Skip to main content
DSALTA connects to Microsoft Entra ID using read-only API access to collect compliance evidence automatically. Data feeds into your Data Library modules. Compliance checks re-run once a day at 02:00 America/New_York.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Microsoft Entra ID environment.

What DSALTA reads

DSALTA reads the Microsoft Entra ID user roster — names, emails, the Entra account type that fills the role column (Member, Guest or User) and active status, which appear on your Access page. It also reads your directory groups and their members, which populate the Groups tab of your People page.It calls these Microsoft Entra ID endpoints:
  • /organization
  • /users
  • /groups
  • /groups/{groupId}/members
  • /reports/authenticationMethods/userRegistrationDetails
  • /policies/identitySecurityDefaultsEnforcementPolicy
  • /identity/conditionalAccess/policies
Permissions the checks require: User.Read.All, Group.Read.All, Directory.Read.All, Policy.Read.All, AuditLog.Read.AllEvery request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Microsoft Entra ID environment.

Troubleshooting

There is no Reconnect button. Open Integrations → Connected, click Manage on the Microsoft Entra ID card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from Microsoft Entra ID. This usually happens when API tokens expire.
Verify the connected account still holds the permissions listed under Before you begin. Then open Integrations in the DSALTA sidebar, stay on the Connected tab, and click Sync from integrations at the top right. That button refreshes every connected integration at once — there is no per-integration sync control.