Include
- Customers implementing Access Control
- Customers using Microsoft 365 as groupware
Purpose
- This article explains how to federate Microsoft 365 with Access Control and configure access control.
* If you wish to integrate with other cloud services, please set up Single Sign-On integration.
Notes
- Please check the required items according to your services and use cases.
- The content of this article is based on the product as of January 2026 and is subject to change without notice.
Table of Contents
- Change the default domain setting in Microsoft 365 (external link)
- Disable "Always connect to Outlook" feature in Outlook on the web
- Check the status of modern authentication for Exchange Online
- Collect Device Info for Device Certificates
- Consider Access Control operation policy
- Configure Access Control operation policy
User Sync from Active Directory to Microsoft 365 / Access Control
- Organize users in Active Directory
- Configure Microsoft Entra Connect and start user sync
- Install HDEPasswordFilter.dll on all domain controllers (WS 2016 or later)
- Install HENNGE Directory Sync Tool
- Install root certificate for HENNGE Directory Sync Tool operation
- Create API client for running HENNGE Directory Sync Tool
- Initial setup of HENNGE Directory Sync Tool configuration file (config.ini)
- Set passwords for users to be synced
- Confirm password settings for users to be synced
- Run HENNGE Directory Sync Tool
User Sync between Access Control and Microsoft 365
- Change object UPN to onmicrosoft.com domain
- Batch user registration / update / delete
- Configure user sync between Access Control and Microsoft Entra ID
Allow Secure Browser unread notifications at the tenant level
- Configure Secure Browser unread notifications
Settings required on the end user side to use Access Control access control
- Install Secure Browser
- Device authentication for Secure Browser
- Configure OTP (One-Time Password) to be received via application
- Configure OTP (One-Time Password) to be received via email
- Issue Device Certificate
- Install Device Certificate
- Check Device Certificate installation status
- Install application to read Device Certificate
Access Control Access Policy Settings
- Assign Access Policy Groups to users
- Test Access Policy Group policy operation
- Assign browser policy groups to users
Settings for using the HENNGE One portal site
- Add Microsoft 365 link to HENNGE One portal site
Connect Access Control and Microsoft 365
- Federation connection work between Microsoft 365 and Access Control
- Confirm federation between Access Control and Microsoft 365
- Disconnect Microsoft Entra ID modern authentication
- Connect with services using Single Sign-On (SSO)
Procedure
Preparation
Change the default domain setting in Microsoft 365
Change the default domain setting of your Microsoft 365 tenant to .onmicrosoft.com (the initial domain of the Microsoft 365 tenant).
For details, please check with Microsoft or your Microsoft 365 reseller.Disable "Always connect to Outlook" feature in Outlook on the web
Check the status of modern authentication for Exchange Online
Collect device information
* If you are using Device Certificates, please perform this step.
Device information is required to issue Device Certificates.
Please select and collect information for the target devices in advance.- Consider Access Control operation policy
Consider the operation policy for Access Control (access control rules, items displayed on the login screen, etc.). - Configure Access Control operation policy
Reflect the considered Access Control operation policy in the actual product settings.
User Sync from Active Directory to Microsoft 365 / Access Control
If you want to sync users from Active Directory to Access Control, please follow this section.
- Configure Microsoft Entra Connect and start user sync
For details, please check with Microsoft or your Microsoft 365 reseller. Install HDEPasswordFilter.dll on all domain controllers (WS 2016 or later)
Procedure for installing root certificate for HENNGE Directory Sync Tool operation
Initial setup of HENNGE Directory Sync Tool configuration file (config.ini)
- Set passwords for users to be synced
Change the password for all users to be synced once.
User Sync between Access Control and Microsoft 365
If you want to sync users between Access Control and Microsoft 365, please follow this section.
Change object UPNs other than Microsoft 365 users to onmicrosoft.com domain
-
Batch user registration / update / delete
-
Configure user sync between Access Control and Microsoft Entra ID
First, refer to the following article to configure immediate and scheduled sync for the target domain.
Access Control User Sync Settings (Access Control → Microsoft 365)* If you are using multiple domains and want to add user sync settings for another domain after already configuring user sync, please refer to the following article.
Add domain for scheduled Access Control user sync (Access Control → Microsoft 365)
Allow Secure Browser unread notifications at the tenant level
Configure Secure Browser unread notifications
* This section is for customers using Secure Browser.
Settings required on the end user side to use Access Control access control
Install Secure Browser
* This section is for customers using Secure Browser.Device authentication for Secure Browser
* This section is for customers using Secure Browser.Configure OTP (One-Time Password) to be received via application
* This section is for customers using OTP.Configure OTP (One-Time Password) to be received via email
* This section is for customers using OTP.Issue Device Certificate
* This section is for customers using Device Certificates.Install Device Certificate
* This section is for customers using Device Certificates.Check Device Certificate installation status
* This section is for customers using Device Certificates.- Install application to read Device Certificate
* This section is for customers using Device Certificates.
Install Microsoft Authenticator
Access Control Access Policy Settings
Assign browser policy groups to users
* This section is for customers using Secure Browser.
Settings for using the HENNGE One portal site
How to Add a Microsoft 365 Link to the Access Control User Portal
* For customers using the HENNGE One portal site.
Access Control and Microsoft 365 Connection
Federation Connection Procedure for Access Control and Microsoft 365
How to Verify Federation Between Access Control and Microsoft 365
Connecting to Services for Single Sign-On (SSO)
If you have services other than Microsoft 365 that use SSO, you can download procedures with a proven track record from this section.