Home / Integrations / Azure Active Directory
Connect Azure Active Directory to Salesforce Agentforce
Azure Active Directory — now Microsoft Entra ID — is the identity platform that enterprise organisations on the Microsoft stack use to manage users, groups, application access, and single sign-on across the application estate. Salesforce holds the commercial and customer record for the same organisation. When headcount changes, Azure AD is where new accounts are created and departing employees are removed — and Salesforce should reflect those changes promptly. When a customer has an access problem, Azure AD holds the group membership and licence assignment that determines what they should be able to reach. When Emerge Digital connects Azure AD to Agentforce, identity events drive CRM provisioning and service agents can answer access questions from live identity data rather than routing every inquiry to IT.
What this unlocks
- User and group context readable during service conversations: when a customer reports an access problem, an agent can read their Azure AD object — application assignments, group memberships, account enabled state — and diagnose the issue before engaging rather than escalating every login problem to IT.
- New hire and provisioning events trigger CRM setup: when a new user is created in Azure AD for a sales or service role, an agent can trigger the Salesforce user provisioning workflow — creating the account, assigning the profile and territory, and routing the onboarding task — so new employees start with a working CRM from day one.
- Account disable or deletion triggers CRM deprovisioning: when an Azure AD account is disabled or deleted for a departing employee, an agent can revoke their Salesforce access, reassign their accounts and opportunities, and log the transition — so the access removal and the account handoff happen together rather than in separate processes.
- Group membership as access governance signal: Azure AD group membership often encodes application entitlement — an agent can read group membership to verify whether a user should have access to a specific Salesforce feature or external system before taking action on their behalf.
In the customer journey
Access problem answered from identity data
A customer contacts support unable to access a specific product feature. The agent reads their Azure AD group memberships and application assignments — the relevant licence assignment is missing from a group they should be in. The agent identifies the provisioning gap, logs it, and routes a targeted fix request to IT rather than asking the customer to reset their password or try a generic troubleshooting step that will not resolve a missing entitlement.
New hire in Azure AD — Salesforce provisioned automatically
A new sales hire is created in Azure AD as part of the IT onboarding process. The agent reads the user object, identifies the role and department, creates the Salesforce user with the correct profile and territory assignment, and notifies Sales Ops. The new rep arrives with a working CRM account on their first day.
Azure AD disable triggers account transition
An employee's Azure AD account is disabled on their departure date. The agent detects the disable event, identifies their Salesforce accounts, open opportunities, and service cases, reassigns each according to the succession plan, and removes their Salesforce access — so the handoff is clean and timely without a separate IT ticket.
Why not Azure AD's native Salesforce connector?
Microsoft's Entra ID / Azure AD has a Salesforce SCIM connector that can provision and deprovision Salesforce users based on Azure AD user lifecycle events. This is a useful starting point for automated provisioning. What it does not provide is Azure AD's live user and group data queryable by an Agentforce agent in real time during a service conversation: an agent cannot ask the SCIM connector for a user's current group memberships, use group membership to diagnose a specific access problem, or surface the identity context needed to route a complex access issue to the right team. Emerge Digital builds the retrieval and action layer that makes Azure AD genuinely available to agents beyond the SCIM provisioning baseline.
Azure AD's Agentforce integration spans onboarding, the active relationship, and offboarding — mirroring the same people and access lifecycle that BambooHR and Workday govern on the HR side, but at the identity and access layer. Grounding agents in Azure AD data means provisioning and deprovisioning are fast, accurate, and automatic, and support agents can diagnose access problems from the actual identity record rather than escalating every access query to IT.
How Emerge integrates Azure Active Directory
Emerge Digital connects Azure Active Directory to Salesforce Agentforce as a consulting engagement. We map which Azure AD data types agents need to read — user objects, group memberships, application assignments, and account status — define the identity lifecycle events that trigger Salesforce actions, configure real-time retrieval for access and entitlement context during service conversations, and set the governance boundaries that decide which agents can read and act on which identity data. The integration is designed around your Azure AD tenant and your organisation's identity governance model.
How we structure an engagementRelated integrations
FAQ
How does this differ from the Okta + Agentforce integration?
The use case is the same — identity context in service conversations and lifecycle events triggering CRM actions. Azure AD / Microsoft Entra ID is the identity platform for organisations on the Microsoft enterprise stack; Okta is the identity platform of choice for organisations with a multi-cloud or non-Microsoft-primary stack. Emerge builds the integration to fit the identity platform your IT team operates.
We use Azure AD for customer identity management, not just employees — does that affect scope?
Yes. Azure AD B2C and the external identities capability are used by some organisations for customer identity — this is a different use case from internal employee identity management. Emerge scopes the integration around which identity model applies: employee provisioning and CRM alignment, or customer access verification and entitlement management.
Does this work with Microsoft Entra ID, or only Azure AD?
Azure Active Directory has been rebranded as Microsoft Entra ID. The underlying service and API are the same. This integration works with the platform under either name.
How long does an Azure AD + Agentforce integration take?
A focused engagement typically runs four to eight weeks: mapping which Azure AD data types and lifecycle events are in scope, configuring provisioning and deprovisioning triggers, building the access context retrieval layer for service agents, and testing access troubleshooting, onboarding, and offboarding workflows. Enterprise tenants with complex group structures and Conditional Access policies add time.
Ground your agents in Azure Active Directory.
Tell us what your agents need to read and write in Azure Active Directory, and we'll design the integration and the governance around it.
Talk to the practicePrefer email? Write to the practice instead.