Quick answer: Azure Data Factory can call Microsoft Graph through its REST connector using a system-assigned or user-assigned managed identity. Grant the Data Factory managed identity the required Microsoft Graph application permission, provide admin consent, then configure the REST linked service with the Graph resource URL.
What is Microsoft Graph API?
Microsoft Graph is a REST API that provides access to Microsoft cloud resources such as users, groups, mail, calendars, contacts, and files.
Authentication
Azure Data Factory can authenticate to REST endpoints using several methods, including system-assigned and user-assigned managed identities. Managed identities avoid storing credentials in the pipeline or linked service. See System-Assigned vs User-Assigned Managed Identity in Azure for the differences between the two identity types.
Using managed identity
For this example, we use the Data Factory system-assigned managed identity. Enable the identity on the Data Factory and grant it the Microsoft Graph application permissions required by the API operation. For example, reading all users requires the appropriate Microsoft Graph User.Read.All application permission and administrator consent.
Let’s see it in action
This example retrieves Microsoft Entra users from Microsoft Graph and copies the response to Azure Blob Storage.
1. Grant Microsoft Graph permissions to Data Factory
Open Microsoft Entra admin center and locate the enterprise application/service principal for the Data Factory managed identity. Grant the required Microsoft Graph application permission and provide administrator consent.


For this example, the Data Factory identity requires User.Read.All application permission to read users through Microsoft Graph.

Available on Microsoft Store
SSRS Reports Migration Wizard
A simple Windows tool for migrating SSRS reports, data sources, and related configurations between report servers.
2. Create a REST linked service
In Data Factory Studio, open Manage > Linked services and create a REST linked service. Select managed identity authentication and use the Microsoft Graph resource:
Authentication Type: System Assigned Managed Identity
AAD resource: https://graph.microsoft.com/

3. Configure Copy Activity
Configure the REST source to call the Microsoft Graph users endpoint:
URL: https://graph.microsoft.com/v1.0/users
For paginated responses, configure pagination using the @odata.nextLink value returned by Microsoft Graph. The REST connector supports pagination for REST APIs.

After the pipeline runs successfully, the API response can be written to the configured Blob Storage sink.

Pro tips:
Grant only the Microsoft Graph permissions required by the API operation. Application permissions can provide access without a signed-in user, so review the permission scope carefully before granting administrator consent.
See more
Visual Studio Marketplace
SSIS Catalog Migration Wizard
Extend Visual Studio with an easy way to migrate SSIS Catalog projects.






