Connect Microsoft 365
Grant Microsoft 365 tenant consent and import your organization into Elba.
Connecting Microsoft 365 lets Elba import users and use the Microsoft capabilities available to your workspace.
Administrator required
Use a Microsoft Global Administrator for the end-to-end setup. Elba recognizes Application Administrators in parts of the sign-in flow, but some tenant-wide permissions can require the stronger role.
Choose the directory import scope
Before granting Microsoft consent, choose which directory records Elba will import:
- Entire directory is the default. Elba imports the eligible users and groups available in the tenant.
- Specific Entra security group imports one security-enabled group and its eligible direct members. Paste the immutable Object ID shown in the group's Microsoft Entra overview.
For a group-scoped import, the Elba organization owner must be an eligible direct member of the selected group. An eligible user is an enabled Entra account with userType set to Member and an email address or user principal name. Guests, disabled accounts, users without either value, and members inherited from nested groups are excluded.
Save the intended scope before continuing. The scope cannot be changed after administrator consent has been granted.
Microsoft permissions remain tenant-wide
Group scope limits the directory data that Elba queries and stores. It does not limit the Microsoft application permissions granted during tenant consent, which remain tenant-wide.
See Microsoft 365 scopes and their purpose for a permission-by-permission explanation.
Authorize Elba
- Sign in with a work or school account for the Microsoft tenant you want to connect.
- Start the Microsoft 365 connection from Elba onboarding or Settings → Integrations.
- Configure the workspace details requested by Elba.
- Choose Entire directory or Specific Entra security group. For group scope, paste the group Object ID.
- Select Authorize to save the scope and open Microsoft’s tenant-consent flow.
- Review the requested permissions and grant consent for the organization.
- Return to Elba and wait for the authorization and scope checks to complete.
- Allow the initial user import to finish. Consent can take up to a minute to propagate, and the import can take a few minutes.
How group-scoped synchronization works
- Elba imports only the selected group's metadata and its eligible direct users. It does not enumerate the tenant's complete users or groups collections.
- Membership is reconciled on a schedule. Directory changes appear within 24 hours, provided synchronization completes successfully.
- Selecting a group as the import scope does not automatically enroll that group in Elba. Complete the usual enrollment step separately.
- After a completed synchronization, users who are no longer eligible direct members are removed from the active Elba scope and unenrolled.
- If the selected group is unavailable, deleted, or no longer contains the organization owner as an eligible direct member, Elba aborts stale-user cleanup. Existing synchronized users are not removed, and Elba never falls back to an entire-directory import.
Verify the connection
- Elba completes the authorization step and advances to the next onboarding stage.
- Users from the intended tenant or selected group begin appearing in Elba.
- Microsoft 365 reports as connected under Settings → Integrations.
Troubleshooting
- Make sure the signed-in account belongs to the intended tenant and has Global Administrator access.
- If your tenant blocks user consent, ask the Microsoft 365 administrator to complete the flow.
- If Elba cannot find the selected group, copy its Object ID—not its name—from Microsoft Entra and confirm that it belongs to the connected tenant.
- If Elba rejects the group, confirm that it is security-enabled and that the organization owner is an eligible direct member rather than a member of a nested group.
- If consent was granted but Elba is still waiting, allow a short propagation window before retrying.
- Restart the authorization from Elba if the Microsoft consent page has expired.