diff --git a/docs/reference/providers/provider-entraID.md b/docs/reference/providers/provider-entraID.md index d27c71d0..edfba868 100644 --- a/docs/reference/providers/provider-entraID.md +++ b/docs/reference/providers/provider-entraID.md @@ -11,16 +11,16 @@ import EntraLeaver from '@site/../examples/workflows/templates/entraid-leaver.ps ## Summary - **Module:** `IdLE.Provider.EntraID` -- **What it’s for:** Entra ID user lifecycle + group entitlements (Microsoft Graph API) +- **What it’s for:** Entra ID user lifecycle + group and Administrative Unit entitlements (Microsoft Graph API) - **Targets:** Microsoft Entra ID (formerly Azure AD) via Microsoft Graph (v1.0) ## When to use Use this provider when your workflow needs to manage **Entra ID user accounts**, for example: -- **Joiner:** create or update a user, set baseline attributes, assign baseline groups +- **Joiner:** create or update a user, set baseline attributes, assign baseline groups and Administrative Units - **Mover:** update org attributes and managed groups (covered as *optional patterns* inside the Joiner template) -- **Leaver:** disable account, revoke sessions, optional cleanup (groups, delete) +- **Leaver:** disable account, revoke sessions, optional cleanup (groups, Administrative Units, delete) Non-goals: @@ -32,7 +32,7 @@ Non-goals: ### Requirements - Your runtime must be able to supply a **Microsoft Graph auth session** (token/session object) to IdLE -- Graph permissions must allow the actions you intend to run (users + groups) +- Graph permissions must allow the actions you intend to run (users, groups, Administrative Units) ### Install (PowerShell Gallery) @@ -127,14 +127,22 @@ Writes to scoped path: `Request.Context.Providers..