  -d '{"kind":"execute"}'

curl -X POST $API/migrations/$ID/exports -H "$KEY" -H "$JSON" \
  -d '{"slugs":["customers","invoices"]}'

The Migration API runs the whole lifecycle over HTTP with an organisation-scoped key. The agent conversation can be streamed into your own UI, and the preview lets you check exactly what an import will produce before a single row is written.

Read the API reference

Related

Other Security & Identity sources

Onboarding a customer off Microsoft Entra Id?

Bring a real Microsoft Entra Id export and we'll show you what lands in your product.