to navigate · to open See all results

Microsoft Entra ID

Connect Microsoft Entra ID directory sync, choose the groups to import, understand what changes during a sync, and disconnect safely.

Last updated

The Directory Sync settings page connects AssetCenter to Microsoft Entra ID. It keeps your People records aligned with members of the Entra groups you choose, so you do not have to maintain the same staff details in two places.

Directory sync is separate from Microsoft sign-in. Changing the organization's login method controls how AssetCenter users sign in. Directory sync maintains People records, which represent employees, contractors and other people who can be assigned assets, subscriptions and locations. A synced person does not automatically receive an AssetCenter user account.

Only an AssetCenter account administrator can manage the connection. A Microsoft administrator must grant AssetCenter permission to read directory users and group memberships. AssetCenter reads from Entra and does not edit your Microsoft directory.

Connect Microsoft Entra

  1. Open Settings from the main menu.
  2. Select Directory Sync.
  3. Press Connect Microsoft Entra.
  4. Sign in to Microsoft with an administrator account that can grant consent for the organization.
  5. Review and accept the requested directory permissions. Microsoft then returns you to the Directory Sync page in AssetCenter.

If Microsoft cannot complete the connection, AssetCenter shows an error on the Directory Sync page. Confirm that you used a work or school Microsoft account with permission to grant organization-wide consent, then try connecting again.

Choose groups to sync

After connecting, use Search Entra groups to add to find a group by its display name. Enter at least two characters, then select a result to add it to Synced groups. You can select more than one group; a person who belongs to several selected groups is added only once.

To remove a group from the sync, press the close button on its group label. Removing a group does not immediately delete People. On the next sync, a previously synced person who is no longer a member of any selected group is marked inactive.

Select at least one group, then press Sync now to start the first sync immediately. You can also wait for the next automatic sync.

What directory sync updates

AssetCenter runs directory sync automatically every ten minutes. You can press Sync now at any time when a sync is not already running. The page shows whether a sync is running, when the last one completed and whether it succeeded, partially completed or failed.

For each member of a selected group, AssetCenter can keep these Person fields current from Entra:

  • First and last name
  • Email address
  • Job title and department
  • Mobile or business phone number
  • Organization or company name
  • External guest status
  • Active or inactive status
  • Profile photo

If an existing Person has the same email address as a directory member, AssetCenter links that record during the first match instead of creating another one. Future syncs use the person's Entra identity, so a later email address change still updates the linked record correctly.

If more than one existing Person shares that email address, AssetCenter links the oldest of them and leaves the rest alone. Use Merge Duplicates on the People list to fold those extra records into one.

Directory members whose Microsoft account is disabled are marked inactive. Previously synced people who leave every selected group are also marked inactive. AssetCenter keeps their records and assignment history; directory sync does not delete them. People created manually and never linked to Entra are not changed by directory sync.

If your plan has a People limit, new active directory members can be added only while capacity remains. Existing linked People are still updated. The sync is marked partial when additional directory members were skipped because the limit was reached.

Disconnect or reconnect

Press Disconnect and confirm to stop automatic directory sync. People that were already synced remain in AssetCenter and can be managed manually. Disconnecting does not delete their records or history.

If the page says Connection needs attention, Microsoft may have rejected or revoked the connection. Press Reconnect, complete administrator consent again and then run a new sync. Reconnecting later links previously synced People back to their Entra identities.

Directory sync keeps your People aligned with Microsoft Entra. To keep your Apple hardware aligned with what your organization actually bought, see Apple Business.

For related tasks, see Managing people, Users and Organization.