An overview of utilising Microsoft data rostering
Prerequisites
Before you get started with Microsoft user syncing, you should note the following:
We recommend using a generic email address rather than a personal account for syncing. However, if this is an existing, shared email address, the account cannot be blocked from Signing in.
- Exist as an Admin user in the Secure Schools platform
- Have the ability to view users and groups
- Be set as an Application Administrator and Cloud Application Administrator.
- Not be Blocked from Signing-in (as detailed above)
You can select a group from Security Groups or Distribution Groups, but Microsoft 365 Groups are not supported.
External: Microsoft 365 Group Types
Setting up the user sync
To begin this process, navigate to Settings > Manage user sync > Import settings and select the Microsoft tab.
When you click on Connect with Microsoft, you'll be prompted to log in with the account you wish to sync with and accept the required permissions. Depending upon your Microsoft tenancy, you may also need to approve the Secure Schools application.
Once your account has been connected, you'll need to select the group you wish to sync with:
Once you have triggered your first sync, your users will be pulled through, which you can view and manage under the Manage user sync screen.
Troubleshooting
If you are returned to the platform after logging into your account without being prompted to pick the groups to sync, there may be a mismatch in the accounts used to sign in and connect.
To address this, confirm:
- The account you're using must already exist in all organisations on the Secure Schools platform. You can add them via the Manage users option.
- You signed into Secure Schools using the exact account you are using to connect to your Microsoft tenancy. This cannot be a rerouted account, etc. and must match exactly.
For example, if you're using "secure-schools@mydomain.com," this must be the account you've signed into on the Secure Schools platform. - If you've previously signed into another account with your browser, this setting can sometimes persist even in a private browsing window. You can try using another browser that is not connected to another Microsoft account or ensure the other account is completely signed out of the browser.
If you are still having issues, please contact our support team.