
Sign up to save your podcasts
Or
In this episode, I sit down with Chetan Desai, a Principal Product Manager on the Microsoft Identity Governance team. We dive deep into a side of Entra that many admins never see: the critical "first mile problem" of getting identities into your system in the first place.
We talk about the evolution from on-prem scripts and MIM to specific connectors for Workday and SuccessFactors and then to the new powerful, generic API-driven approach that can handle any HR system and the architectural decisions behind it. Chetan also gives us a masterclass on how the provisioning engine differs from the Graph API and provides advice for anyone looking to migrate from a legacy Identity Governance and Administration (IGA) solution.
Subscribe with your favorite podcast player or watch on YouTube π
About Chetan Desai
Chetan Desai is a Principal Product Manager at Microsoft on the Entra team. For the past seven years, he has been a core part of the Entra Identity Governance and Provisioning team. Before his time at Microsoft, Chetan spent 17 years in consulting within the identity and access management domain , bringing a wealth of real-world deployment and integration experience to his product management role.
π Related Links
* Application and HR provisioning documentation
* Provisioning with SCIM
* API-driven inbound provisioning concepts
π Chapters
00:34 The "First Mile Problem" in Identity
04:51 From AD Sync to HR-Driven Provisioning
09:52 The Entra Provisioning Service Architecture
16:17 Hybrid vs. Cloud-Only Identity Flows
19:17 Beyond Workday: The Need for a Generic Connector
27:43 The Great Debate: CSV vs. SQL vs. API
35:34 Provisioning API vs. Graph API: What's the Difference?
43:24 The Latest Evolution: Custom Security Attributes
49:26 Advice for Migrating to Modern IGA
Podcast Apps
ποΈ Entra.Chat - https://entra.chat
π§ Apple Podcast β https://entra.chat/apple
πΊ YouTube β https://entra.chat/youtube
πΊ Spotify β https://entra.chat/spotify
π§ Overcast β https://entra.chat/overcast
π§ Pocketcast β https://entra.chat/pocketcast
π§ Others β https://entra.chat/rss
Merill's socials
πΊ YouTube β youtube.com/@merillx
π LinkedIn β linkedin.com/in/merill
π€ Twitter β twitter.com/merill
πΊ TikTok β tiktok.com/@merillf
π¦ Bluesky β bsky.app/profile/merill.net
π Mastodon β infosec.exchange/@merill
π§΅ Threads β threads.net/@merillf
π€ GitHub β github.com/merill
5
44 ratings
In this episode, I sit down with Chetan Desai, a Principal Product Manager on the Microsoft Identity Governance team. We dive deep into a side of Entra that many admins never see: the critical "first mile problem" of getting identities into your system in the first place.
We talk about the evolution from on-prem scripts and MIM to specific connectors for Workday and SuccessFactors and then to the new powerful, generic API-driven approach that can handle any HR system and the architectural decisions behind it. Chetan also gives us a masterclass on how the provisioning engine differs from the Graph API and provides advice for anyone looking to migrate from a legacy Identity Governance and Administration (IGA) solution.
Subscribe with your favorite podcast player or watch on YouTube π
About Chetan Desai
Chetan Desai is a Principal Product Manager at Microsoft on the Entra team. For the past seven years, he has been a core part of the Entra Identity Governance and Provisioning team. Before his time at Microsoft, Chetan spent 17 years in consulting within the identity and access management domain , bringing a wealth of real-world deployment and integration experience to his product management role.
π Related Links
* Application and HR provisioning documentation
* Provisioning with SCIM
* API-driven inbound provisioning concepts
π Chapters
00:34 The "First Mile Problem" in Identity
04:51 From AD Sync to HR-Driven Provisioning
09:52 The Entra Provisioning Service Architecture
16:17 Hybrid vs. Cloud-Only Identity Flows
19:17 Beyond Workday: The Need for a Generic Connector
27:43 The Great Debate: CSV vs. SQL vs. API
35:34 Provisioning API vs. Graph API: What's the Difference?
43:24 The Latest Evolution: Custom Security Attributes
49:26 Advice for Migrating to Modern IGA
Podcast Apps
ποΈ Entra.Chat - https://entra.chat
π§ Apple Podcast β https://entra.chat/apple
πΊ YouTube β https://entra.chat/youtube
πΊ Spotify β https://entra.chat/spotify
π§ Overcast β https://entra.chat/overcast
π§ Pocketcast β https://entra.chat/pocketcast
π§ Others β https://entra.chat/rss
Merill's socials
πΊ YouTube β youtube.com/@merillx
π LinkedIn β linkedin.com/in/merill
π€ Twitter β twitter.com/merill
πΊ TikTok β tiktok.com/@merillf
π¦ Bluesky β bsky.app/profile/merill.net
π Mastodon β infosec.exchange/@merill
π§΅ Threads β threads.net/@merillf
π€ GitHub β github.com/merill
1,983 Listeners
365 Listeners
636 Listeners
366 Listeners
183 Listeners
1,009 Listeners
312 Listeners
415 Listeners
7,913 Listeners
166 Listeners
189 Listeners
314 Listeners
74 Listeners
127 Listeners
43 Listeners