Description
- This article explains the procedure for administrators to check the federation status when using Access Control federated with Microsoft 365.
Notes
- The content of this article is based on the product specifications as of August 2026 and may be changed without prior notice.
- Global administrator privileges for Access Control are required to actually make configuration changes.
For instructions on how to access the Administration, please refer to the following article.
How to Access the Access Control Administration - If federation with Microsoft 365 was established using PowerShell commands, it may not appear in Connected Services.
In such cases, you can check the connection status by adding the Connected Service using the procedure below.
[Access Control] Federation Connection Procedure with Microsoft 365
Procedure
-
From the Access Control Administration, go to [System] – [Connected Services].
-
From the list of services, select the row where the "Display Name" is [Microsoft] and the "Type" is [Microsoft].
* If federation was previously established only using the old procedure (PowerShell), "Microsoft" will not appear in the service list.
[Access Control] Federation Connection Procedure with Microsoft 365 -
Click [Federated Domains] – [Manage Domains].
- If the [Requested Permissions] screen for Microsoft 365 appears, check [Consent on behalf of your organization] and select [Accept].
* If authentication has already been completed, you can proceed to the next screen by selecting the user. -
On the "Domain Management" screen, the federation status of each domain in the authenticated tenant will be displayed.
Field (Domain Management)
| Status | Description | Notes |
| Federated | Federation is configured from the Access Control Administration (Note 1) | Click [Delete] to disconnect federation. [Access Control] Disconnection Procedure (Microsoft 365) |
| Federated (Old Procedure) | Federation is configured using Windows PowerShell (Note 1) | Click [Upgrade] to change the status to [Federated]. (Note 2) |
| Federated (Different IdP) | Federation is configured with an IdP other than Access Control | Click [Migrate] to change the federation from an IdP other than Access Control to Access Control. |
| Inherited Federation from Parent Domain | Federation status is automatically inherited from the parent domain | Click [Detach] to disconnect the parent-child relationship with the parent domain. |
| Federation Not Available | Federation cannot be configured | You can check the reason why it cannot be configured by clicking the "?" next to it. |
Note 1: Federation configuration from the Access Control Administration is the method introduced in the setup procedure as of September 2025.
It uses a more secure technology than the previous Windows PowerShell configuration.
Note 2: To disconnect federation, first change the status using [Upgrade], then click [Delete].
Note 3: For the federation status, please check the status of the parent domain.