What it provides
- SSO authentication — Staff and portal users sign in with their Entra credentials
- User sync — Entra users are imported as portal contacts automatically
- Device sync — Intune-managed devices are imported as assets
- Compliance evidence — Conditional access policies, MFA status, and device compliance states are collected as evidence for compliance frameworks
Setup
Start admin consent
Click Connect to initiate the Azure AD admin consent flow. You will be redirected to Microsoft’s login page.
Grant consent
Sign in with a Global Administrator or Privileged Role Administrator account and approve the permissions requested by the Regentra application.
The admin consent flow grants Regentra read access to users, groups, devices, and directory data. No write permissions are requested.
What syncs
| Entra object | Regentra object | Details |
|---|---|---|
| Users | Portal contacts | Display name, email, department, job title |
| Devices (Intune) | Assets | Hostname, OS, serial number, compliance state |
| Groups | Contact groups | Used for portal access control |
Sync frequency
- Identity sync (users, contacts, devices) runs every 4 hours on the hour
- Evidence collection sync (conditional access policies, MFA status, device compliance signals) runs every 6 hours, offset 15 minutes from the identity sync to avoid Graph API contention
- Manual sync can be triggered at any time from the integration settings page
The initial sync may take several minutes depending on the size of your Entra directory. Subsequent syncs are incremental and faster.
Per-company sync
For MSP customers operating multiple client tenants, Regentra also exposes a per-company Sync With M365 button on the PSA Company detail page (PSA → Companies → [company]). This pulls a fresh snapshot of users + devices for that one customer without waiting for the next 4-hour cycle. The button handles two states:- Not yet connected to a tenant — click redirects to Microsoft for admin consent on the customer’s tenant; on return, the initial sync queues automatically
- Already connected — click queues an Inngest sync job that runs in the background; the page shows “Sync queued” and contacts + devices refresh on the next load