Yres
HomeFeaturesConnectorsPricingCompareCustomer storiesFAQ
NL|EN
Talk to a data architect
Yres

Data stays in your own Azure tenant

Address

Friesestraatweg 219 9743 AD Groningen

Contact

info@yres.app
+31 85 130 3905

About us·Microsoft Marketplace

Product

  • Features
  • Integrations
  • Pricing
  • FAQ

Background

  • What is data warehouse automation?
  • Why not just Azure Data Factory?
  • Compared with other tools
  • Yres compared with TimeXtender
  • Yres compared with AnalyticsCreator
  • Yres or building it yourself on Azure
  • A data foundation for AI
  • Yres and Microsoft Fabric

Who it is for

  • Housing associations
  • Food and manufacturing
  • Partners
  • Customer stories

Service

  • Wiki
  • Academy
  • Log in
  • Talk to a data architect

© 2026 Yres. Yres Oog op Data

Privacy PolicyIRIS is now Yres
Connectors/Microsoft Graph
Microsoft Graph logo

Microsoft 365 data through Microsoft Graph in your Azure data warehouse

Microsoft 365 data via Graph

Microsoft Graph is Microsoft's entry point to Microsoft 365 data, and in Yres the underlying connection for scenarios such as Teams and Office 365. You register one app in Microsoft Entra ID, grant it the Graph permissions your question requires and enter the tenant ID, client ID, client secret and scope. Yres obtains a token with OAuth2, sends it with every request and walks through all pages. The data lands in an Azure SQL database in your own tenant and can be used in Power BI from there.

Talk to a data architectView all connectors

At a glance

Connection
Microsoft Graph version 1.0. The address is fixed; Yres builds the token address from your tenant ID
Sign-in
OAuth2 through an app in Microsoft Entra ID. Grant type Client Credentials or Authorization Code (which requires a refresh token)
Scope
The OAuth scope you enter, for example https://graph.microsoft.com/.default
Permissions
Application or delegated permissions on Microsoft Graph, depending on your scenario, with admin consent from an administrator
Paging
Yres follows the next-page link (@odata.nextLink) Graph includes in every response
Where it runs
On the Azure Data Factory cloud runtime; Graph is publicly reachable over HTTPS. Self-hosted only when traffic must pass through a restricted or on-premises network
Where the app's details are kept
Client ID, secret and grant type in the Key Vault of your own environment; refresh token, scope and token address in a configuration table of your own data warehouse database

What you arrange yourself

  1. 1Register an app in the Microsoft Entra admin center and copy the Application (client) ID and the Directory (tenant) ID from the overview page.
  2. 2Create a client secret under Certificates & secrets. Copy the value at once, because it is displayed only one time.
  3. 3Under API permissions, add the Graph permissions for the data you want to read and have an administrator grant admin consent.
  4. 4Decide on the grant type: Client Credentials for access without a signed-in user, Authorization Code plus a refresh token for access on behalf of a user.
  5. 5Add the Graph source in Yres and enter the tenant ID, client ID, client secret, scope and grant type.

When you need this — and when you don't

A standalone connector is enough if…

If you need a single overview from Microsoft 365, an export or a built-in report in the admin center is quicker than an app registration and a data warehouse.

Yres adds value if…

Yres earns its place when Microsoft 365 data has to sit next to other sources on a permanent basis, for example users and groups next to your HR system, refreshed at fixed times without anyone producing exports.

Frequently asked questions: Microsoft Graph

Which Microsoft 365 data can I load through Graph?

Whatever the Graph endpoints return that your app has rights to. That is the core of this connection: one app registration, and the permissions determine what is readable. Yres does not prescribe permissions; you choose application or delegated permissions that fit your scenario and have an administrator approve them.

Where is the refresh token stored?

Not in the web application. Client ID, client secret, grant type and the address go to the Key Vault of your environment. The refresh token, the scope and the token address are kept in a configuration table in your own data warehouse database, where the process that renews tokens uses them.

What do I enter in the Scope field?

The OAuth scope Yres requests a token for. For Microsoft Graph that is, for example, https://graph.microsoft.com/.default. You do not enter the token address yourself: Yres builds it from your tenant ID and shows it as a read-only field.

Is Microsoft Graph an OData source in Yres?

Graph uses OData conventions and Yres pages through the OData next link, but it is not a plain OData source with Basic sign-in. Since version 1.56 Yres stores Graph as an OData source with OAuth2, so the token is obtained per run and sent along as a header.

Full technical description in the knowledge base →·Last reviewed: 2026-09-21

Data warehouse automation that runs in your own Azure

Built for organisations on Azure and Power BI. Yres connects your sources, keeps the history and promotes changes in a controlled way, without manual work.

Talk to a data architectSee how it works