Connect Microsoft 365
Grant Microsoft 365 tenant consent and import your organization into Elba.
Connecting Microsoft 365 lets Elba import users and use the Microsoft capabilities available to your workspace.
Administrator required
Use a Microsoft Global Administrator for the end-to-end setup. Elba recognizes Application Administrators in parts of the sign-in flow, but some tenant-wide permissions can require the stronger role.
Choose the directory import scope
Before granting Microsoft consent, choose which directory records Elba will import:
- Entire directory is the default. Elba imports the eligible users and groups available in the tenant.
- Specific Entra security group imports one security-enabled group and its eligible direct members. Paste the immutable Object ID shown in the group's Microsoft Entra overview.
For a group-scoped import, the Elba organization owner must be an eligible direct member of the selected group. An eligible user is an enabled Entra account with userType set to Member and an email address or user principal name. Guests, disabled accounts, users without either value, and members inherited from nested groups are excluded.
Save the intended scope before continuing. The scope cannot be changed after administrator consent has been granted.
Microsoft permissions remain tenant-wide
Group scope limits the directory data that Elba queries and stores. It does not limit the Microsoft application permissions granted during tenant consent, which remain tenant-wide.
See Microsoft 365 scopes and their purpose for a permission-by-permission explanation.
Authorize Elba
- Sign in with a work or school account for the Microsoft tenant you want to connect.
- Start the Microsoft 365 connection from Elba onboarding or Settings → Integrations.
- Configure the workspace details requested by Elba.
- Choose Entire directory or Specific Entra security group. For group scope, paste the group Object ID.
- Select Authorize to save the scope and open Microsoft’s tenant-consent flow.
- Review the requested permissions and grant consent for the organization.
- Return to Elba and wait for the authorization and scope checks to complete.
- Allow the initial user import to finish. Consent can take up to a minute to propagate, and the import can take a few minutes.
How group-scoped synchronization works
- Elba imports only the selected group's metadata and its eligible direct users. It does not enumerate the tenant's complete users or groups collections.
- Membership is reconciled on a schedule. Directory changes appear within 24 hours, provided synchronization completes successfully.
- Selecting a group as the import scope does not automatically enroll that group in Elba. Complete the usual enrollment step separately.
- After a completed synchronization, users who are no longer eligible direct members are removed from the active Elba scope and unenrolled.
- If the selected group is unavailable, deleted, or no longer contains the organization owner as an eligible direct member, Elba aborts stale-user cleanup. Existing synchronized users are not removed, and Elba never falls back to an entire-directory import.
Verify the connection
- Elba completes the authorization step and advances to the next onboarding stage.
- Users from the intended tenant or selected group begin appearing in Elba.
- Microsoft 365 reports as connected under Settings → Integrations.
Connect a GDAP customer as an MSP
For an existing Microsoft MSP workspace, use the GDAP tab of the MSP dashboard to add a customer. This is the customer connection journey; the directory-import setup above applies to the organization's own Microsoft connection.
The list belongs to your MSP. Opening an existing customer through Log In, including in another tab, does not change which partner's customers are listed or which ones are marked Connected. The table shows 25 customers per page. Use the next-page control for later customers, or search by part of the customer's name. Search ignores capitalization and treats punctuation as normal text.
If GDAP itself offers Connect, complete the Microsoft authorization for your MSP. When Microsoft has not yet supplied the required permissions, Elba waits for up to five minutes. If Connect appears again, retry the GDAP authorization. This wait concerns access to the list; the customer connection below has its own confirmation step.
- Open the MSP dashboard and choose GDAP.
- Select Connect on the intended customer row.
- Complete Microsoft's administrator consent for that customer, then return to Elba in the same browser.
- Elba checks the consent and the customer's relationship to your MSP before adding it. A confirmed connection returns to the MSP dashboard. Opening another existing customer with Log In in a different tab does not change which MSP receives the selected customer.
If Microsoft has not confirmed the consent yet, Elba checks again automatically every five seconds, for up to five minutes after you started the connection. It then offers Check again and Back to the GDAP customers. The connection attempt expires after thirty minutes; select Connect on the customer again to start a new attempt.
If the connection is refused, the GDAP list explains why:
- Canceled consent: no customer was added. Select Connect to start again.
- Unmatched or expired attempt: return to the intended customer row and select Connect in this browser.
- Customer relationship could not be confirmed: check the GDAP connection before starting again. This message does not prove that the customer is absent from your MSP.
- An Elba organization already exists for that Microsoft tenant: use the support link shown in Elba instead of retrying indefinitely.
Recover an unavailable customer list
If Elba cannot read the complete GDAP list, it shows elba could not load your GDAP customers with Try again. No customer rows are shown in that state; it does not mean that you have no customers or that an existing customer is disconnected. Select Try again to reload the list. The page waits for this action rather than retrying the failed list continuously.
A dashboard tab left open before this update may keep showing a spinner while the list is unavailable. Reload that page to use the current warning and retry controls. If the problem persists, or the intended customer is still missing after checking search and later pages, contact Elba support. Do not select a different customer as a workaround.
Repeating the same confirmed customer-consent return does not add another customer or send another welcome email. A consent page opened before the customer-connection update may return to the dashboard without a notice; select Connect again from the intended customer row if the customer was not added.
Troubleshooting
- Make sure the signed-in account belongs to the intended tenant and has Global Administrator access.
- If your tenant blocks user consent, ask the Microsoft 365 administrator to complete the flow.
- If Elba cannot find the selected group, copy its Object ID—not its name—from Microsoft Entra and confirm that it belongs to the connected tenant.
- If Elba rejects the group, confirm that it is security-enabled and that the organization owner is an eligible direct member rather than a member of a nested group.
- If consent was granted but Elba is still waiting, allow a short propagation window before retrying.
- If Elba says an authorization was started for another organization, your existing settings are unchanged. Return to the Elba organization where you began the authorization, then start it again through that organization's setup. Do not grant access from the different organization shown in your current session.
- If you canceled an authorization or the Microsoft consent page expired without changing organizations, restart it from the same organization's setup.