Orleans.Lattice.Membership.Entra.Graph
9.9.0
dotnet add package Orleans.Lattice.Membership.Entra.Graph --version 9.9.0
NuGet\Install-Package Orleans.Lattice.Membership.Entra.Graph -Version 9.9.0
<PackageReference Include="Orleans.Lattice.Membership.Entra.Graph" Version="9.9.0" />
<PackageVersion Include="Orleans.Lattice.Membership.Entra.Graph" Version="9.9.0" />
<PackageReference Include="Orleans.Lattice.Membership.Entra.Graph" />
paket add Orleans.Lattice.Membership.Entra.Graph --version 9.9.0
#r "nuget: Orleans.Lattice.Membership.Entra.Graph, 9.9.0"
#:package Orleans.Lattice.Membership.Entra.Graph@9.9.0
#addin nuget:?package=Orleans.Lattice.Membership.Entra.Graph&version=9.9.0
#tool nuget:?package=Orleans.Lattice.Membership.Entra.Graph&version=9.9.0
Orleans.Lattice.Membership.Entra.Graph
Microsoft Graph-backed group resolver for Orleans.Lattice.Membership.Entra.
Entra ID tokens cap the number of group ids they carry. When a caller belongs to
more groups than the token can hold, Entra omits the groups claim and marks the
token as overflowed. This package resolves that overflow: it calls Microsoft
Graph to fetch the caller's full transitive group membership and hands it back to
the Entra authenticator through the IEntraGroupResolver seam.
The same registration also installs a Graph-backed ILatticeIdentityDirectory
(provider id entra) that searches and resolves the tenant's users and groups,
sharing the resolver's app-only Graph client.
The Microsoft Graph SDK and MSAL dependencies live here, isolated from the core Entra authenticator package, so applications that never hit the overage case pay for neither.
Transparent token management
On the default client-secret path the resolver acquires its own app-only
Microsoft Graph access token through the MSAL confidential-client token cache
(AcquireTokenForClient), which caches the token and transparently refreshes it
before expiry; a secret-less TokenCredential (for example a managed identity)
can be supplied instead. Operators never hand-manage
or rotate a Graph token. Concurrent group lookups share a single in-flight token
acquisition rather than each triggering their own, so a cold cache does not
stampede the token endpoint.
Register it after the Entra authenticator, and set that authenticator's
GroupResolutionMode to EntraGroupResolutionMode.ResolveOnOverage: the
authenticator consults the resolver for the overage case only in that mode (its
TokenOnly default never makes an external lookup).
See the Entra Graph documentation for configuration.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Graph (>= 6.5.0)
- Microsoft.Identity.Client (>= 4.88.0)
- Microsoft.Kiota.Abstractions (>= 2.0.0)
- Microsoft.Orleans.Sdk (>= 10.2.2)
- Orleans.Lattice.Membership.Entra (>= 9.9.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 9.9.0 | 52 | 10/2/2026 |
| 9.8.0 | 100 | 9/26/2026 |
| 9.7.0 | 98 | 9/21/2026 |
| 9.6.0 | 331 | 9/5/2026 |
| 9.5.0 | 102 | 9/2/2026 |
| 9.4.0 | 115 | 8/29/2026 |
| 9.3.0 | 103 | 8/25/2026 |
| 9.2.0 | 116 | 8/23/2026 |
| 9.1.0 | 108 | 8/20/2026 |
| 9.0.0 | 142 | 8/14/2026 |
| 8.0.1 | 178 | 7/21/2026 |
| 8.0.0 | 122 | 7/20/2026 |
| 7.9.0 | 114 | 7/9/2026 |
| 7.8.0 | 123 | 7/4/2026 |