Microsoft Entra ID + Kroy

Connect Microsoft Entra ID once. Use it safely with any AI.

  1. Microsoft Entra ID, where it already is.

    Microsoft Entra ID stays the authoritative record. Nothing moves, and nothing is copied that doesn’t need to be.

  2. Microsoft Entra ID connects to Kroy.

    OpenID Connect sign-in with Microsoft Entra ID, plus an app registration with administrator consent for reading users and groups. Kroy holds the connection.

  3. Your AI connects to Kroy.

    Claude, ChatGPT or another AI connects to Kroy — not to Microsoft Entra ID. It never receives Microsoft Entra ID credentials.

  4. Exactly what is allowed.

    Each Microsoft Entra ID action is a Kroy capability. Kroy reads identity information. It does not create, change or delete users or groups in Entra ID.

  5. A real request.

    Claude asks for read users. Kroy checks the person, the agent and the policy, calls Microsoft Entra ID, and records the request.

Microsoft Entra ID
Kroy
Claude
Priya Client manager
AUDIT

Microsoft Entra ID capabilities

  • entra.users.read
  • entra.groups.read
  • entra.group_members.read
  • Kroy reads identity information. It d…
Microsoft Entra ID
Kroy
Claude
Priya Client manager
AUDIT

Microsoft Entra ID capabilities

  • entra.users.read
  • entra.groups.read
  • entra.group_members.read
  • Kroy reads identity information. It d…
Microsoft Entra ID connecting to Kroy, then to an authorised AI. Microsoft Entra ID, where it already is.. Microsoft Entra ID connects to Kroy.. Your AI connects to Kroy.. Exactly what is allowed.. A real request..

Supported resources

  • Users (sign-in identity, name, email, account status)
  • Security groups and group membership

Authentication

OpenID Connect sign-in with Microsoft Entra ID, plus an app registration with administrator consent for reading users and groups. Kroy holds the credentials; AI clients never receive Entra tokens.

Supported actions

CapabilityTypeDefault
entra.users.read
Read users
readPolicy
entra.groups.read
Read groups
readPolicy
entra.group_members.read
Read group membership
readPolicy

Events

entra.user.disabledentra.group_membership.changed

Overview

When an AI tool acts in your organisation, two questions matter: which agent is this, and which person is it acting for? Kroy answers the second with the identity system you already run.

People sign in to Kroy with Microsoft Entra ID. Kroy then links every AI agent they use — Claude, ChatGPT, Copilot or an internal agent — to that person through a delegation. Every request carries both: the agent and the human behind it.

Groups become roles

Kroy can map Entra security groups to Kroy roles. Members of Audit – Managers receive the Kroy role that sees audit clients; members of Partners can approve external communication. Your IT team keeps managing membership where it already does, and Kroy applies it to AI.

People, agents and delegation

Entra ID knows your people. Kroy adds what an identity provider does not usually model: which agents may act for which person, for which tasks, with which Skills and until when. Kroy decides each request against the person, the agent, the delegation, the policy and any approval.

Leavers and changes

When someone leaves and IT disables their Entra account, Kroy treats their access — and every delegation from them to an AI agent — as ended. When someone moves teams, their Kroy role follows their group membership.

Industries

Law firms and financial services firms often need to show who could see what, and when. Tying AI access to managed identities makes that record straightforward to produce.

Security

Kroy holds the app registration credentials. AI clients never receive Entra tokens and cannot sign in as a person. Every sign-in, delegation, request and refusal is recorded against a named identity.

Limitations

  • Kroy reads identity information. It does not create, change or delete users or groups in Entra ID.
  • Kroy does not replace your Entra conditional access policies; they continue to apply at sign-in.
  • How quickly a change in Entra reaches Kroy depends on how synchronisation is configured.
  • Agent identities are managed in Kroy. Kroy links each agent to the person or team it acts for.