Azure Integration
Note: This integration requires the use of ThreatLocker Agent Version 8.0 or above.
How to Configure the Azure Integration
To begin, navigate to the ThreatLocker portal.
From the left-hand navigation menu, click âIntegrationsâ and click âNew Integrationâ.

Click âSetupâ next to the Azure icon.

Enter a valid Tenant ID from your Azure Directory and click âOpen Consent Screenâ.

Note: This next step requires a Microsoft administrator account.
Login as an administrator and accept the permissions requested.

If done correctly, the Admin Consent will now state âGrantedâ and the Configuration tab will become visible.

Click âConfigurationâ, select the Azure groups youâd like to sync from the drop-down menu, and click âAddâ.

Once you have your Azure groups added, click âSaveâ.

A bar will pop-up to confirm you have successfully saved the Azure integration and you will see the Azure Integration listed on your Integrations page.


How to Apply the Azure Integration to Your Policies
To begin, navigate to the ThreatLocker portal, expand the Application Control menu on the left hand side, and click âApplication Policiesâ.

Add a new application policy or edit an existing policy. In the popup window, scroll down to the section asking âWhich users and groups should this policy apply to?â, choose âLet me select users and groupsâ, select the Azure group(s) this policy should apply to from the drop down menu, and click âAddâ.

Please note: It is recommended to select the group name from the drop-down menu to avoid any type-os. The Azure group name must match exactly.
Click âSaveâ.

Note: Our enterprise application used for the integration requires specific pieces of information from the Azure groups and their members in order to function properly. The permissions required for this integration are necessary. ThreatLocker will not read any information other than what is truly required and will not be writing any data.