ePO - On-prem supports Microsoft Entra ID and GCC High Entra ID for registered directory servers. Use this procedure to connect your on-premises environment with your identity provider to enable user-based policies and group synchronization.
Note
Only change the default service URL under Server Settings → Microsoft Entra ID if the service location changes. Incorrect URL settings cause connection failures. If you change this URL, you must restart the ePO - On-prem services for the changes to take effect.
Log in to ePO - On-prem with your credentials.
From Menu, go to Configuration → Registered Servers and select the Server Type as Directory Server.
Click on New Server and enter a name.
Select Directory server type as Microsoft Entra ID (Azure AD).
Enter the client credentials obtained from Azure portal.
Copy the Directory (tenant) ID to the Tenant GUID field.
Copy the Application (client) ID to the Client ID field.
Copy the Secret Value string to the Client ID Secret field.
Perform a Test Connection and Save the configuration.
Note
For policy enforcement for any Entra ID users or groups, ensure the Database Mirroring Enabled option for User policies from Server Settings is set to Yes for any product which uses User-Based Policies (UBP).