---
title: "Azure AD - Register Application and Set Permissions"
canonical: "https://helpcenter.mindproapps.com/space/SDC/2347729419/Azure%20AD%20-%20Register%20Application%20and%20Set%20Permissions"
format: markdown
---
> ℹ️ **Summary: **Learn how to set application and permissions in Entra ID / Azure AD before connecting with the app.

### **Registering Mindpro Sync as an application in Entra ID / Azure AD: **


Before using the app, make sure you have Mindpro Sync registered in your Entra ID / Azure AD instance and set the permissions to allow the system to see and map the attributes. 


From the Entra ID / Azure Main screen, select the "App Registration" under the “Applications” option:

![Mindpro-1716484295737-1x.png](media://a15765e7-6ddf-4d5f-b49c-8e44cca56e98)


Then, click on “+ New Registration” to proceed:

![Mindpro-1716484906671-1x.png](media://590a931c-0be8-42a6-a4b3-911c346e57d0)


Enter the application name, leave all options as they appear on the screen, and click on “Register”:

![Mindpro-1716485074348-1x.png](media://1094b371-9276-48d1-8b47-fecafb07b48f)


Now, from the just created app’s “Overview” screen, click to add a new client secret:

![Mindpro-1716487283706-1x.png](media://4351979d-6ea9-4bee-bbb0-c006de9ea6fd)


The “Certificates & secrets” screen will open. Click on “+ New client secret”:

![Mindpro-1716487366870-1x.png](media://14e490e1-b15b-467f-87cd-090e081be4a0)


From the panel on the right, enter the secret description and duration, and click on “Add":

![Mindpro-1716487476673-1x.png](media://369ec9a9-45de-46c4-9540-4a47cf8a7ff6)


Copy the content from the “Value” field and** paste it into another place to be used later**:

![Mindpro-1716487575163-1x.png](media://d19efdbe-f04b-4bf6-8f64-137f1dcdcc4e)

> ⚠️ **Important**:
> ⚠️ 
> ⚠️ If you do not copy this value, the next time you access this screen, the secret will appear masked, and you may need to create a new one to copy the value.



Next, click on the “Owners” option from the left menu and then on the “Add Onwers” button to assign the application to the respective users:

![Mindpro-1716487717181-1x.png](media://71016644-294e-4ae8-9902-0c7bd63daea4)

   


Choose the users you want to assign to this application and click on “Select":

![Mindpro-1716487815802-1x.png](media://6dcb1628-6458-43dc-8ea9-60f747c45493)


The selected users will be added to the list:

![Mindpro-1716487891874-1x.png](media://98803657-1dd4-4911-b1d9-df8dad3e9a31)

---


### **Setting permissions to the application:**


From the left menu, click on the "App Registration"  option and select the application you want to configure (the example below is just a suggestion):

![Mindpro-1716488105296-1x.png](media://ec1f87e4-c7a7-4ccd-9274-fc4534bcc032)


After accessing the Application screen, click on "API Permissions" from the left menu. The permissions will be displayed. In case you don't have any, click on  "+ Add Permission": 

![Mindpro-1716488515587-1x.png](media://d94a3cbc-4c42-4638-b282-108896e25b3b)


From the right pop-up menu, click on "Microsoft Graph" and then select "Application Permissions", as below:

![Mindpro-1716488677460-1x.png](media://1e404606-3831-4a7f-b773-96b7fa5fc5dc)

![Mindpro-1716488835304-1x.png](media://ee62477f-2f9a-4af7-a7d2-6b52cefd2b1d)


Find the "User" option, expand it, and check the "**User.Read.All**" checkbox. Then, click on "Add permissions":

![Mindpro-1716488964802-1x.png](media://6407cad7-793c-4302-8ff7-f4c5b3ec1b6b)


> ✅ **Pro Tip**
> ✅ 
> ✅ In case you work with [Extension Attributes](https://mindpro.atlassian.net/wiki/spaces/SDC/pages/2347729681/Azure+AD+-+Available+Attributes#Azure-AD-Extension-Attributes) in Entra ID / Azure AD, we recommend you select the “**User.ReadWrite.All**” checkbox as well, so Mindpro Sync can also read these fields during the mapping process.


Back to the permissions screen, make sure to grant Admin consent to your company/directory/user, clicking on "Grand admin consent for...". The system will update the permissions: 

![Mindpro-1716489402264-1x.png](media://18e916d7-8a19-4799-97f1-5fd20ad4a797)


After completing these steps you will have the Entra ID / Azure AD set with the necessary permissions to work with Mindpro Sync.


> ℹ️ **Good to know**
> ℹ️ 
> ℹ️ These are the minimum permissions required to allow Mindpro Sync to map your attributes from Entra ID / Azure AD. You can add additional ones depending on your internal policies (i.e.: Directory.Read.All).

---

### **Need any help?**

Didn’t find what you were looking for? Raise a ticket [here](https://mindpro.atlassian.net/servicedesk/customer/portal/3) or get in touch at [support@mindproapps.com](mailto:support@mindproapps.com)