Deel ATS integrates with your organization’s Microsoft Azure account to make interview scheduling seamless and secure. By connecting Azure, you can centralize scheduling, streamline authentication, and ensure that interview details are managed directly within Deel.
This article explains how clients can connect their organization's Microsoft Azure account to Deel ATS to schedule interviews with candidates.
In this article
Here’s what you’ll find in this article:
- Before you begin
- Step 1. Get a Microsoft Entra client ID and tenant ID
- Step 2. Get a Microsoft Azure private key
- Step 3. Customize API Permissions
- Step 4. (Optional) Prepare the app for automatic secret rotation
- Step 5. Connect your Microsoft Azure account
- Step 6. Allow Deel ATS to attach Microsoft Teams meetings
- Automatic secret rotation
Before you begin
To successfully follow this guide, you’ll need:
- A user with an admin role on Deel
- A user with a Global Administrator role on Microsoft Azure
Step 1. Get a Microsoft Entra client ID and tenant ID
On your Microsoft Azure portal, search for Microsoft Entra ID (formerly Azure Active Directory).
On the Entra ID overview page, click Add > App registration.
Give your app a name and click Register.
On the details page of your newly created app, copy the Application (client) ID and Tenant ID.
Step 2. Get a Microsoft Azure private key
On your app’s homepage, go to Certificates & secrets > Client secrets.
Click New client secret.
Provide a description, customize the expiration date, and click Add.
Copy the generated client secret.
Step 3. Customize API Permissions
Navigate to the API Permissions tab of your app.
Remove any default configured permissions.
Click Add a permission > Microsoft Graph > Application permissions.
-
Select the required permissions listed below and click Add permissions.
API Permission Name Type Description User User.ReadApplication Read all users' full profiles Calendar Calendars.ReadWriteApplication Have full access to user calendars Online Meetings OnlineMeetings.ReadWrite.AllApplication Read and create user's online meetings -
Back on the API permissions page, under Configured permissions, grant admin consent for the default directory.
Step 4. (Optional) Prepare the app for automatic secret rotation
Client secrets in Microsoft Entra expire. When the client secret expires, Deel ATS can no longer read calendars or schedule interviews until someone enters a new one.
With automatic secret rotation, Deel creates a replacement client secret before the current one expires and switches to it without interrupting interview scheduling. This step gives your Azure app the access Deel needs to do this.
If you prefer to replace the client secret manually, skip to Step 5.
Step 4a. Grant the rotation permission
Deel creates each replacement secret by calling the Microsoft Graph addPassword API on your app registration. This requires the Application.ReadWrite.OwnedBy application permission.
- On the app’s API permissions tab, select Add a permission > Microsoft Graph > Application permissions.
- Add the following permission:
| API | Permission name | Type | Description |
|---|---|---|---|
| Application | Application.ReadWrite.OwnedBy |
Application | Manage apps that this app creates or owns |
- Under Configured permissions, select Grant admin consent for your tenant, and confirm that the permission shows as granted.
Step 4b. Make the app an owner of itself
The Application.ReadWrite.OwnedBy permission only lets an app manage app registrations it owns. Granting the permission is not enough on its own: the app’s own service principal must also be an owner of its app registration.
The Owners page in the Azure portal only accepts users, so you must add this owner with the Azure CLI. You need two different object IDs:
| Value | Where to find it |
|---|---|
| App registration object ID | App registrations > your app > Overview > Object ID. This is not the Application (client) ID. |
| Service principal object ID | Enterprise applications > your app > Overview > Object ID. This is a different value from the app registration object ID. |
- Sign in to your tenant with the Azure CLI:
az login --tenant <tenantId> --allow-no-subscriptions
- Add the service principal as an owner of the app registration:
az ad app owner add \ --id <appRegistrationObjectId> \ --owner-object-id <servicePrincipalObjectId>
- Confirm that the service principal is now an owner. The output must include the service principal object ID:
az ad app owner list --id <appRegistrationObjectId> --query "[].id"
Step 4c. Check your tenant’s client secret lifetime policy
Deel creates each replacement secret with a lifetime of about six months. If your tenant has an app management policy that limits client secret lifetimes, the limit must be at least 180 days. Otherwise, Microsoft rejects every replacement secret and rotation cannot succeed.
If such a policy applies to your tenant, do one of the following:
- Exempt this app registration from the policy.
- Raise the limit to at least 180 days.
- Leave automatic secret rotation turned off and replace the client secret manually.
Step 5. Connect your Microsoft Azure account
1. On Deel, go to People > Hiring > Settings.
2. Select Interview settings > Microsoft Azure and click Connect.
3. Enter the private key, client email, and client ID generated in the previous sections.
4. Click Submit.
When Automatic secret rotation is on, Deel verifies your Azure setup before saving the connection. To do this, it creates a temporary client secret named Deel ATS rotation probe and removes it immediately. If the setup is incomplete, the connection is not saved and an error message explains what is missing. See Troubleshooting automatic secret rotation.
Step 6. Allow ATS to attach Microsoft Teams meetings
To enable ATS to automatically attach Microsoft Teams meetings to interviews, you must grant access using PowerShell. You can do this from your local PowerShell CLI or from Azure Cloud Shell.
Run the following command to create a Teams Meetings policy, replacing
<policy-name>with your chosen policy name and<application-client-id>with the App ID you copied in Step 1.4:
New-CsApplicationAccessPolicy -Identity <policy-name> -AppIds "<application-client-id>" -Description "Teams Meetings Policy"2. Run the following command to assign the policy globally:
Grant-CsApplicationAccessPolicy -PolicyName "<policy-name>" -GlobalOnce complete, ATS will be able to generate and attach Microsoft Teams links directly to scheduled interviews.
Automatic secret rotation
Automatic secret rotation is available for both Microsoft integrations in Deel ATS: the Microsoft Outlook email integration and the Microsoft Azure interview scheduling integration. It works the same way for both, but each integration has its own client secret and its own rotation setting.
| Integration | Where to manage it |
|---|---|
| Microsoft Outlook email integration | ATS Settings > Email management > Microsoft Outlook card |
| Microsoft Azure interview scheduling integration | ATS Settings > Interview settings > Microsoft Azure card |
The actions described below are in the menu on the integration’s card.
How automatic secret rotation works
When automatic secret rotation is on:
- About seven days before the current client secret expires, Deel creates a replacement secret on your app registration. The replacement secret is valid for about six months.
- Deel waits about an hour for the new secret to become active in Microsoft Entra, confirms that it works, and then switches to it. The integration keeps working without interruption.
- Deel does not delete the previous secret. It stays listed under Certificates & secrets until it expires. This is expected.
- The integration’s card shows Auto-rotation on and the expiry date of the current client secret.
When automatic secret rotation is off, ATS admins receive email reminders before the client secret expires, and the integration’s card shows an alert starting 14 days before the expiry date. To avoid interrupting the integration, replace the client secret before the current one expires, as described in Replacing the client secret manually.
Turning automatic secret rotation on or off later
You can turn automatic secret rotation on for an existing connection without disconnecting the integration.
- Complete Step 4.
- On the integration’s card, select Enable automatic secret rotation.
- For the Microsoft Azure interview scheduling integration only, enter the Tenant ID, Client ID, and Client secret again, leave Automatic secret rotation turned on, and select Submit.
For the Microsoft Outlook email integration, Deel verifies your Azure setup using the credentials that are already saved, so you do not need to enter them again. For the Microsoft Azure interview scheduling integration, Deel needs the client secret again to verify your Azure setup.
To verify the setup, Deel creates a temporary client secret named Deel ATS rotation probe and removes it immediately. If the setup is incomplete, rotation stays off and an error message explains what is missing. See Troubleshooting automatic secret rotation.
To turn automatic secret rotation off, select Disable automatic secret rotation on the integration’s card. The current client secret keeps working until it expires.
Replacing the client secret manually
You can replace the client secret at any time without disconnecting the integration:
- Create a new client secret for your app, as described in Step 2.
- On the integration’s card, select Update secret.
- Enter the Tenant ID, Client ID, and the new Client secret, and select Submit.
If automatic secret rotation is paused, entering a new client secret also resumes it.
Troubleshooting automatic secret rotation
| Problem | Did you try? | How to fix |
|---|---|---|
| “Azure setup incomplete for automatic secret rotation” when turning rotation on | Confirm that Application.ReadWrite.OwnedBy shows as granted under Configured permissions. | Repeat Step 4a and Step 4b. The app must be an owner of itself. |
| “Azure tenant policy blocks creating client secrets with the required lifetime” | Check your tenant’s app management policy for a client secret lifetime limit. | See Step 4c. |
| “Microsoft Azure rejected the credentials: the client secret is expired” | Check the secret’s expiry date under Certificates & secrets. | Create a new client secret, as described in Step 2, and enter it. |
| “Microsoft Azure rejected the credentials: authentication failed” | Check that the Tenant ID, Client ID, and Client secret are correct. | Copy the values again from Step 1 and Step 2. |
| “Could not verify the Azure setup for automatic secret rotation, please try again” | Try again after a few minutes. | If the error persists, check Step 4b. An app that is not an owner of itself can also produce this error. |
Rotation is paused because creating the replacement secret failed (secret_mint_failed) |
Check Step 4a, Step 4b, and Step 4c. Microsoft refused to create the replacement secret. | Fix the configuration, then select Resume rotation on the integration’s card. Alternatively, select Update secret and enter a new client secret. |
Rotation is paused because the replacement secret couldn’t be verified (secret_promotion_failed) |
Check that no Conditional Access policy blocks app-only sign-ins (client credentials) for this app. The replacement secret was created, but it could not be used to sign in. | Fix the policy, then select Resume rotation on the integration’s card. Alternatively, select Update secret and enter a new client secret. |