---
title: "Entra ID Connector | Supported Data and Collection Limitations"
canonical: "https://docs.certero.com/space/CUP/326172713/Entra%20ID%20Connector%20%7C%20Supported%20Data%20and%20Collection%20Limitations"
format: markdown
---
---

## Overview

This article describes what the Certero Entra ID Connector collects from your Microsoft Entra ID tenant, and the limits of that collection. It is worth reading before you rely on Entra-sourced data for reporting or compliance, the connector completes successfully and simply returns less data than you might expect when compared to Active Directory.

---

## What the Connector Collects

| <span style="color: #ffffff">**Data**</span> | <span style="color: #ffffff">**Detail**</span> |
| --- | --- |
| **Organisation** | Tenant name, address, country, created date, and the default verified domain. |
| **Users** | Profile, contact and organisational attributes, account status, last password change, user type, on-premises correlation attributes, and manager. |
| **Groups** | Name, description, mail address, group type, security and mail enablement, visibility, created date. |
| **Group membership** | Direct user members of each group. |
| **Devices** | Hostname, display name, operating system, registration date, last sign-in, account status, and extension attributes 1–15. |

---

## Collection Limitations

### <span style="color: #6554c0">Devices</span>

- **Android and iOS devices are not collected.** The connector filters them out. If you need mobile device visibility, the separate Certero for Mobile module is required.
- **Devices with no operating system recorded in Entra are also skipped.** These are usually incomplete or stale registrations.
- **Windows, macOS and Linux devices are collected.**
- **Device detail from Entra alone is sparse.** Entra provides a generic operating system value such as `Windows` rather than a full version string. Detailed hardware, software and operating system version data requires the Certero client agent to be installed. Where an agent is present, the agent's data is used in preference to the Entra value.

### <span style="color: #6554c0">Groups</span>

- **Only direct members are collected.** If a group contains another group, the members of that nested group are not included. Group membership counts in Certero may therefore be lower than the effective membership shown in the Entra portal.
- **Only user members are collected.** Service principals, contacts and nested groups are excluded from membership. This is a second reason counts may differ from the Entra portal.

### <span style="color: #6554c0">Users</span>

- **Data completeness reflects your tenant.** Fields such as telephone number, street address and department are populated only where they are maintained in Entra. A sparsely populated tenant produces sparsely populated records in Certero.
- **Last sign-in requires additional permission and licensing.** See *[What permissions required for the Entra ID Connector](https://docs.certero.com/space/CUP/326172692/What+Permissions+are+Required+for+the+Entra+ID+Connector)*, the `AuditLog.Read.All` permission and at least one Entra ID P1 licence are both needed. Without either, the field is silently empty.
- **Manager relationships are resolved within Entra only.** A user's manager is collected and linked where that manager is also present in the Entra data. A manager held only in Active Directory will not be linked from the Entra record.
- **User Type. **The type of User account configured is populated within the User Type attribute and will show either Guest, Member or B2B user types based upon what has been configured for each user in Entra ID.

### <span style="color: #6554c0">Organisation</span>

- **Only the first organisation returned by the tenant is collected.** Tenants configured with multiple organisations will have only one represented in Certero.

---

## Attributes you can choose to Exclude

The connector allows specific user attributes to be excluded from collection, configured on the **User Attributes** tab of the connector properties. This is useful where your organisation's data handling policy restricts what may be copied into third-party systems.

Excluding an attribute means it is never requested from Graph, so it will not appear anywhere in Certero.

---

## Further Information

If you are running both an Active Directory connector and an Entra ID connector, see *[Setting your Preferred Directory Source](https://docs.certero.com/space/CUP/326336556/Setting+your+Preferred+Directory+Source)* and *[How are users matched between Active Directory and Entra ID](https://docs.certero.com/space/CUP/326336576/How+Are+Users+Matched+Between+Active+Directory+and+Entra+ID)*, these describe how data from the two sources is combined.

If you are deploying without Active Directory, see *[Feature availability in an Entra-only Environment](https://docs.certero.com/space/CUP/326172793/Feature+Availability+in+an+Entra-Only+Environment)*.

---

## Getting Started / Support

If you have questions or need help, please contact the **Certero Help Desk** or your Certero account team.

---

© 2026 Certero Company Confidential. All rights reserved.