> ## Documentation Index
> Fetch the complete documentation index at: https://sso.brellium.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Graph Permissions for Group Sync

> Grant Brellium read-only access to group memberships in Microsoft Entra ID so Brellium can sync groups that are not assigned to the SCIM application

This guide adds two read-only Microsoft Graph permissions to your existing Brellium SSO application and grants admin consent for your organization. It takes about 5 minutes.

## When you need this

SCIM provisioning only pushes groups that are **directly assigned** to the Brellium SCIM enterprise application. Microsoft Entra ID does not send any other groups, even if provisioned users are members of them.

| Your setup | Graph permissions |
| - | - |
| Brellium only needs the groups that are assigned to the SCIM application | Not needed |
| Brellium also needs groups that are **not** assigned to the SCIM application (for example, location or department groups) | **Required** |

With these permissions, Brellium reads group memberships from Microsoft Graph for the users that SCIM provisions. You do not have to assign every group to the SCIM application.

<Note>
  The screenshots come from a Brellium test tenant. Your application name, organization name, and IDs will be different.
</Note>

## What Brellium can access

| API | Permission | Type | Access |
| - | - | - | - |
| Microsoft Graph | `Group.ReadBasic.All` | Application | Read the basic properties of groups, such as the display name |
| Microsoft Graph | `GroupMember.ReadBasic.All` | Application | Read group memberships |

Both permissions are read-only. Brellium never writes to your directory.

## Prerequisites

* The **Global Administrator** or **Privileged Role Administrator** role. You need one of these roles to grant admin consent for Microsoft Graph application permissions.
* SCIM provisioning configured for Brellium (see the [SCIM Provisioning Configuration guide](/integrations/azure-ad-scim))
* A Brellium account with the **can edit org settings** permission, with SSO and SCIM turned on for your organization (see [Access the Brellium setup portal](#access-the-brellium-setup-portal))
* The client ID of your Brellium SSO application. In Brellium, go to [Control Center > Settings](https://app.brellium.com/settings). The **Client ID** under **Single sign-on** is the **Application (client) ID** of the app registration in Entra ID.

## Access the Brellium setup portal

IT administrators can open the SSO and SCIM setup portal on their own. In Brellium, go to [Control Center > Settings](https://app.brellium.com/settings). The **Single sign-on** and **Directory sync (SCIM)** sections each have an **Edit configuration** button. Each button opens the setup portal for that connection in a new tab, so you can configure and change settings without a support ticket.

<Frame caption="Brellium Control Center > Settings — the Single sign-on and Directory sync (SCIM) sections">
  <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/brellium-settings/settings-page.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=e1c848dc76ea414af11b6960e0ed44cf" alt="Brellium Team Settings page showing the Single sign-on connection with its Client ID, the Directory sync (SCIM) section, and an Edit configuration button for each" width="2784" height="2226" data-path="images/brellium-settings/settings-page.png" />
</Frame>

Before you can use the setup portal, make sure that:

1. **SSO and SCIM are turned on for your organization.** If you do not see the **Single sign-on** and **Directory sync (SCIM)** sections on the settings page, contact your customer success manager to turn on the feature for your organization. You can open the SSO and SCIM configuration only after the feature is on.
2. **You have the can edit org settings permission.** Your Brellium account must have the **can edit org settings** permission under **Settings**. If you do not have it, ask a Brellium administrator in your organization to give it to you.

<Frame caption="The can edit org settings permission under Settings">
  <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/brellium-settings/can-edit-org-settings.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=5c9af158d83c6994722245404b949640" alt="Brellium Settings permissions with can view page and can edit org settings turned on" width="1554" height="158" data-path="images/brellium-settings/can-edit-org-settings.png" />
</Frame>

## Configuration steps

<Steps>
  <Step title="Find the SSO app registration">
    1. Open the [Microsoft Entra admin center](https://entra.microsoft.com).
    2. Go to **Entra ID** > **App registrations** and stay on the **All applications** tab.
    3. Search for your Brellium SSO application by name (for example, `BRELLIUM SSO`) or by the client ID from Brellium, and select it.

    <Frame caption="App registrations — search for the Brellium SSO application">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/01-app-registrations.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=96117ac96ece790e1f44a46148066912" alt="App registrations page with a search for BRELLIUM SSO and one result" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/01-app-registrations.png" />
    </Frame>

    <Note>
      Use **App registrations**, not **Enterprise apps**. You add API permissions on the app registration.
    </Note>
  </Step>

  <Step title="Open API permissions">
    1. Go to **Manage** > **API permissions**.
    2. Check the current list under **Microsoft Graph**. The SSO application already has delegated permissions such as `Directory.Read.All`, `Group.Read.All`, `openid`, and `User.Read`, all **Granted for** your organization. Do not change them. Sign-in uses them.
    3. Click **Add a permission**.

    <Frame caption="API permissions — the existing delegated permissions on the SSO application">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/02-api-permissions.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=71bd3671a0be05068ba9c2e2939e33e5" alt="BRELLIUM SSO API permissions page with six delegated Microsoft Graph permissions granted" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/02-api-permissions.png" />
    </Frame>

    <Note>
      Your list can be slightly different from the screenshot. What matters are the two permissions you add in the next steps.
    </Note>
  </Step>

  <Step title="Choose Microsoft Graph">
    In the **Request API permissions** panel, stay on the **Microsoft APIs** tab and select **Microsoft Graph**.

    <Frame caption="Request API permissions — select Microsoft Graph">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/03-microsoft-graph.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=5da4866d4a4fcf4e751fe0e2422760f0" alt="Request API permissions panel with the Microsoft APIs tab and the Microsoft Graph tile" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/03-microsoft-graph.png" />
    </Frame>
  </Step>

  <Step title="Choose application permissions">
    Select **Application permissions** ("Your application runs as a background service or daemon without a signed-in user").

    <Frame caption="Select Application permissions">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/04-application-permissions.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=79c7bee173679bbb5b75a36992265e1a" alt="Request API permissions panel with the Delegated permissions and Application permissions options" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/04-application-permissions.png" />
    </Frame>

    <Warning>
      Do not select **Delegated permissions**. Brellium reads group memberships in the background, with no user signed in. Delegated permissions only work while a user is signed in, so they do not give Brellium access.
    </Warning>
  </Step>

  <Step title="Select the two permissions">
    The **Select permissions** list opens with a filter box at the top. **Add permissions** stays disabled until you select at least one permission.

    <Frame caption="The Select permissions list">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/05-select-permissions.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=cbeb4b03620095acc4de60a9bde16470" alt="Request API permissions panel showing the Select permissions list and filter box" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/05-select-permissions.png" />
    </Frame>

    1. Type `Group` in the filter box.
    2. Under **Group**, select `Group.ReadBasic.All` ("Read all groups' basic property").
    3. Under **GroupMember**, select `GroupMember.ReadBasic.All` ("Read all group memberships").
    4. Click **Add permissions**.

    <Frame caption="Group.ReadBasic.All and GroupMember.ReadBasic.All selected">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/06-group-permissions-selected.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=d0ac6ee44750b7ba2f68fa6f9365f93f" alt="Select permissions list filtered by Group with Group.ReadBasic.All and GroupMember.ReadBasic.All checked" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/06-group-permissions-selected.png" />
    </Frame>

    <Warning>
      Select only these two permissions. Do not select `Group.ReadWrite.All`, `GroupMember.ReadWrite.All`, or other permissions in the list. Brellium does not need them.
    </Warning>
  </Step>

  <Step title="Grant admin consent">
    1. Wait for the message **Successfully saved permissions** at the top right.
    2. Check that the list now shows `Group.ReadBasic.All` and `GroupMember.ReadBasic.All` with type **Application** and status **Not granted for** your organization.
    3. Click **Grant admin consent for** your organization, then click **Yes**.

    <Frame caption="The new application permissions before admin consent">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/07-not-granted.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=ba8b76ff724e7995cda1b7a0f35c5efb" alt="API permissions page with Group.ReadBasic.All and GroupMember.ReadBasic.All listed as Application permissions, not granted yet" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/07-not-granted.png" />
    </Frame>

    <Warning>
      Grant consent in the same session. Until you do, the two new permissions stay **Not granted** and Brellium cannot read group memberships.
    </Warning>
  </Step>

  <Step title="Verify that consent was granted">
    1. Wait for the message **Grant consent successful**. The banner changes to **Successfully granted admin consent for the requested permissions**.
    2. Check that all permissions, including the two new **Application** rows, show **Granted for** your organization.

    <Frame caption="All permissions granted">
      <img src="https://mintcdn.com/brellium/o9lDwwnSccBrrsWA/images/azure-ad/graph-permissions/08-consent-granted.png?fit=max&auto=format&n=o9lDwwnSccBrrsWA&q=85&s=1d451dd280975c4e89dc2ed29745c568" alt="API permissions page with all eight Microsoft Graph permissions granted, including the two Application permissions" width="2788" height="2218" data-path="images/azure-ad/graph-permissions/08-consent-granted.png" />
    </Frame>
  </Step>

  <Step title="Tell Brellium">
    Email [sso.support@brellium.com](mailto:sso.support@brellium.com) or your customer success manager to say that consent is granted. Include the names of the groups Brellium should sync.

    Brellium uses the existing credentials of the SSO application, so you do not need to send a new secret.
  </Step>
</Steps>

## Remove access

To remove Brellium's access to group memberships:

1. Open **API permissions** on the same app registration.
2. On each of the two **Application** rows, click **...** and select **Remove permission**.

<Note>
  After you remove the permissions, Brellium only receives the groups that are assigned to the SCIM application.
</Note>

## Troubleshoot

| Issue | Cause | Solution |
| - | - | - |
| **Grant admin consent** is disabled | Your role cannot grant admin consent | Ask a Global Administrator or Privileged Role Administrator to grant consent |
| The permissions show **Not granted** | Admin consent was not granted | Click **Grant admin consent for** your organization and confirm |
| The new permissions show type **Delegated** | **Delegated permissions** was selected | Remove the delegated rows, then add the permissions again as **Application permissions** |
| Groups that are not assigned to the SCIM application still do not appear in Brellium | Brellium was not told that consent is granted, or the users are not provisioned | Contact [Brellium support](mailto:sso.support@brellium.com). Brellium only reads groups for users that SCIM provisions. |

## Support

If you have questions or encounter issues not covered in this guide, contact the Brellium support team:

* **Email**: [sso.support@brellium.com](mailto:sso.support@brellium.com)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.