Target
- Administrators using Access Control
- Environments using Access Control and Microsoft 365 with federation settings
Purpose
- This document explains the procedure to verify the federation status between Access Control and Microsoft 365.
Notes
- The content of this article is based on the product specifications as of October 2025 and may change without notice.
- Global administrator privileges for Access Control are required for actual configuration changes.
Please refer to the following article for how to access the Administration.
How to Access the Access Control Administration
Procedure
-
Access the [System] - [Edit Connected Service] from the Access Control Administration.
-
Select the row where the "Display Name" is [Microsoft] and the "Type" is [Microsoft] from the list of services.
-
Click [Federated Domains] - [Manage Domains].
- If the [Required Permissions] screen for Microsoft 365 is displayed, check [Consent on behalf of your organization] and select [Accept].
※ If verification is complete, select users to proceed to the next screen. -
On the "Domain Management" screen, the federation status of each domain in the verified tenant is displayed.
Items (Domain Management)
| Status | Description | Description |
| Federated | Federation settings are configured from the Access Control Administration (※1) | Click [Delete] to disconnect the federation. [Access Control] Disconnect Procedure (Microsoft 365) |
| Federated (Legacy) | Federation settings are configured with Windows Powershell (※1) | Click [Upgrade] to change the status to [Federated]. (※2) |
| Federated (Different IdP) | Federation settings are configured with an IdP other than Access Control | Click [Migrate] to change the federation destination from an IdP other than Access Control to Access Control. |
| Federation linked to parent | Automatically inherits the federation settings state of the parent domain | Click [Separate] to disconnect the parent-child relationship with the parent domain. |
| Unable to Federate | Unable to configure federation settings | The reason for the inability to configure can be checked from the adjacent "?". |
※1 The federation settings from the Access Control Administration are the method introduced from September 2025 onwards.
It adopts a safer technology than the conventional Windows PowerShell settings.
※2 If you want to disconnect the federation, first change the status with [Upgrade], then click [Delete].
※3 Please check the status of the parent domain for the federation status.