Target
Customers who synchronize users between Microsoft Entra ID and HENNGE Access Control.
If you synchronize users each time by "Data Synchronization" in [Domain Settings] - [HENNGE Directory Sync Connection] without periodic synchronization, please check the restrictions in the following paragraphs as this update will change the operation.
Contents
Periodic user synchronization settings between HENNGE Access Control and Entra ID can now be performed in the Admin Console.
This allows you to stop and restart periodic synchronization at any time on the Admin Console.
Immediate synchronization outside of the periodic synchronization time is also still available.
For customers who are currently setting up periodic synchronization, the settings on the "Provisioning Settings" page will change as shown in the image below.
The following image is an example of synchronization from HENNGE Access Control to Entra ID.
The new screen now displays the ID of the Entra ID tenant being connected and the domain name being synchronized.
The following can be performed on the "Check Details" screen.
- Check sync logs
- Check DryRun logs
- Execute "Sync Now"
- Execute "DryRun"
- Disable periodic sync
- Change the Max Allowed Deletions setting(※)
※What is the Max Allowed Deletions?
The synchronization process is canceled if the deletion rate of the synchronization destination user exceeds the set value.
Example) When the user deletion tolerance rate is set to 90 in the synchronization setting from HENNGE Access Control to Entra ID, if the deletion rate of Entra ID users exceeds 90%, the synchronization process is canceled.
Notes
With this update, if you do not set periodic synchronization, you will no longer be able to save Entra ID tenant information on the HENNGE Access Control screen.
Therefore, if you want to synchronize users each time without setting periodic synchronization, please go through the setup wizard for synchronization settings from "Add Service" and execute "Sync Now".
※This operation is required every time, but the Powershell execution part can be omitted after the first time.