Microsoft 365 / Azure Active Directory

Automatically sync all of your Azure Active Directory users into Vendr.

Pauline Chin avatar
Written by Pauline Chin
Updated over a week ago

Available For:

  • Vendr 2.0

  • Vendr Premium Intelligence

  • Vendr Premium Procurement

How it works

The Microsoft 365 integration syncs your Microsoft 365 users into Vendr in just a few clicks. Connecting Vendr to your Microsoft 365 instance lets you quickly deploy Vendr across your entire organization. Whenever a user is added or leaves your organization, they'll automatically be added or removed from your Vendr organization.



  • Automatically provide access to Vendr to all of your employees in a few clicks and keep those users in sync with your Azure Active Directory directory.

  • Sync employee details like Name, Email, Title, and Manager from Azure Active Directory to Vendr in just a few clicks.

  • Assign approval steps in procurement requests to an employee's manager.


Installing the Microsoft 365 integration does not enable SSO. ​To allow users to sign in using SAML you'll also need to configure SSO. Learn more.


To begin installation, you must be a Microsoft administrator. To install the Microsoft integration:

  1. Hit Integrate

  2. Complete the resulting OAuth flow

Requested Permissions:

You'll be able to review the permissions the integration requires before approving the connection.

  • The permissions are all read-only.

  • For a full list of the permissions, please refer to the Security / Privacy section at the bottom of this page.

Syncing Users

The integration currently supports syncing over the following standard fields in Azure. Syncing custom attributes from Azure is not currently supported.

Azure Field

Vendr Field


Display Name




Job Title


User Manager Id


Must be manager id or manager email


Direct Reports

This is populated based on the user's assigned Manager in Azure

After Installation

Once the integration is installed, you should start to see People and Product data flow into your account, although it can take up to 24 hours for the initial sync to complete.

If you've got any applications behind SAML SSO, you'll want to confirm that your App Bindings are correct - see how to do that here: App Bindings.

If you're only using regular Google oAuth, you don't need to worry about App Bindings.


  1. Head to the My Integrations page in your account.

  2. Click "Manage" for the integration you wish to remove.

  3. Click the "Remove Integration" button in the top right of the integration details page.

If you'd like to purge all data previously imported, we're happy to help, just contact Support.​

Security / Privacy

This integration is read-only and does not have permission to affect your organization.

The specific permissions requested by the integration are:

  • AuditLog.Read.All

  • Directory.Read.All

  • email

  • offline_access

  • Organization.Read.All

  • User.Read

  • User.Read.All

Did this answer your question?