{"id":82442,"date":"2023-06-05T13:11:23","date_gmt":"2023-06-05T17:11:23","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=82442"},"modified":"2024-04-09T12:19:26","modified_gmt":"2024-04-09T16:19:26","slug":"faq-m365-directory-integration","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/faq-m365-directory-integration","title":{"rendered":"FAQ: Microsoft 365 Directory Integration"},"content":{"rendered":"\n
JumpCloud uses an OAuth2 token for authorization, and TLS to secure and persist its connection with Microsoft 365 to perform our integration tasks. <\/p>\n<\/div><\/div><\/div>\n\n\n\n
Within the Microsoft 365 admin console, navigate to the admin center for Entra ID<\/strong>. From the Entra ID admin center dashboard, select the Users<\/strong> tab and then the Audit logs<\/strong> tab under Activity<\/strong>. All events occurring via the JumpCloud \/ Microsoft 365 OAuth connection are logged in these audit logs under the admin account used to authorize the OAuth connection in JumpCloud. It is best practice to create a dedicated Microsoft 365 admin account to authorize the JumpCloud \/ Microsoft 365 OAuth connection. <\/p>\n<\/div><\/div><\/div>\n\n\n\n When the OAuth session is deactivated in JumpCloud, all users in Microsoft 365 will remain active and functioning. This is by design. Within JumpCloud, all user accounts will remain active as well when de-authorization with Microsoft 365 occurs. Note that when de-authorization occurs, all selected members bound to Microsoft 365 are un-selected. When and if the products are-reactivated, the admin will need to re-bind the users in the Microsoft 365 Directory to re-establish the connection and ownership-control of the accounts in Microsoft 365. <\/p>\n<\/div><\/div><\/div>\n\n\n\n While this was previously not a supported configuration, use of the Active Directory Bridge can now indeed be used when either Google Apps or Microsoft 365 user provisioning are enabled.<\/p>\n<\/div><\/div><\/div>\n\n\n\n JumpCloud can integrate with multiple Microsoft 365 tenants, but JumpCloud users are only able to integrate with one M365 tenant based on their email address. JumpCloud does not support binding users to multiple M365 tenants.<\/p>\n<\/div><\/div><\/div>\n\n\n\n At this time, JumpCloud can not import user profile pictures or avatars into JumpCloud’s user accounts. <\/p>\n<\/div><\/div><\/div>\n\n\n\n At this time, JumpCloud does not support integration with GoDaddy’s implementation of Microsoft 365. This version has more limited management capabilities that require SSO login with GoDaddy’s services in order to operate appropriately. Because of these requirements, we are inhibited from making changes to the identity with the integration.<\/p>\n<\/div><\/div><\/div>\n\n\n\n Prior to 1 January 2013, generic MX records such as mail.global.frontbridge.com could be used for email. After 15 July 2014, if they weren’t updated, service disruption may be experienced. See the Microsoft Communities article<\/a> for more information.<\/p>\n<\/div><\/div><\/div>\n\n\n\n The Microsoft 365 and Google Workspace Directory integrations can be used together to successfully synchronize both service providers with JumpCloud. The directory integrations utilize the user’s email address as the unique identifier for synchronization. Due to this architecture, your domain records may need to be mapped so that the same email address is used between all service providers. For more information refer to the follow vendor-specific documentation:<\/p>\n\n\n\n Are your new JumpCloud users not getting their Welcome emails? Microsoft 365 may be blocking your emails from JumpCloud because of the pre-inbox filters you\u2019re using. Try adding an allow-list entry in Microsoft 365 for the jumpcloud.com<\/a> domain. Learn how to securely add a sender to an allow list in Microsoft 365 in Step 7 of Microsoft\u2019s Configure your spam filter policies<\/a> article.<\/p>\n\n\n\n Read about Microsoft 365\u2019s anti-spoofing protection<\/a>.<\/p>\n<\/div><\/div><\/div>\n\n\n\n Upon import, you will see a failure for this user to import, as an account with the same email already exists. <\/p>\n<\/div><\/div><\/div>\n\n\n\n JumpCloud’s Microsoft 365 synchronization UI displays all of your Microsoft 365 users, regardless of whether they were previously imported. We will provide filtering mechanisms and improved workflow in the future. <\/p>\n<\/div><\/div><\/div>\n\n\n\n At this time, only user accounts and security groups are supported between JumpCloud and Microsoft 365. <\/p>\n<\/div><\/div><\/div>\n\n\n\n No. Once the Global Administrator credentials have been authenticated, the connection to Microsoft 365, regardless of Administrator, can perform importation and provisioning tasks. <\/p>\n<\/div><\/div><\/div>\n\n\n\n Please see the attributes table in Sync User Attributes with M365<\/a>.<\/p>\n<\/div><\/div><\/div>\n\n\n\n While an admin can prevent a welcome email from being delivered to the end user when creating the account, binding the user to Microsoft 365 will send an email to the employee. We recommend educating the employee base first before adding them to Microsoft 365.<\/p>\n<\/div><\/div><\/div>\n\n\n\n Not right away. It takes a few minutes for the JumpCloud user to be provisioned in M365. Once that is done, their license will need to be added manually for them. The user will then need to reset their password through JumpCloud so their JumpCloud and M365 passwords will be in sync.<\/p>\n<\/div><\/div><\/div>\n\n\n\n Yes, Directory Insights will show only the successful <\/strong>events referenced in the table below.<\/p>\n\n\n\n\n
Importing<\/h2>\n\n\n\n
Provisioning<\/h2>\n\n\n\n
\n\n
\n \n DI Event <\/th>\n \n Description <\/th>\n <\/tr>\n \n \n \u00a0user_create_provision <\/td>\n \n Logged when a user is created in M365.\u00a0 <\/td>\n <\/tr>\n \n \n user_update_provision <\/td>\n \n Logged when one or more user attributes are updated in M365.\u00a0 <\/td>\n <\/tr>\n \n \n user_password_update_provision\u00a0\n <\/td>\n \n Logged when a user\u2019s password is updated in M365. <\/td>\n <\/tr>\n \n \n user_deprovision\n <\/td>\n \n Logged when user is deactivated in M365 due to the user being suspended or having access to the integration revoked in JumpCloud. <\/td>\n <\/tr>\n <\/table>\n<\/div><\/div>\n<\/div><\/div><\/div>\n\n\n\n Synchronization<\/h2>\n\n\n\n