Overview
This article explains the configuration procedure for customers who want to manually or periodically synchronize user information from Access Control to Microsoft Entra ID.
Notes
- The content of this article is based on product specifications as of September 2026 and is subject to change without notice.
- To configure user synchronization, you need global administrator privileges for Access Control and global administrator privileges for Microsoft 365.
- For instructions on how to access the Administration, please refer to the following article.
[Access Control] How to log in to the Administration - User synchronization must be configured for each domain.
- Before executing user synchronization, you must register the required users in Access Control in advance.
- Users created in Microsoft Entra ID via user synchronization from Access Control will not be assigned Microsoft 365 licenses.
If necessary, please assign Microsoft 365 licenses to users from the administrator after synchronization. - After enabling periodic synchronization, user information will be synchronized every hour.
*The synchronization interval cannot be changed. - The user attributes synchronized to Microsoft 365 are [Family name], [Given name], [Display Name], and [UserPrincipalName].
Passwords from Access Control are not synchronized to Microsoft 365. In addition, for synchronization with Microsoft 365, the email address is retrieved from Microsoft 365 and reflected in Access Control. - If you are already synchronizing users from Active Directory to Microsoft Entra ID, this procedure is not required.
Pre-checks
- For the domain to be synchronized, please change the domain of non-user objects.
Change UPN of non-user objects to onmicrosoft.com domain
Procedure
-
From the Access Control Administration, go to Provisioning Settings.
-
From the Sync from Access Control menu, click + Add Service.
-
On the Select Sync Service screen, click the service you want to synchronize.
If only [Entra ID] is displayed, such as during the initial sync, click [Entra ID].If the [Use Saved Data] menu is displayed, click the target tenant from [Use Saved Data] and proceed to step 6.
*This menu appears if you have already completed [Accept] for [Requested Permissions] in step 5. - The Microsoft 365 login screen will appear. Log in with a global administrator account.
- When the [Requested Permissions] screen appears, click [Accept].
-
Select the domain to synchronize, change the settings as needed, and click [Continue].
-
Domain
Check the domain(s) to be synchronized. -
User Deletion Threshold (%)
If the percentage of users to be deleted exceeds the set threshold, the process will be canceled to prevent unintentional mass deletion of users.
Example: If the user deletion threshold is set to 65%, the process will be canceled if more than 65% of users are to be deleted during synchronization.
-
Domain
-
The [Requested Permissions] screen will appear. Check [Consent on behalf of your organization] and select [Accept].
*If this screen does not appear and you proceed to the next screen, authentication has already been completed. Please proceed to the next step. -
For each target domain, click [Start Sync Preview] to output the expected user synchronization results.
*If you have multiple domains, please run the sync preview for each domain. -
Select [Download Result] and check the downloaded sync preview result (CSV file).
*If you have multiple domains, please check the results for each domain.
*The user deletion threshold is not applied to the sync preview, so the preview may show user deletions exceeding the threshold.Please be sure to check the sync preview results with reference to the following.
If the sync results include unexpected Add, Delete, or Update users, click [Cancel], edit the user information as needed, and try again.
If you have any questions, please contact your HENNGE representative or HENNGE One Technical Support.
*The order of users in the output user list cannot be changed.
*The output user list includes the Immutable ID for each user.
If Add or Delete appears in the sync preview results+
If Update appears in the sync preview results+
-
If there are no issues, click [Continue].
-
Select [Set up periodic sync] or [Sync Now], then click [Execute].
*It is recommended to perform a sync preview and [Sync Now] to confirm that synchronization works as expected before setting up periodic sync.-
Sync Now
Immediately synchronizes user information (Add, Delete, Update).
*When you execute [Sync Now], user information (Add, Delete, Update) will be synchronized immediately and Microsoft 365 users will be updated.
Please execute only after confirming that the sync preview results are as expected. -
Set up periodic sync
Synchronizes user information (Add, Delete, Update) from the sync source service to the sync destination service every hour. -
About synchronization (Add, Delete, Update)
- Add: If a user exists only in the sync source service and not in the sync destination service, the user will be added to the sync destination service.
- Delete: If a user does not exist in the sync source service but exists in the sync destination service, the user will be deleted from the sync destination service.
- Update: If the same user exists in both the sync source and sync destination services, and there are differences in items such as family name, given name, or display name, the values in the sync destination service will be updated to match the sync source.
-
Sync Now
-
Click [Check Sync Logs] to confirm the synchronization results.
*If you selected [Periodic Execution for Entra ID], synchronization will not be performed at the time periodic sync is enabled, so it will not appear in the sync logs.
After enabling periodic sync, user information will be synchronized every hour and sync logs will be output.
For details on how to check sync logs, please refer to the following article.
[Access Control] How to check sync logs
*Once you have confirmed that user synchronization has completed successfully, please be sure to contact your HENNGE One implementation representative or support desk.
If you are using multiple domains and want to configure user information for another domain later, please refer to the following procedure.
Add a domain for periodic user synchronization in Access Control (Access Control → Microsoft 365)