# Integrating Entra ID to DEX Manager Plus **Last Updated On**: 03 Mar 2026 **9 minutes read** Entra ID (formerly known as Azure Active Directory) is a cloud-based identity and access management service developed by Microsoft. It provides centralized management of user identities, authentication, and authorization for cloud-based applications and services. By integrating Entra ID with DEX Manager Plus, customers can synchronize user, computer, and group data, streamlining IT operations and enhancing management efficiency within DEX Manager Plus. ## Pre-Requisites for Setup ### Prerequisites Before integrating Entra ID with DEX Manager Plus, ensure the following requirements are met: - **Entra ID Subscription:** Ensure you have an active Entra ID subscription (e.g., Entra ID Free, Premium P1, or Premium P2). - **DEX Manager Plus Access:** You must have access to the DEX Manager Plus platform with at least SoM Full Control and All Computers Scope / Administrator permissions to configure the Entra ID integration. - **SSL Certificate: (Optional)** An SSL certificate can be installed on the server hosting DEX Manager Plus to ensure secure communication during synchronization. - **Configure NAT Settings:** [Configure NAT settings](https://www.manageengine.com/help/modulename/nat-settings.html) to allow communication between DEX Manager Plus and Entra ID. ## Steps to Add an Entra ID Domain Follow the steps below to add an Entra ID domain to DEX Manager Plus. 1. **Navigate to Domain Settings in DEX Manager Plus:** Go to the Agent tab. Select Domain and then click on Add Domain. 2. **Select Entra ID as Domain Type:** Click on Add Domain and select Entra ID from the available domain types. Select the specific Entra ID services you wish to integrate (e.g., Global, DoD, etc.). ![Select Entra ID domain type](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-1.webp) **Note:** DEX Manager Plus supports integration with various Entra ID services, including Global, US Govt L4, L5 (DoD) and China operated by 21Via Net. 3. **Register the DEX Manager Plus Application with Entra ID:** - Log in to the Azure Portal. - Navigate to App registrations and click on New registration. ![Azure New App Registration](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-3.webp) - Provide a name for the Azure OAuth app (e.g., UEMS). - Under Supported account types, select Multitenant. ![Select Supported account types](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-4.webp) **Note:** The same app registration can be used for all tenants within your organization. - Select Web as the Redirect URI, and copy the Redirect URI from the MDM console to enter it here. ![Set Redirect URI - Part 1](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-5.webp) ![Set Redirect URI - Part 2](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-6.webp) - Click on Register. 4. **Obtain Client ID and Client Secret:** - Once the Azure OAuth app is registered, go to the Overview page of the registered app and copy the Client ID. ![Copy Client ID](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-7.webp) - To generate the Client Secret, navigate to the Certificate & Secrets section in the left panel, then go to Client secrets and click New client secret. ![Create new client secret](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-8.webp) - Provide a description and set the expiry days, or you can choose a custom date. Click Add. ![Set client secret expiry](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-9.webp) - Copy the Client Secret provided in the Value column. ![Copy client secret value](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-10.webp) 5. **Provide Client ID and Client Secret in DEX Manager Plus:** - Go to the DEX Manager Plus Entra ID Domain Addition page and provide the Client ID, Client Secret, and Client Secret Expiry Date. Click Add domain. ![Enter OAuth details in ](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-11.webp) **Note:** If you have already registered the application, you will be prompted to Authenticate. - Click Authenticate. - You will be redirected to the Microsoft Azure Login page. After logging in, a consent screen will be displayed for integration consent. - Click Accept. ![Consent screen](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-12.webp) 6. **Configure Sync Frequency:** After authentication and accepting the consent from Azure Portal, return to DEX Manager Plus and configure the sync frequency for the Entra ID domain. Choose from the following frequency options: - Every 6 hours - Twice a day - Once a day - Select the Timezone based on your Entra ID timezone. ![Configure sync frequency and timezone](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-13.webp) - You can also initiate an On-demand Sync by using the Sync action available in the action button. ![On-demand Sync action](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-14.webp) ## Managing Entra ID Domain Once the Entra ID domain is added, you can manage it through the Actions menu. 1. **Add Computers:** To add Entra ID computers, select the domain, navigate to Actions, and click Add Computers. ![Add Computers from Actions](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-15.webp) 2. **Sync Now:** To initiate a sync immediately, navigate to the Actions menu for the corresponding domain and click Sync Now. ![Sync Now action](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-14.webp) **Note:** You can only initiate a manual sync 4 times per day. 3. **Modify Domain:** To edit domain details, navigate to the Actions menu of the corresponding domain and click Modify Domain. ![Modify Domain](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-18.webp) **Note:** This option is only applicable to Windows Server Active Directory. 4. **Modify Sync Details:** To update the sync frequency or start time, navigate to the Actions menu of the corresponding domain and click Modify Sync Details. ![Modify Sync Details](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-16.webp) 5. **Delete Domain:** To delete a domain, navigate to the Actions menu of the corresponding domain and click Delete. ![Delete Domain](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-17.webp) **Warning:** Deleting a domain will erase all associated data for that domain. A domain cannot be deleted unless all the managed computers are removed from the Scope of Management. 6. **Change to Workgroup:** To convert a domain-based device to a workgroup, select the domain, click the corresponding action, and choose Change to Workgroup. ![Change to Workgroup](https://cdn.manageengine.com/sites/meweb/images/digital-employee-experience/help/device-onboarding/msentraad-19.webp) **Note:** This option is only applicable to Windows Server Active Directory. ## Troubleshooting Entra ID Configuration If you encounter issues during the Entra ID configuration or syncing process, consider the following steps: - **Check Network Connectivity:** Ensure that the server running DEX Manager Plus has proper network connectivity to Entra ID. - **Verify API Permissions:** Ensure that the app registered in Entra ID has sufficient API permissions to access directory data. - **Check SSL Certificate: (Optional)** Verify that your SSL certificate is correctly installed and valid for secure communication between DEX Manager Plus and Entra ID. - **Review Sync Frequency:** Ensure that the sync frequency is configured correctly based on your organization's requirements. - **Check for Valid Client ID/Secret:** Ensure that the provided Client ID/Secret is valid or has not reached the expiry date. If not, get the Client ID and Secret value from the Azure Portal, update it in the OAuth details available in the OAuth tab, and reauthenticate domains.