Google Workspace
Connect your Google Workspace organization to enable SaaS discovery, identity sync, and automated provisioning.
Microsoft Entra ID
Connect your Microsoft Entra ID (formerly Azure AD) tenant to enable identity sync and automated provisioning.
Google Workspace
What connecting Google Workspace enables
- SaaS Discovery — automatically detect all apps accessed using Google sign-in across your organization.
- Identity sync — import your users and groups from Google Workspace.
- Automated provisioning — create, update, and suspend Google Workspace accounts as part of onboarding/offboarding workflows.
- Data transfer at offboarding — transfer Drive files and email ownership when an employee leaves.
Connect Google Workspace
Authenticate with a Google Workspace Super Admin account
You must authenticate as a Super Administrator to grant the required permissions.
Authorize the required scopes
Primo requests read access to users, groups, and org units — and write access for provisioning and offboarding actions.
What Primo accesses in Google Workspace
| Data | Purpose |
|---|---|
| Users (name, email, status) | Identity sync and provisioning |
| Groups and org units | Apply provisioning rules |
| OAuth app access | SaaS Discovery mapping |
| Drive (at offboarding only) | File ownership transfer |
Microsoft Entra ID
What connecting Entra ID enables
- Identity sync — import users and groups from your Entra tenant.
- Automated provisioning — create, update, and disable Entra accounts as part of onboarding/offboarding.
- Mac login via Entra — allow employees to log in to their Mac with their Entra credentials (see Entra Platform SSO).
SaaS Discovery via Entra is not yet available. Use the Chrome Extension for broader SaaS coverage. See Activate SaaS Discovery.
Connect Microsoft Entra ID
Sign in as an Entra Global Administrator
You need Global Admin or a delegated admin role with the required API permissions.
Grant the required Microsoft Graph permissions
Primo requests permissions to read and write users, groups, and directory data.
What Primo accesses in Entra ID
| Data | Purpose |
|---|---|
| Users (name, email, status, attributes) | Identity sync and provisioning |
| Groups | Apply provisioning rules |
| Application assignments | SaaS visibility |