Azure Active Directory (Azure AD) User Sync

Azure Active Directory (Azure AD) User Sync

Azure Active Directory (Azure AD) User Sync

Integrate Microsoft Entra ID (previously called Azure AD User Sync) with ServiceDesk Plus MSP Cloud to sync user details from the Microsoft Azure AD account of your organization and customers periodically.

Notes
Any changes in Microsoft Azure AD will be automatically updated in ServiceDesk Plus MSP Cloud based on sync configuration.
ServiceDesk Plus MSP Cloud only reads user information from Microsoft Azure AD via API and does not modify.

Enable Azure AD User Sync Integration

Info
Role Required: SDAdmin/OrgAdmin
  1. Go to Setup > Apps & Add-ons > Integrations > Third Party Integrations.
  2. From the customer filter in the header, select your organization or the customer you want to configure.
  3. Enable the toggle on the Azure AD User Sync card.
  4. When the integration is enabled, the flow to authorize integration differs based on the selected customer.
Case 1: If integration is enabled for your organization, a pop-up is displayed where you can perform the following:
  1. Read through terms and conditions.
  2. Choose whether full user details must be synced from Microsoft Azure AD, besides basic details.
  3. Click Agree.
  4. To authorize the integration, you will be prompted to sign in to Microsoft account as global administrator.
 
Case 2: If the integration is enabled for a specific customer, an authorization notification is sent to the customer's point of contact (POC) ServiceDesk Plus MSP Cloud account.
  1. The POC can authorize the integration from Quick Actions  in ServiceDesk Plus MSP Cloud.
  2. To complete the authorization, the POC will be prompted to sign in to the Microsoft account of their tenant as global administrator.
  3. After the authorization is complete, the Azure AD User Sync integration will be enabled.
 
Info
If the SDAdmin/OrgAdmin (case 1) or the customer's POC (case 2) is not a Microsoft Azure global administrator, they must obtain consent from the Microsoft Azure global administrator to authorize the integration. Learn how.
  1. Post integration, every two minutes, a minimum of 200 users will be updated to ServiceDesk Plus MSP Cloud.

Info
At any point in time, the integration can be revoked.
  1. If SDAdmin/OrgAdmin revokes the integration for a customer, the corresponding POC's authorization becomes invalid.
  2. If the POC revokes their authorization, the sync will no longer execute, and the integration will be disabled. To re-enable the integration, the customer must contact the MSP organization.
  3. The POC can authorize, revoke, and view their authorization status from Quick Actions  in ServiceDesk Plus MSP Cloud.

Configure Azure AD User Sync     

Schedule the sync, configure import criteria, map user fields, and choose how the user data must reflect in ServiceDesk Plus MSP Cloud for specific Microsoft Azure AD actions.
To do this, go to Setup > Apps & Add-ons > Integrations > Third Party Integrations, and click Configure on the Azure AD User Sync card.
Set Sync Frequency:  Set the sync frequency to define how often synchronization must execute. You can select a frequency ranging from 1 to 7 days.
Configure User Deletion Sync:   Choose how the user data must reflect in ServiceDesk Plus MSP Cloud when they are deleted in Microsoft Azure AD.
  1. Select how to handle when users are deleted: When users are deleted or moved to the trash in Microsoft Azure AD, you can modify user profiles in ServiceDesk Plus MSP Cloud by revoking their login, removing their profile, or doing nothing.
  2. Select how to handle deleted users during the next sync: You can either ignore the deleted users or re-sync them.     
  3. User profile picture sync: Choose whether the user profile picture must be synced from Microsoft Azure AD to ServiceDesk Plus MSP Cloud.
  4.  Default login state for users added from Azure AD to ServiceDesk Plus:  You can enable or disable login for ServiceDesk Plus MSP Cloud, or sync login status from Microsoft Azure AD.
  5. Default login state for users updated from Azure AD to ServiceDesk Plus: You can either follow login status from Microsoft Azure AD or do nothing.  
Field Mapping:   Map Microsoft Azure AD fields with the corresponding ServiceDesk Plus MSP Cloud fields, as shown.

Info
Only one Microsoft Azure AD field can be mapped per ServiceDesk Plus MSP Cloud field.
Field mapping supports user and technician additional fields.

Before the Azure AD User Sync is integrated, the following Microsoft Azure AD fields can be mapped by default: Name, First Name, Last Name, User Principal Name, and Email.
Post integration, the following fields will be available for mapping:
Microsoft Azure AD Fields
ServiceDesk Plus MSP Cloud Fields
Name
First name
Last name
User Principal Name
Email
Display Name
First Name
Last Name
Email
Employee ID
Email
Phone
Mobile
Department
Site
Job Title
Reporting Manager
Secondary Email
Character related UDFs
 
The following details can be mapped if Microsoft Azure or Entra ID User Sync integration is enabled by global administrator or user with global administrator's consent to integrate.
Microsoft Azure AD Fields
ServiceDesk Plus MSP Cloud Fields
Name
First name
Last name
User Principal Name
Job title
Department
Manager
Company Name
Employee ID
Street address
State or Province
Country or region
Office
City
ZIP or Postal Code
Office Phone
Mobile Phone
Email
Alternate Email
Cost Center
Division
Fax Number
On-premises Distinguished Name
On-premises Domain Name
On-premises Immutable Id
On-premises Last Sync Date Time
On-premises SAM Account Name
On-premises Security Identifier
On-premises User Principal Name
Display Name
First Name
Last Name
Employee ID
Email
Phone
Mobile
Department Name
Site
Job Title
Reporting Manager
Secondary Email
Character related UDFs

Additionally,
  1. Azure AD Login Name field is populated based on On-premises SAM Account Name, On-premises Domain Name, and On-premises User Principal Name fields.
  2. User profile images from Azure will be synced to their ServiceDesk Plus MSP Cloud accounts. Any updates to the profile image in Azure will automatically be reflected during subsequent syncs.
 
User Import Criteria: You can import all Microsoft Entra ID users into ServiceDesk Plus MSP Cloud or specific users based on criteria.
  1. To import specific users, select Based on Criteria and add the required conditions. For example, you can set a criterion to import users of specific sites only.
  2. To import all Microsoft Azure AD users, select Without Criteria.
Default Microsoft Azure AD fields available for criteria configuration:
  1. Domain
  2. Email
  3. First Name
  4. Last Name
  5. Name
  6. Usage Location
  7. User Principle Name
  8. Users with Azure Login
 
The following fields will be available for criteria configuration if Microsoft Azure or Entra ID User Sync integration is enabled by Microsoft Azure global administrator or user with global administrator's consent to integrate.
  1. User Type
  2. Department
  3. Office
  4. Job title
  5. Employee ID
  6. Mobile Phone
  7. Business Phone
  8. Reporting To
  9. City
  10. Company Name
  11. Street Address
  12. State or Province
  13. ZIP or Postal Code
  14. Country or Region
  15. Alternate Email
  16. Groups
  17. Cost Center
  18. Division
  19. Fax Number
  20. On-premises Sync Enabled
  21. On-premises Distinguished Name
  22. On-premises Domain Name
  23. On-premises Immutable Id
  24. On-premises Last Sync Date Time
  25. On-premises SAM Account Name
  26. On-premises Security Identifier
 
Finally, click Save and Sync to initiate the sync, or click Save to sync later.
 
You can sync later by using the Start Sync button in the Entra ID User Sync integration card.

Azure AD User Sync Reports     

Generate a report of all actions taken on user data synced from Azure AD, including additions, deletions, and modifications.
  1. Go to Setup > Apps & Add-ons > Integrations > Third Party Integrations.
  2. Click Configure in the Entra ID User Sync integration card.
  3. Under Sync Reports, select the Enable Azure AD User Sync Reports checkbox.
If enabled, you can download the report from the Entra ID User Sync integration card under Setup > Apps & Add-ons > Integrations > Third Party Integrations.
Info
User sync details are split into multiple reports, each up to 10 MB in size.
Up to 10 reports are available for download. You can download all or specific reports.
When the limit is exceeded, the oldest reports are removed automatically to accommodate new ones.

Resync Data from Azure    

Info
ServiceDesk Plus MSP Cloud Enterprise edition only.
After the initial sync, administrators can resync all data from Microsoft Entra ID to ServiceDesk Plus MSP Cloud when the integration configurations are modified after the user import.
  1. Go to Setup > Apps & Add-ons > Integrations > Third Party Integrations.
  2. Click Configure in the Entra ID User Sync card.
  3. Enable Resync to apply changes to the old data.
  4. Click Save.
 
Number of Users in Microsoft Azure AD
Number of Resync Allowed Per Day
Less than 10,000 users
2 resync (the time will be tracked for each resync individually)
More than 10,000 users
1 resync
 

Disable Azure AD User Sync   

  1. Go to Setup > Apps & Add-ons > Integrations > Third Party Integrations, and disable the toggle in the Azure AD User Sync integration card.
  2. In the confirmation pop-up, click Disable.
     
Warning
All users imported into ServiceDesk Plus MSP Cloud from Azure AD will be retained even after the integration is disabled.
   

Points to Remember   

  1. If the administrator who set up the Entra ID User Sync integration leaves the organization, the user who revokes the administrative privileges from the former administrator becomes the integration owner. The new integration owner's token will then be used to validate the integration.
  2. Users in unverified domains will be added as non-login users in ServiceDesk Plus MSP Cloud.
  3. Login users will be added based on the user sync configuration.
 

Sync Process Workflow     

 Authorization Workflow for Non-Admin Microsoft Azure Users 

When a non-admin Microsoft Azure user authorizes the integration, they will be prompted to request the Microsoft Azure global administrator to grant ServiceDesk Plus MSP Cloud access to the Azure AD user data.
To grant that access, Microsoft Azure global administrator must set up these requisites:
  1. Step 1: Grant admin consent for ServiceDesk Plus MSP Cloud
  2. Step 2: Configure admin consent settings
These steps are not mandatory if the integration is authorized by the Microsoft Azure global administrator.  
  1. Sign in to the Microsoft Entra ID admin center.
  2. Go to Enterprise applications.
  3. In the left pane, under Manage, select All applications.
  4. Search for the ServiceDesk Plus MSP Cloud application, and select it.
  1. In the left pane, under Security, click Permissions.
  1. Under the Permissions section, select Grant admin consent for ServiceDesk Plus MSP Cloud. You will now be redirected to complete the Microsoft authorization.

Step  2: Configure Admin Consent Settings       

  1. Sign in to the Microsoft Azure AD admin center.
  2. Go to Enterprise applications > Consent and permissions > Admin consent settings.
    1. Under Admin consent requests, select Yes for Users can request admin consent to apps they are unable to consent to.
  3. Configure the following settings:
    1. Who can review admin consent requests: Select users, groups, or roles eligible to review admin consent requests.
Info
  1. Global administrator and reviewers can approve consent requests for application permissions.
  2. Reviewers can view, block, or deny requests and view pending requests.
  3. New reviewers cannot act on existing or expired requests.
    1. Selected users will receive email notifications for requests: Enable or disable consent request email notifications for reviewers.
    2. Selected users will receive request expiration reminders: Enable or disable reminder emails to send before a request expires.
    3. Consent request expires after (days): Specify the number of days a consent request should stay valid.
  1. Click Save.

How Microsoft Azure Non-Admin Users Can Authorize Integration

The Azure AD User Sync integration requires authorization from:
  1. SDAdmin/OrgAdmin, if the integration is enabled for the MSP organization
  2. Customer's POC, if the integration is enabled for a specific customer
During authorization, the corresponding user will be prompted to sign in to Microsoft account as a global administrator.
If the POC or SDAdmin/OrgAdmin is not a Microsoft Azure global administrator, they will be prompted to request approval from the appropriate global administrator to authorize the integration, as shown:
The consent request will be submitted to the corresponding administrator/reviewers.
Info
Make sure the admin consent settings is configured in Microsoft Azure AD.
  1. Sign in to Microsoft Azure.
  2. Go to Microsoft Entra ID.
  3. Under Manage, click Enterprise applications.
  4. In the left pane, under Activity, select Admin consent requests.
  5. Go to the My Pending tab to view pending consent requests from non-admin users.
    1. Click the request you want to review.
  6. Click Review permissions and consent.
    1. To view the application details, go to the App details tab.
    2. To view the requester and the request reason details, go to the Requested by tab.
    3. To evaluate the request, use the Approve, Deny, or Block options. Learn more.