Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Azure / Microsoft Entra directory setup and acceptance. Read tenant users and account state. User inventory never grants portal access; SSO, immutable identity links and SCIM govern sign-in. Current availability: Implemented; verification required. Before you start. An authorized administrator in the correct company or the TLS owner console, with mandatory verification completed. Use an approved synthetic account for acceptance. Keep credentials, personal data and recovery codes out of recordings. Step 1. Authorize Graph User.Read.All application access for the intended tenant, grant the tenant administrator’s consent and record its immutable tenant ID. Step 2. Open Connected services > Azure / Microsoft Entra directory. In the correct company or TLS scope, enter Microsoft tenant ID, Application client ID, Client secret in the protected form. Record the provider expiry or planned rotation date. Step 3. Save and Verify read access. Confirm the returned identity and records with the vendor console. A failed verification stays a setup issue; it cannot be treated as a working connection. Step 4. Enable synchronization. Review the complete paged pass and its timestamp. Search saved records and open source links only when your provider account permits it. Step 5. Pause before offboarding or credential replacement. Saving new credentials clears verification. Recycled connections retain a 60-day recovery window, with restoration paused until reverified. Now verify the result. Minimum catalog eligibility: Standard. Selected service dependencies and an active paid subscription also apply. TLS platform credentials and company credentials remain separate. Accept one complete provider pass and a real scheduled continuation before claiming the service is connected. If you get stuck. This inventory does not create SSO links or SCIM provisioning. Configure and accept Identity & SSO separately. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.