Understanding equipme's access to your Entra data
Here you will find detailed technical information about which data equipme has access to through the Microsoft Entra SSO setup.
What equipme actually requests: openid, email, profile
The integration uses only three standard OpenID Connect scopes:
openid Required for all OIDC logins. Provides the user’s unique identifier (sub) and the security framework of the token.
email Provides the user’s primary email address.
profile Provides basic profile information such as name, given name and family name.
No additional scopes or Graph API permissions are used. Nothing beyond identity-level data is requested.
Identity claims returned by Entra ID
Based on these scopes, Microsoft Entra ID includes the following user-related fields in the ID token:
sub Unique identifier of the user inside the Microsoft tenant.
email Primary email address.
name Full display name.
given_name First name.
family_name Last name.
preferred_username Login identifier inside Entra ID (often identical to the email).
oid Object ID of the user in the directory. Common in Entra-based tokens.
In addition to these identity claims, the token also includes standard OIDC protocol fields such as:
iss, aud, iat, exp, nonce, tid
These protocol fields are required for validation but are not processed as user attributes.
equipme uses only the identity-related claims to authenticate and match the user. All other values in the token are ignored after verification.
No access to directory data
Because equipme uses only the scopes openid, email and profile, the application does not access or receive:
directory roles
security groups
group memberships
custom attributes
organisational units
job titles
manager relationships
phone numbers
device information
Microsoft Graph API data
The integration does not request permissions such as Directory.Read.All, User.Read.All, or any elevated access.
This keeps the authentication flow strictly limited to identity confirmation.
Understanding the consent screen
When an admin completes the Microsoft consent, Microsoft displays two permission descriptions. These look broader than the underlying scopes, but they refer to standard OIDC behavior.
“View your basic profile” This corresponds directly to the scopes openid, email and profile. It includes only name, email and the basic identity claims listed above.
“Maintain access to data you have given it access to” This does not grant additional rights. It means the consent stays active until it is manually revoked. The application does not gain extra directory permissions from this statement.
Microsoft shows these descriptions for all OIDC apps, even when only the minimal scopes are used.
Why permissions inside equipme remain separate
Even though Entra ID confirms the user’s identity, equipme does not inherit or rely on:
Entra roles
group memberships
conditional access structures
role-based access control in the tenant
All permissions inside equipme — including roles, access levels, and what a user can see or do — are fully controlled within equipme.
This separation avoids complex mapping rules and ensures consistent behavior across all customers.
SSO vs HR Sync
SSO handles authentication only.
It does not import:
department
location
job role
employment status
custom fields
organisational data
If you want to synchronise user and organisational data automatically from your HR system or directory service, this is done via HR Sync and not via SSO.
Last updated
Was this helpful?