Identity & Access Data Sources
Identity and access data sources allow you to query tenant information, license subscriptions, role definitions, groups, and conditional access templates.Tenant Information
microsoft365_graph_beta_identity_and_access_tenant_information
Retrieve information about your Microsoft 365 tenant. Query Methods:tenant_id- Query by tenant ID (GUID)domain_name- Query by domain name
tenant_id- Unique tenant identifierdisplay_name- Tenant display namedefault_domain_name- Primary domain (e.g., contoso.onmicrosoft.com)federation_brand_name- Federation brand nameverified_domains- List of verified domains
License Management
microsoft365_graph_beta_identity_and_access_subscribed_skus
Query subscribed license SKUs and their availability. Query Methods:- No filter (retrieves all SKUs)
sku_part_number- Filter by SKU part number (partial match)applies_to- Filter by applies to (User, Company)sku_id- Filter by specific SKU ID
sku_id- SKU identifiersku_part_number- SKU part number (e.g., “ENTERPRISEPREMIUM”)consumed_units- Number of licenses assignedprepaid_units.enabled- Total available licensesprepaid_units.suspended- Suspended licensesprepaid_units.warning- Licenses in warning statecapability_status- SKU status (Enabled, Deleted, Suspended)applies_to- What the SKU applies to (User, Company)service_plans- List of included service plans
microsoft365_utility_licensing_service_plan_reference
Look up detailed service plan information for license SKUs. Example:matching_products- List of matching productsproduct_name- Product display namestring_id- String identifierguid- Product GUIDservice_plans_included- Included service plans
Groups
microsoft365_graph_beta_groups_group
Query Entra ID (Azure AD) groups. Query Methods:object_id- Query by object ID (most efficient)display_name- Query by display namemail_nickname- Query by mail nicknameodata_query- Advanced OData filter
id/object_id- Group identifierdisplay_name- Group display namedescription- Group descriptionmail_nickname- Mail aliasmail- Email addressmail_enabled- Whether group is mail-enabledsecurity_enabled- Whether group is a security groupgroup_types- List of group types (e.g., [“Unified”], [“DynamicMembership”])visibility- Group visibility (Public, Private, HiddenMembership)assignable_to_role- Whether assignable to Azure AD rolemembership_rule- Dynamic membership rulemembership_rule_processing_state- Dynamic membership state (On, Paused)members- List of member object IDsowners- List of owner object IDsassigned_licenses- Licenses assigned to groupproxy_addresses- Email proxy addressescreated_date_time- Creation timestamponpremises_sync_enabled- Whether synced from on-premisesonpremises_sam_account_name- On-premises SAM account nameonpremises_security_identifier- On-premises SID
Role Definitions
microsoft365_graph_beta_identity_and_access_role_definitions
Query Azure AD role definitions. Example:id- Role definition IDdisplay_name- Role namedescription- Role descriptionis_builtin- Whether it’s a built-in roleis_enabled- Whether role is enabledresource_scopes- Resource scopesrole_permissions- List of permissions
Conditional Access
microsoft365_graph_beta_identity_and_access_conditional_access_template
Query conditional access policy templates. Example:Directory Settings
microsoft365_graph_beta_identity_and_access_directory_setting_templates
Query directory setting templates. Example:Common Use Cases
License Compliance Check
Multi-Stage Deployment with Groups
Validate Group Membership
Best Practices
Use Object IDs for Performance
Use Object IDs for Performance
When you know the object ID, use it instead of name-based lookups:
Monitor License Usage Proactively
Monitor License Usage Proactively
Set up alerts for license availability:
Document Group Dependencies
Document Group Dependencies
Clearly document which groups your configuration depends on:
Next Steps
Device Management Data Sources
Query devices and policies
Application Data Sources
Retrieve application data
Identity & Access Resources
Manage users, groups, and policies
Examples
Browse complete examples
