{"id":82218,"date":"2023-06-05T13:10:22","date_gmt":"2023-06-05T17:10:22","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=82218"},"modified":"2024-10-18T19:15:32","modified_gmt":"2024-10-18T23:15:32","slug":"m365-sync","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/m365-sync","title":{"rendered":"Microsoft 365 \/ Entra ID Directory Sync"},"content":{"rendered":"\n
The Microsoft 365 (M365)\/Entra ID Cloud Directory sync integration allows for secure and persistent connectivity between JumpCloud and M365\/Entra ID. The integration allows you to automatically, in real-time, provision new JumpCloud user accounts into M365\/Entra ID, continuously synchronize specified user attributes from JumpCloud to M365\/Entra ID, manage security groups, and take over management of existing user accounts and security groups in M365\/Entra ID from JumpCloud. In addition, admins can import users from M365\/Entra ID into JumpCloud through the M365\/ Entra ID Directory Sync or import and continuously synchronize user attributes using an Entra ID SCIM integration.<\/p>\n\n\n\n
Important Considerations<\/strong><\/p>\n\n\n\n Creating an integration between JumpCloud and M365\/Entra ID starts with adding the M365\/Entra ID integration in the Cloud Directories page of the Admin Portal. Once added, you authorize M365\/Entra ID Directory synchronization. After you authorize sync, you must validate your password expiration setting in Microsoft.<\/p>\n\n\n\n <\/p><\/div> Don\u2019t authorize the same M365\/Entra ID domain in multiple M365\/Entra ID directory sync instances. If you do, users that are given access to multiple M356\/Entra ID directory instances that are connected to the same domain could be suspended if you remove access\u00a0from one of the instances. You can avoid this by deactivating sync for all but one M365\/Entra ID directory sync instances for a single domain. Be aware that after you deactivate sync for an M365\/Entra ID directory instance, that sync integration is permanently deleted and cannot be recovered.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To add and authorize M365 Sync integration in JumpCloud<\/strong><\/p>\n\n\n\n <\/p><\/div> You\u2019ll receive an error and won\u2019t be able to proceed if:<\/p>\n\n\n\n After account synchronization is established between JumpCloud and M365\/Entra ID, perform the following steps to make sure JumpCloud is the authority for password expiration for users in M365\/Entra ID.<\/p>\n\n\n\n After you authorize sync with Microsoft, a modal opens with a list of existing active Microsoft user accounts.<\/p>\n\n\n\n You can close this tab to import accounts at a later time, or you can continue importing accounts now.<\/p>\n\n\n\n For more information and instructions for manually importing users, see Sync Users and Groups to Microsoft 365 \/ Entra ID<\/a>. <\/p>\n\n\n\n For more information about importing and syncing users from M365\/Entra ID in real-time using a SCIM integration, see Configure Real-time User Provisioning from Entra ID.<\/a><\/p>\n\n\n\n There are a few more steps to complete the M365\/Entra ID Cloud Directory Synchronization Integration setup. <\/p>\n\n\n\n Simplify access control using group management from JumpCloud. Create and update group names and membership in M365\/Entra ID from JumpCloud.<\/p>\n\n\n\n <\/p><\/div> Disabling group management will leave the groups as-is in M365\/Entra ID and stops managing membership.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Specify one or more domains as part of the integration configuration to have more granular control over which user accounts sync and how the translation rule for the email to User Principal Name (UPN) mapping is applied. There are three (3) possible configurations: no domains, a list of one or more domains but no default, and a list of one or more domains with one of those domains used as a default for the UPN translation rule. Each configuration is described in more detail below.<\/p>\n\n\n\n Examples of how domains are used by the integration.<\/p>\n\n\n\n\n
\n
Adding and authorizing an M365\/Entra ID Sync Integration<\/strong><\/h2>\n\n\n\n
\n
\n
\n
Validating the Password Expiration Setting in Microsoft<\/strong><\/h3>\n\n\n\n
To check Microsoft’s password expiration setting<\/strong><\/h4>\n\n\n\n
\n
\n
Importing M365 Users<\/strong><\/h2>\n\n\n\n
M365\/Entra ID<\/strong> Synchronization Configuration and Maintenance<\/strong><\/h2>\n\n\n\n
\n
Enabling Management of Security Groups and Memberships<\/strong><\/h3>\n\n\n\n
To enable security groups and membership management<\/strong><\/h4>\n\n\n\n
\n
To disable security groups and membership management<\/strong><\/h4>\n\n\n\n
\n
Managing Domain(s)<\/strong><\/h3>\n\n\n\n
\n
\n