---
version: "2026.1.0"
language: "en"
---
# Azure Active Directory Server Connection

**Azure Active Directory** is a cloud-based identity and access management service provided by Microsoft Azure. It serves as a comprehensive solution for managing user identities, securing access to resources, and enabling single sign-on across various cloud applications and services.  
**Note:** This feature can be accessed by Leapwork Admin only.

## Add Connection

To add a connection:

1. Click the **Add**button and the following pop-up appear:

![image-png-Mar-07-2023-05-35-31-8145-AM-20260629-132338.png](https://docs.leapwork.com/__attachments/a_86d02b9dd8e438d77ed2a6d4f66a1fcabc1a3c0bdb052de2412ba87473457b1a/image-png-Mar-07-2023-05-35-31-8145-AM-20260629-132338.png?cb=2d8df9788f627a56efafd6a17dce979d)

In the **Add Connection** pop-up window:

* Enter the title in the **Title** field. It should be unique.

* Enter the description in the **Description**field.

* From the **Type** drop-down, select the **Azure Active Directory** server option:

![image-20260121-111601.png](https://docs.leapwork.com/__attachments/a_ecbb24e1d45e908d5a11143ac9100ebdabe534a3125385eace4dc09b2233a9fd/image-20260121-111601.png?cb=3895b22b0b01abcaa107faea781febab)

* Select **Azure Active Directory****Server** and the following new fields appear:

![image-20260121-111710.png](https://docs.leapwork.com/__attachments/a_f820397aa0e37f8502f4518c178ce7927fa1ece97245bece52a0adf5a859f13a/image-20260121-111710.png?cb=dd7a049c03231bd313b34be8da84e375)

2. To complete the **Add Connection** process, follow these steps in the Azure portal (<https://portal.azure.com/)>.

* Click the **App Registration** to create a new app registration.

* Enter the name in the **Name** field.

* Select the users from the **Supported Account Types** options.

* Click **Register** button.

![image-20260701-100527.png](https://docs.leapwork.com/__attachments/a_5e395adccb956d237dc0fadc357056a41f112d8dd9f9144b5259de03c20b49c3/image-20260701-100527.png?cb=effb64dac64ebd9d2c008734acb4c297)

* Click the **Add a Redirect URI** hyperlink on the **Overview Section** window of the new application:

![image-20260701-100832.png](https://docs.leapwork.com/__attachments/a_8f6aa013f023ddeeaaf280c48f1bdb1edfc57fbcce7c8a67b14d35b9190ef8ae/image-20260701-100832.png?cb=fed3187b465d2090bdfbb89f3b03d77a)

* Click the **Add a Platform** option.

* Click **Mobile and Desktop Applications** button in Configure platforms field.

![image-20260701-101222.png](https://docs.leapwork.com/__attachments/a_6b37ec1892f25df644f613962794a8bf43e47e9f7d3883740aa49d9ddf2d9bb4/image-20260701-101222.png?cb=8c99e9a133c8ac6e12a87e89f6650554)

* Select the <https://login.microsoftonline.com/common/oauth2/nativeclient> checkbox.

* Click **Configure** button.

* On the **API Permissions** section:

  1. Click **Add a Permission** button.

  2. Select **Microsoft Graph** option.

  3. Select **Application Permissions** button.

  4. Select "*User.Read.All* ", "*Directory.Read.All* ", and "*GroupMember.Read.All* " in the **Users**checkbox.

  5. Select **Delegate Permissions** button.

  6. Add "*Directory.Read.All* ", and "*User.Read* " in the **Users**checkbox.

  7. Click the **Add Permissions** button.

* On the **Certificates \& Secrets** section:

  1. Click **Next Client Server** button.

  2. Write a description in the **Description** field.

  3. Select an expiration date from the **Expiration** dropdown.

* Securely store the **Secret Value** for backup.

![image-20260701-110046.png](https://docs.leapwork.com/__attachments/a_6f47ce6199ac375932a1e0a5214bea214d23c14fd34840db761ba81bd4856419/image-20260701-110046.png?cb=b35cbd136ce56ff93dec4664f402ef28)  
**Note:** Please allow 5-10 minutes for the app registration changes to take effect. You may now proceed with the Add Connection process.

The**Instance** and **API URL** fields are automatically filled for Azure Active Directory (AAD).

* Enter the tenant in **Tenant**field.

* Enter the client id in **Client ID** field.

* Enter the client secret in the **Client Secret** field.

**Note:** The Tenant and Client ID are found in the Overview section of the application that has already been registered on the Microsoft Azure Portal. (<https://portal.azure.com/#home)>  
![image-20260701-121512.png](https://docs.leapwork.com/__attachments/a_c07e2bb38d7826127b3fce2cd8e1fbab7e40ab054734c397d5e9f1b3eac8476f/image-20260701-121512.png?cb=2bc59f841420661457028b357f3eb2b2)

* The Client Secret is generated from the **Certificates \& secrets** section:

![image-20260701-124547.png](https://docs.leapwork.com/__attachments/a_2b51be89bf1f53168095ada16d589b2e03a2bd20db1745644869650afa65fb7c/image-20260701-124547.png?cb=78c263b4c1e91488d1de33b20f25ab5b)  
**Note:** For more information about registering app in Microsoft Azure Portal please visit: <https://learn.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app>.

3. Click the **Test connection** button to test the connection.

   * The embedded browser will open.

     1. Enter the username and password.

     2. Click Ok to test the connection.

![image-20260121-113118.png](https://docs.leapwork.com/__attachments/a_6ada20e722ef9b6b68808db9d146eea187872d1a58662a6fc59a173fdd779289/image-20260121-113118.png?cb=aa47328f1f094cd3a2757d65fb36a730)

Ensure the **Set this as default user directory** checkbox is selected. After testing the connection, a success message will confirm it is established.

4. Click the **Save \& Continue** button to save the details.

Once your connection is saved a success message appears to let you know the connection is successful.

Once the connection is successfully saved, it would be added to the connections list.

Use the **Edit** or **Delete** buttons located next to the **Add** button to modify or remove the connection.  
![image-png-Nov-15-2022-07-56-10-4735-AM-20260701-124627.png](https://docs.leapwork.com/__attachments/a_b0875bec98454ad1cbde9e7dc138a4ac96061cbf665bbac8aab2730bd47fdb84/image-png-Nov-15-2022-07-56-10-4735-AM-20260701-124627.png?cb=d58ffce763920ac380ea52cfed28f086)