Skip to main content
This guide adds two read-only Microsoft Graph permissions to your existing Brellium SSO application and grants admin consent for your organization. It takes about 5 minutes.

When you need this

SCIM provisioning only pushes groups that are directly assigned to the Brellium SCIM enterprise application. Microsoft Entra ID does not send any other groups, even if provisioned users are members of them. With these permissions, Brellium reads group memberships from Microsoft Graph for the users that SCIM provisions. You do not have to assign every group to the SCIM application.
The screenshots come from a Brellium test tenant. Your application name, organization name, and IDs will be different.

What Brellium can access

Both permissions are read-only. Brellium never writes to your directory.

Prerequisites

  • The Global Administrator or Privileged Role Administrator role. You need one of these roles to grant admin consent for Microsoft Graph application permissions.
  • SCIM provisioning configured for Brellium (see the SCIM Provisioning Configuration guide)
  • A Brellium account with the can edit org settings permission, with SSO and SCIM turned on for your organization (see Access the Brellium setup portal)
  • The client ID of your Brellium SSO application. In Brellium, go to Control Center > Settings. The Client ID under Single sign-on is the Application (client) ID of the app registration in Entra ID.

Access the Brellium setup portal

IT administrators can open the SSO and SCIM setup portal on their own. In Brellium, go to Control Center > Settings. The Single sign-on and Directory sync (SCIM) sections each have an Edit configuration button. Each button opens the setup portal for that connection in a new tab, so you can configure and change settings without a support ticket.
Brellium Team Settings page showing the Single sign-on connection with its Client ID, the Directory sync (SCIM) section, and an Edit configuration button for each

Brellium Control Center > Settings — the Single sign-on and Directory sync (SCIM) sections

Before you can use the setup portal, make sure that:
  1. SSO and SCIM are turned on for your organization. If you do not see the Single sign-on and Directory sync (SCIM) sections on the settings page, contact your customer success manager to turn on the feature for your organization. You can open the SSO and SCIM configuration only after the feature is on.
  2. You have the can edit org settings permission. Your Brellium account must have the can edit org settings permission under Settings. If you do not have it, ask a Brellium administrator in your organization to give it to you.
Brellium Settings permissions with can view page and can edit org settings turned on

The can edit org settings permission under Settings

Configuration steps

1

Find the SSO app registration

  1. Open the Microsoft Entra admin center.
  2. Go to Entra ID > App registrations and stay on the All applications tab.
  3. Search for your Brellium SSO application by name (for example, BRELLIUM SSO) or by the client ID from Brellium, and select it.
App registrations page with a search for BRELLIUM SSO and one result

App registrations — search for the Brellium SSO application

Use App registrations, not Enterprise apps. You add API permissions on the app registration.
2

Open API permissions

  1. Go to Manage > API permissions.
  2. Check the current list under Microsoft Graph. The SSO application already has delegated permissions such as Directory.Read.All, Group.Read.All, openid, and User.Read, all Granted for your organization. Do not change them. Sign-in uses them.
  3. Click Add a permission.
BRELLIUM SSO API permissions page with six delegated Microsoft Graph permissions granted

API permissions — the existing delegated permissions on the SSO application

Your list can be slightly different from the screenshot. What matters are the two permissions you add in the next steps.
3

Choose Microsoft Graph

In the Request API permissions panel, stay on the Microsoft APIs tab and select Microsoft Graph.
Request API permissions panel with the Microsoft APIs tab and the Microsoft Graph tile

Request API permissions — select Microsoft Graph

4

Choose application permissions

Select Application permissions (“Your application runs as a background service or daemon without a signed-in user”).
Request API permissions panel with the Delegated permissions and Application permissions options

Select Application permissions

Do not select Delegated permissions. Brellium reads group memberships in the background, with no user signed in. Delegated permissions only work while a user is signed in, so they do not give Brellium access.
5

Select the two permissions

The Select permissions list opens with a filter box at the top. Add permissions stays disabled until you select at least one permission.
Request API permissions panel showing the Select permissions list and filter box

The Select permissions list

  1. Type Group in the filter box.
  2. Under Group, select Group.ReadBasic.All (“Read all groups’ basic property”).
  3. Under GroupMember, select GroupMember.ReadBasic.All (“Read all group memberships”).
  4. Click Add permissions.
Select permissions list filtered by Group with Group.ReadBasic.All and GroupMember.ReadBasic.All checked

Group.ReadBasic.All and GroupMember.ReadBasic.All selected

Select only these two permissions. Do not select Group.ReadWrite.All, GroupMember.ReadWrite.All, or other permissions in the list. Brellium does not need them.
6

Grant admin consent

  1. Wait for the message Successfully saved permissions at the top right.
  2. Check that the list now shows Group.ReadBasic.All and GroupMember.ReadBasic.All with type Application and status Not granted for your organization.
  3. Click Grant admin consent for your organization, then click Yes.
API permissions page with Group.ReadBasic.All and GroupMember.ReadBasic.All listed as Application permissions, not granted yet

The new application permissions before admin consent

Grant consent in the same session. Until you do, the two new permissions stay Not granted and Brellium cannot read group memberships.
7

Verify that consent was granted

  1. Wait for the message Grant consent successful. The banner changes to Successfully granted admin consent for the requested permissions.
  2. Check that all permissions, including the two new Application rows, show Granted for your organization.
API permissions page with all eight Microsoft Graph permissions granted, including the two Application permissions

All permissions granted

8

Tell Brellium

Email sso.support@brellium.com or your customer success manager to say that consent is granted. Include the names of the groups Brellium should sync.Brellium uses the existing credentials of the SSO application, so you do not need to send a new secret.

Remove access

To remove Brellium’s access to group memberships:
  1. Open API permissions on the same app registration.
  2. On each of the two Application rows, click … and select Remove permission.
After you remove the permissions, Brellium only receives the groups that are assigned to the SCIM application.

Troubleshoot

Support

If you have questions or encounter issues not covered in this guide, contact the Brellium support team: