Before you start
Make sure you have registered the Cognite API and the CDF application in Microsoft Entra ID and set up Microsoft Entra ID and CDF groups to control access to CDF data.Step 1: Register an app in Microsoft Entra ID to use with Transformations
Sign in to Azure portal
Select your tenant
Open Microsoft Entra ID
Create new app registration
Register the application
Copy the Application ID
Create a client secret

Configure the secret
Copy the client secret value
Step 2: Create a group in Azure AD and add the registered app as its member
Open Groups in Azure AD
Create a group
Add members to the group
Add the app as a member
Add users
Copy the Object ID

Step 3: Create a group in CDF and link to the Microsoft Entra ID group
Navigate to Groups in CDF
Create a new group
Add capabilities
read and write capabilities accordingly for the CDF resources you want to read and write using transformations. For instance, if you are transforming the data in RAW and writing the data to assets, you must add raw:read and asset:write capabilities.projects:list, groups:list, transformations:read, transformations:write, and sessions:create.Create the group
Configure OpenID connect
token_url. The token_url contains the ID of your Microsoft Entra ID tenant. To find your tenant ID, see this article.sessions:create and set the token_url to maintain access to Transformations for an extended time period.To enable Run as current user for transformations, you must add the sessions:create capability.Link to Microsoft Entra ID group
- In the Source ID field, enter the Object Id for the AAD group exactly as it exists in AAD. You can use the same group Id for multiple transformations.
- In the Source name field, enter the name of the group in Azure AD.