Choose your directory import scope.
Synchronize eligible users and groups, across your directory or a selected Entra security group.
Synchronize your directory, then connect OneDrive and SharePoint to review file exposure. Add Teams separately to send employees security notifications.
Directory sync · Separate OneDrive, SharePoint, and Teams connections
Product illustration · Example data and workflow.
Capabilities
Synchronize eligible users and groups, across your directory or a selected Entra security group.
Connect OneDrive and SharePoint separately to review sharing and remove eligible item permissions.
Enable the separate Teams connection to send employees security notifications.
Example workflow
How the integration supports a specific security task.
A separate OneDrive or SharePoint connection surfaces an eligible sharing issue.
Your team reviews the item and decides which access is still needed.
An eligible permission is removed through the connected Data Protection source.
Related capability
Before you connect
The Microsoft 365 base connection synchronizes directory data. Teams notifications, phishing simulations, and SharePoint or OneDrive Data Protection use separate Microsoft applications or consent flows.
Explore security & privacyUse a Global Administrator for the complete flow. Some tenant-wide permissions require that role even when an Application Administrator is recognized during part of sign-in.
No. It limits which directory records elba queries and stores, while the application permissions accepted during tenant consent remain tenant-wide.
Not after administrator consent. Choose and validate the intended import boundary before authorizing the connection.
No. These capabilities use separate applications or consent flows and must be reviewed and enabled independently.
Discuss your requirements
Review the available capabilities, required permissions, and setup for your environment with our team.