---
title: "Workstate Codes: Using Microsoft Graph API with Azure Active Directory"
description: In this blog post, we will go over how to gain access to the Graph API and demonstrate an example request to get the list of users from Azure Active Directory.
image: https://resources.workstate.com/hubfs/blog-images/iam/IdentityServer3views.png
---

[![Workstate](https://resources.workstate.com/hubfs/Workstate-Nov2016/Image/Logo.png "Workstate")](http://workstate.com/)

- Practices 
    - [Technology Team Rental](http://workstate.com/teamrental)
    - [Big Data](http://workstate.com/bigdata)
    - [Cloud Shift](http://workstate.com/cloud-shift)
    - [QA and Testing](http://workstate.com/qa)
    - [Identity and Access Management](http://workstate.com/iam)
    - [Application Security](http://workstate.com/appsecurity)
- [Blog](http://web.workstate.com/blog)
- [Careers](https://workstate.workable.com/)

# Workstate Insights Blog

# Workstate Codes: Using Microsoft Graph API with Azure Active Directory

 February 22, 2017

by [Bryan Bernard, Associate Software Consultant](https://resources.workstate.com/blog/author/bryan-bernard-associate-software-consultant)

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fworkstate-codes-using-microsoft-graph-api-with-azure-active-directory%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fworkstate-codes-using-microsoft-graph-api-with-azure-active-directory%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fworkstate-codes-using-microsoft-graph-api-with-azure-active-directory%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fworkstate-codes-using-microsoft-graph-api-with-azure-active-directory%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=Workstate%20Codes%3A%20Using%20Microsoft%20Graph%20API%20with%20Azure%20Active%20Directory) [![Share on Email](https://static.hubspot.com/final/img/common/icons/social/email-24x24.png)](mailto:?subject=Check%20out%20https%3A%2F%2Fresources.workstate.com%2Fblog%2Fworkstate-codes-using-microsoft-graph-api-with-azure-active-directory%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fresources.workstate.com%2Fblog%2Fworkstate-codes-using-microsoft-graph-api-with-azure-active-directory%3Futm_medium%3Dsocial%26utm_source%3Demail)

![IdentityServer3views.png](https://resources.workstate.com/hs-fs/hubfs/blog-images/iam/IdentityServer3views.png?width=320&name=IdentityServer3views.png)Microsoft Azure contains a wide variety of cloud services, including its industry-leading platform for identity and access management. With it you can manage all of your users, groups and other identity objects in a similar way that you would an on-premise instance of Active Directory.

While the user interface (Azure Management Portal) is constantly improving, there are still a number of management and power tools that aren’t available yet. This is where the power of the Microsoft Graph API comes into play. With some simple RESTful API calls, you can easily manage your directory information, even without a portal UX.

Want to easily migrate from on-premise Active Directory to Microsoft Azure AD?

[Click here to learn more!](https://resources.workstate.com/azure-active-directory-migration-tool-workstate)

In this blog post, we will go over how to gain access to the Graph API and demonstrate an example request to get the list of users from Azure Active Directory.

Before you get started, make sure you have an Azure Subscription with an Active Directory Tenant and any flavor of Visual Studio with .NET 4+.

****Create an Azure AD application with privileges to read and write to the directory**The first step in creating a custom application to manage Azure Active Directory is to create an Azure AD App with privileges to view and modify the directory.

Log into your Azure Management portal, and go to the Azure Active Directory tab. Next go to Applications and Add a new application. Once that is created, navigate to the app and go to the configure tab.

Copy down the Client ID field; we will need this later when authorizing the app to make a call to the Graph API.

Next, in the Keys section add a new key. After saving the application, the key value will appear – copy that down, as we will be using it later when we refer to the App Key.

Finally, in the Other Applications section, click Add Application and add the Microsoft Graph application. In the Permissions section, set the Application Permissions to “Read and Write directory data.”

******Get valid access token using application clientid and secret**Now we are ready to write the code that will use this application to authorize access to the Graph API, so we can view and edit the directory data.

First, we will need a valid access token. In order to retrieve this we will need the Azure AD TenantID and the Application ClientID and AppKey from the earlier steps.******

```
var authority = "https://login.microsoftonline.com/{TenantID}/oauth2/token"
var authenticationContext = new AuthenticationContext(authority, false);
var clientCred = new ClientCredential({ClientID}, {AppKey});
var authenticationResult = authenticationContext.AcquireToken("https://graph.microsoft.com", clientCred);
var accessToken = authenticationResult.AccessToken;
```

******Now that we have the access token, we can add it to the request header to authorize access to the Graph API.******

  
************Calling the Graph API**  
For this example, we will use the [Get User](https://graph.microsoft.io/en-us/docs/api-reference/v1.0/api/user_get) endpoint, which will return a list of all users registered in the Active Directory.**********

```
var url = "https://graph.microsoft.com/v1.0/" + {tenant} + "/users"
var request = new HttpRequestMessage(HttpMethod.Get, url);
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", result.AccessToken);
var response = await http.SendAsync(request);
var content = response.Content.ReadAsStringAsync();
```

**The content returned will be a JSON object with all of the users in the Active Directory.**

---

For more information on all of the different things you can do with Graph API, check out Microsoft’s [Graph API Documentation](https://graph.microsoft.io/en-us/docs). If you would like to test out the various API calls without writing code, check out Microsoft’s [Graph Explorer](https://graph.microsoft.io/en-us/graph-explorer), which is a great way to make sure you have the proper formatting and permissions in place while debugging any issues.

Interested in learning more about the fundamentals of Identity and Access Management?

[![Get IAM Primed Now!](https://no-cache.hubspot.com/cta/default/2258296/3543afec-f439-45d5-afbe-3ea824a116c1.png)](https://cta-redirect.hubspot.com/cta/redirect/2258296/3543afec-f439-45d5-afbe-3ea824a116c1)

Don’t forget to subscribe to receive future blog posts directly in your email!

### Subscribe to Email Updates

### Recent Posts

### Posts by Topic

- [Cloud Shift (17)](https://resources.workstate.com/blog/topic/cloud-shift)
- [IAM (16)](https://resources.workstate.com/blog/topic/iam)
- [Cloud Computing Best Practices (11)](https://resources.workstate.com/blog/topic/cloud-computing-best-practices)
- [Enterprise Identity (10)](https://resources.workstate.com/blog/topic/enterprise-identity)
- [Identity and Access Management (10)](https://resources.workstate.com/blog/topic/identity-and-access-management)
- [Cloud Migration (8)](https://resources.workstate.com/blog/topic/cloud-migration)
- [Technology Team Rental (8)](https://resources.workstate.com/blog/topic/technology-team-rental)
- [Cloud Shift Best Practices (6)](https://resources.workstate.com/blog/topic/cloud-shift-best-practices)
- [Identity (5)](https://resources.workstate.com/blog/topic/identity)
- [Workstate Codes (5)](https://resources.workstate.com/blog/topic/workstate-codes)
- [AWS (4)](https://resources.workstate.com/blog/topic/aws)
- [Application cloud migration (4)](https://resources.workstate.com/blog/topic/application-cloud-migration)
- [Big Data (4)](https://resources.workstate.com/blog/topic/big-data)
- [For Developers (4)](https://resources.workstate.com/blog/topic/for-developers)
- [Indentity and Access Management Best Practices (4)](https://resources.workstate.com/blog/topic/indentity-and-access-management-best-practices)
- [Lift and Shift (4)](https://resources.workstate.com/blog/topic/lift-and-shift)
- [Workstate (4)](https://resources.workstate.com/blog/topic/workstate)
- [Best practices (3)](https://resources.workstate.com/blog/topic/best-practices)
- [Cloud Innovation (3)](https://resources.workstate.com/blog/topic/cloud-innovation)
- [big data insights (3)](https://resources.workstate.com/blog/topic/big-data-insights)
- [Application Security (2)](https://resources.workstate.com/blog/topic/application-security)
- [Google Cloud (2)](https://resources.workstate.com/blog/topic/google-cloud)
- [IdentityServer3 (2)](https://resources.workstate.com/blog/topic/identityserver3)
- [Insider (2)](https://resources.workstate.com/blog/topic/insider)
- [Microsoft Azure (2)](https://resources.workstate.com/blog/topic/microsoft-azure)
- [data intelligence (2)](https://resources.workstate.com/blog/topic/data-intelligence)
- [hadoop (2)](https://resources.workstate.com/blog/topic/hadoop)
- [Azure Active Directory Best Practices (1)](https://resources.workstate.com/blog/topic/azure-active-directory-best-practices)
- [Design Patterns (1)](https://resources.workstate.com/blog/topic/design-patterns)
- [Development teams (1)](https://resources.workstate.com/blog/topic/development-teams)
- [IdentityModel (1)](https://resources.workstate.com/blog/topic/identitymodel)
- [Programmer Productivity (1)](https://resources.workstate.com/blog/topic/programmer-productivity)
- [QA & Testing (1)](https://resources.workstate.com/blog/topic/qa-testing)
- [Technology mentorship (1)](https://resources.workstate.com/blog/topic/technology-mentorship)
- [identity and access management best practices (1)](https://resources.workstate.com/blog/topic/identity-and-access-management-best-practices)

see all

![Round Workstate Logo](https://resources.workstate.com/hs-fs/hubfs/Workstate-Nov2016/Image/Footer%20Logo.png?width=350&name=Footer%20Logo.png "Round Workstate Logo")

Columbus  
Los Angeles  
Pittsburgh  
San Francisco  
Seattle

**OUR PRACTICES**

[Technology Team Rental](http://workstate.com/teamrental)  
[Big Data](http://workstate.com/bigdata)  
[Cloud Shift](http://workstate.com/cloud-shift)  
[Identity and Access Management](http://workstate.com/iam)  
[QA and Testing](http://workstate.com/qa)  
[Application Security](http://workstate.com/appsecurity)

**CONTACT**

  (614) 559-3904  
  [hello@workstate.com](mailto:hello@workstate.com)

30 Spruce St. Suite 300  
Columbus, OH 43215

<https://twitter.com/workstate> <https://www.linkedin.com/company/workstate> <https://facebook.com/workstate>