Benefits of granting Teams and Entra ID synchronization permissions
Granting the Directory.Read.All, Group.Read.All, and User.Read.All permissions to the absentify Group Sync Permission app offers significant advantages for your organization:- Automated department management: Syncs user group memberships directly with department assignments in absentify, making it easier to maintain accurate team structures.
- Manager synchronization: Ensures that department managers or group owners assigned in Microsoft are automatically reflected as managers in absentify.
- Prefill for User Export: Populates absentify’s Excel import file with users from Teams and Azure AD groups, streamlining user onboarding and reducing manual data entry.
Default functionality without permissions
If the Directory.Read.All, Group.Read.All, and User.Read.All permissions are not granted, absentify’s Teams and Entra ID synchronization features are unavailable. Without these permissions:- Manual department assignments: HR or admin teams must manually assign users to departments in absentify, increasing administrative effort and the potential for outdated information.
- No automated manager sync: Manager assignments will need to be manually maintained, increasing administrative workload for HR.
- Limited user onboarding efficiency: The user export and onboarding processes will lack automatic population from Teams and Entra ID, requiring manual data entry.
How absentify uses the Directory and Group permissions
To promote transparency and trust, here’s how absentify uses the Directory.Read.All, Group.Read.All, and User.Read.All permissions in the absentify Group Sync Permission app:- Directory sync: Directory.Read.All allows absentify to access group and organizational information necessary to mirror your company’s structure in absentify without accessing additional personal data.
- Group management: Group.Read.All permits absentify to read group memberships and sync changes as department structures change, ensuring that department assignments and managers are consistently updated.
- User information: User.Read.All allows absentify to access basic user profile information needed for synchronizing user details with Teams and Entra ID groups.
- Secure storage: All group and department data is stored in absentify’s database to maintain application performance and reduce reliance on Microsoft API calls. Data is stored securely in Azure North Europe, adhering to GDPR requirements. Access to this data is strictly limited to authorized personnel at absentify GmbH, with no access for developers or external parties.
Security and data protection
absentify adheres to strict security protocols to protect your organization’s data:- ISO 27001 certification: absentify is ISO 27001 certified, confirming compliance with international standards for information security management.
- Microsoft 365 App Certification: The absentify Group Sync Permission app has achieved Microsoft 365 App Certification, meeting Microsoft’s requirements for security, privacy, and compliance. This certification assures that absentify follows best practices in data handling.
- Controlled access: Access secrets and permissions required for group synchronization are securely stored in an Azure Key Vault, restricted to necessary personnel only. No developers or members of other departments can access production data, ensuring full data security.
Enabling Teams and Entra ID synchronization
Grant Directory.Read.All for the absentify Group Sync Permission app from absentify. Do not open a public Microsoft consent URL. Go to Settings > Microsoft and turn on the feature. If the Microsoft permission is missing, Permissions Required opens. If someone sent you a consent link from that page, open that link instead. If you are a tenant administrator, select I am a Tenant Administrator, then Grant Permissions Now. You need a linked Microsoft account. Microsoft opens so you can grant the permission. If you are not a tenant administrator, select I am not a Tenant Administrator. Select Open Pre-Filled Email or Copy Consent Link, then send that request to your IT team. On the web, Grant Permissions Now takes you to Microsoft. You leave absentify and return to Settings > Microsoft with a result banner. If Microsoft confirmed consent but the permission is not visible to absentify yet, Settings > Microsoft shows Waiting for Microsoft… and Microsoft confirmed the consent. The permission usually shows up within a minute; this page checks every few seconds. Select Check now. In Microsoft Teams or SharePoint, Microsoft opens in another window. Settings > Microsoft then shows Waiting for Microsoft… and Grant the permission in the window that opened, then come back here. Select I have granted it. A banner on Settings > Microsoft reports the result after you return from the web. Copied or emailed links, and the window in Microsoft Teams or SharePoint, open a result page instead. That page may show Permission granted, Almost there, Permission was not granted, Wrong Microsoft 365 tenant, This link is no longer valid, or Something went wrong. If the feature was switched off in absentify, you see Permission was not activated. If you close Microsoft before consent, or if consent is declined, nothing changes. Granting the permission requires a Microsoft 365 administrator. A copied or emailed link belongs to your workspace and expires after 14 days. A request you start in the app expires after 15 minutes. Old public Microsoft consent URLs fail with This link is no longer valid. Start again from absentify. If your tenant later revokes the permission, the row shows a warning and Grant again. Teams and Entra ID (Azure Active Directory) Groups synchronization must be on in Settings > Microsoft. If you started from that page, a successful grant turns it on. Then go to Settings > Integrations to connect Teams and Entra ID groups.Key features of Teams and Entra ID synchronization
With the Teams and Entra ID integration enabled, absentify provides several key features:- Auto-create user accounts: Automatically create new user accounts in absentify based on Teams and Entra ID group memberships.
- Sync department membership: Department assignments are updated as users are added to or removed from Microsoft groups.
- Archive users: Automatically archive users in absentify if they are no longer assigned to departments in Microsoft.
- Sync group owners as department managers: Keep department manager assignments in absentify aligned with group owners in Microsoft.
-
Automatic filtering of disabled accounts: absentify only syncs users whose Microsoft Entra ID account is enabled (
accountEnabled: true). Disabled accounts, such as terminated or unlicensed users, are automatically excluded from synchronization.
Revoking permissions
If you need to revoke the Directory.Read.All, Group.Read.All, or User.Read.All permissions for the absentify Group Sync Permission app, follow these steps:- Access Azure Active Directory: Sign in to the Azure portal with your Microsoft 365 administrator account.
- Navigate to Enterprise applications: In the left-hand menu, go to Azure Active Directory > Enterprise applications.
- Find and select absentify Group Sync Permission: Locate the absentify Group Sync Permission app (App ID: 488f9b43-3708-4ee5-ad96-de025c894343) in your list of applications.
- Manage permissions: Go to the Permissions section and select Directory.Read.All, Group.Read.All, and User.Read.All to revoke absentify’s access to group and directory data.