Quick answer: Azure Data Factory can call Microsoft Graph through its REST connector using a system-assigned or user-assigned managed identity. Grant the Data Factory managed identity the required Microsoft Graph application permission, provide admin consent, then configure the REST linked service with the Graph resource URL.

What is Microsoft Graph API?

Microsoft Graph is a REST API that provides access to Microsoft cloud resources such as users, groups, mail, calendars, contacts, and files.

Authentication

Azure Data Factory can authenticate to REST endpoints using several methods, including system-assigned and user-assigned managed identities. Managed identities avoid storing credentials in the pipeline or linked service. See System-Assigned vs User-Assigned Managed Identity in Azure for the differences between the two identity types.

Using managed identity

For this example, we use the Data Factory system-assigned managed identity. Enable the identity on the Data Factory and grant it the Microsoft Graph application permissions required by the API operation. For example, reading all users requires the appropriate Microsoft Graph User.Read.All application permission and administrator consent.

Let’s see it in action

This example retrieves Microsoft Entra users from Microsoft Graph and copies the response to Azure Blob Storage.

1. Grant Microsoft Graph permissions to Data Factory

Open Microsoft Entra admin center and locate the enterprise application/service principal for the Data Factory managed identity. Grant the required Microsoft Graph application permission and provide administrator consent.

Microsoft Entra enterprise application for Azure Data Factory managed identity
Grant Microsoft Graph API permissions to Azure Data Factory managed identity

For this example, the Data Factory identity requires User.Read.All application permission to read users through Microsoft Graph.

Microsoft Graph User.Read.All permission for Azure Data Factory

Available on Microsoft Store

SSRS Reports Migration Wizard

A simple Windows tool for migrating SSRS reports, data sources, and related configurations between report servers.

2. Create a REST linked service

In Data Factory Studio, open Manage > Linked services and create a REST linked service. Select managed identity authentication and use the Microsoft Graph resource:

Authentication Type: System Assigned Managed Identity

AAD resource: https://graph.microsoft.com/

Azure Data Factory REST linked service using managed identity

3. Configure Copy Activity

Configure the REST source to call the Microsoft Graph users endpoint:

URL: https://graph.microsoft.com/v1.0/users

For paginated responses, configure pagination using the @odata.nextLink value returned by Microsoft Graph. The REST connector supports pagination for REST APIs.

Azure Data Factory Copy Activity calling Microsoft Graph API

After the pipeline runs successfully, the API response can be written to the configured Blob Storage sink.

Azure Data Factory pipeline output written to Blob Storage

Pro tips:
Grant only the Microsoft Graph permissions required by the API operation. Application permissions can provide access without a signed-in user, so review the permission scope carefully before granting administrator consent.

See more

Visual Studio Marketplace

SSIS Catalog Migration Wizard

Extend Visual Studio with an easy way to migrate SSIS Catalog projects.

Pavan Bangad

9+ years of experience in building data warehouse and big data application.
Helping customers in their digital transformation journey in cloud.
Passionate about data engineering.