NEWFreshservice is now a Ploy integrationSee what shipped
INTEGRATIONSIDENTITY PROVIDER
Microsoft28 OF 28 CAPABILITIES ASSESSED

Entra groups, admin roles and licences are granted from Ploy

Entra ID users, groups, directory roles and app assignments, with sessions revoked and licences reclaimed.

TYPE · IDPAUTH · OAUTH + SCIMDOMAIN · MICROSOFT.COM
Microsoft connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync users, service principals and app registrationsEvery Entra identity, human and non-human, with whether it is active or blocked, when it last signed in and which multi-factor methods are registered. App registrations resolve to the service principals that act for them.
READ
Import Entra profiles as peopleUser profiles arrive as member records carrying the fields policy reads: name, email, manager, department, location and employment dates.
READ
Discover groups, admin roles, access packages, licences and devicesThe grantable things in Entra and who holds each of them, including the access a group carries such as admin roles and conditional access policy targets.
READ
Find enterprise applications and read the sign-in trailEnterprise applications arrive with the OAuth grants behind them. Sign-in and audit events land too, successful and failed, with their IP and location context.
READ
Create, update, suspend and delete accountsPloy opens the account or cross-tenant guest invite a joiner needs, keeps it in step with a move, and blocks or deletes it on a leaver. A delete is Entra soft delete, so the account lands in deleted items rather than vanishing.
WRITE
Grant and revoke groups, admin roles, access packages and calendar permissionsThe grant path for Entra access, and Ploy can create the security or Microsoft 365 group a new grant needs.
WRITE
Reset a password, revoke every session and clear MFA methodsRevokes OAuth tokens and invalidates all active sign-in sessions, and clears the registered factors when a device is lost.
WRITE
Assign and reclaim licence seats, and delete a deviceA leaver hands their SKU back to the pool rather than billing on, and a device can be removed from the tenant.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

ACCOUNTS

The Entra account arrives with the joiner

Ploy creates the user, or the cross-tenant guest invite for a contractor, assigns the licence and puts them in the groups the role calls for.

ACCESS

Groups, roles and access packages are the grant

An approved request writes membership straight into Entra, creating the security or Microsoft 365 group where none exists yet, and pulls it back when the window closes.

OFFBOARDING

Every session ends, not just the password

On the last working day Ploy blocks the account, revokes the OAuth tokens and invalidates every active sign-in session, reclaims the licence and deletes the device from the tenant.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Authorise the app

An admin approves the Ploy app in Microsoft. Read only to begin with.

STEP 02

Watch the first sync

Users, groups and app assignments land in the graph.

STEP 03

Turn on writes

Pick which groups and apps Ploy may change, and who approves.

2.4OFTEN CONNECTED TOGETHER
WorkdayHR SOURCESlackAPPROVALSGitHubSOURCE CONTROL
BROWSE ALL 62 INTEGRATIONS

Connect Microsoft, see it in 10 minutes.