Two ways. First, a custom connecter was written to access the data from Graph API. In the Azure AD tenant, we deploy a new enterprise application to the Graph API which exposes data, including Azure AD. Second, certain Microsoft software including Defender for Endpoint and Log Analytics use “out of the box” APIs that are called up from the query themselves and require a simple log in to your tenant to be imported.