Skip to main content

Microsoft 365 Synchronization

Menu Path: Settings > Inbound Provisioning > Microsoft365


Table of Contents

  • Overview
  • Setting Synchronization Target
  • Path Display Reference Group Settings
  • Automatic Synchronization
  • Manual Synchronization
  • Microsoft account integration processing
  • Caution

Overview

Synchronize users and groups registered in Microsoft 365 (Azure Active Directory) with the Security365 management center. You can choose to synchronize either the entire directory or only specified AD groups.

**Reference:**You can only enable one inbound provisioning method. When you enable Microsoft 365 synchronization, other methods (SCI Server, local Active Directory, CSV directory synchronization) will be disabled.

**Preconditions:**You must have a Microsoft 365 account with administrator privileges to set up the integration.


Setting Synchronization Target

Select the range to synchronize.

Full synchronization

Synchronize all AD groups and associated users of Microsoft 365.

  • You can manually select the path display reference group (when the checkbox is activated).

**Caution:**When selecting full synchronization, all groups and users registered in Microsoft 365 will be reflected in the admin center. Please check in advance to ensure that unnecessary users are not included.

Syncing Specified AD Group

Synchronize only the selected specific AD group and the users belonging to that group.

  1. AD 그룹 관리of[그룹 선택]Select the group to synchronize by clicking the button.
  • [구성원 보기]You can check the subgroups and member information of the group selected by the button.
  • It will be synchronized with the subgroups as well.
  1. [확인]Click the button to check the selected group information.
  2. bottom of the[저장]Click the button to apply the settings.

**Caution:**If you switch to the specified AD group synchronization method, data from groups that were previously synchronized outside of the selection may be deleted. Be sure to check the impact scope before the switch.

Reference:The types of groups supported in Microsoft 365 areSecurity GroupandMail Groupis. Other group types (such as Microsoft 365 groups) are excluded from synchronization targets.

Reference: 사용자, 그룹User and group information manually entered in the menu will not be deleted due to synchronization.


Path Display Reference Group Settings

Specify the group that serves as the basis for displaying the affiliation path of synchronized users in logs and on the screen.

Synchronization MethodHow to Set Up Path Display Reference Group
Full synchronizationActivate checkbox and manually select from dropdown (1 top-level root group)
Syncing Specified AD GroupThe groups selected as synchronization targets are automatically set as the top-level root group.

**Caution:**If the reference group is set incorrectly, the group path of some users may not be displayed in the logs.


Automatic Synchronization

itemDescription
Microsoft Account Automatic SynchronizationUse / Do not use selection
Synchronization PeriodWhen using automatic synchronization, set the time (hour/minute) to run daily.
  • If automatic synchronization is not used,**[Manual Synchronization]**You can press the button to synchronize immediately.
  • When using automatic synchronization, synchronization will automatically occur at the set time every day.
  • During automatic synchronization**[Manual Synchronization]**You can press the button to execute immediately.

Manual Synchronization

After saving the settings, on the inbound provisioning list screen, in the Microsoft365 card,**[Manual Synchronization]**Clicking the button will execute synchronization immediately.

  • After synchronization is complete, the success/failure status and completion time will be displayed.

**Caution:**Duplicate execution is not possible while synchronization is in progress.


Microsoft account integration processing

After importing users with Microsoft 365 synchronization, the Microsoft account login must be enabled in the authentication settings for that user to log in with a Microsoft account.

If you signed up manually without using Microsoft:

Synchronization MethodIntegration Method
Full synchronization[수동 동기화]Link your Microsoft account with the button.
Syncing Specified AD Group[AD 그룹 관리]Link your Microsoft account with the button.

After logging in with a Microsoft account that has administrator privileges and receiving delegated permissions, a connection success notification will be displayed.

**Caution:**After successful account linking,설정 > 사용자 인증atSecurity365 인증 사용andCSP 인증 사용 > Microsoft 계정 인증You need to activate it for existing administrators to log in with a manual account.


Caution

  • You must have an account with Microsoft 365 admin permissions to set up the integration.
  • You must have the necessary permission delegation completed in Azure AD.
  • Even if you directly modify synchronized user information in the management center, it will be overwritten with the original information from Microsoft 365 during the next synchronization execution. If permanent changes are needed, please modify it in Microsoft 365 first.
  • Changing the group selection in the specified AD group synchronization method may affect the previously synchronized user/group data.
  • If synchronization fails, check the network connection status and Microsoft 365 integration settings.
  • If there are missing users, check if the user is included in the selected group.
  • You can only activate one inbound provisioning method, and if another method is already activated, you must use it after switching.