👑 Enterprise Feature
Would you like to use this feature? Please contact us to activate it!
📧 Contact: support@sproof.com
🤝 We look forward to your inquiry!
💡 At a glance
The Microsoft Entra ID synchronization enables plan admins to centrally and automatically manage plan members directly through the Microsoft environment. Profiles are reconciled, permissions are controlled via group IDs, and departing people are automatically removed from the sproof Sign plan. With the advanced configuration options, plan admins retain full control over how data fields are mapped, which information takes precedence, and which fields are allowed for plan members to edit.
Once set up, synchronization runs fully automatically every night to keep your plan up to date without manual effort.
⚙️ Configuration and field mapping
As a plan admin, you can now specify in detail how data import from Entra ID should occur. This includes defining overwrite rules, mapping custom attributes, and controlling user rights for profile changes.
-
Definition of overwrite logic: For each user property (e.g., first name, last name, job title), you determine whether existing data in sproof Sign may be overwritten by values returned from Entra ID or should be retained.
-
Mapping of attributes: You can assign individual Entra ID properties (Custom Properties) to the corresponding fields in sproof Sign. This ensures that specific directory data appears in the correct place in the plan member's profile.
-
Editability by plan members: In the configuration you set which profile fields are locked for plan members to edit and which they may change themselves despite active synchronization.
-
Cost center assignment: Assign a cost center to your plan members to have it automatically taken into account in the plan statistics.
-
Intelligent license control: Determine which license (User or User+) newly synchronized members should automatically receive.
📑 Step-by-step guide
Set up and start synchronization
-
Navigate in Settings to the "License & Team" section and select the "Plan Members" tab.
-
Click the button "Set up synchronization"
-
Confirm data access in the Microsoft window that appears.
-
An overlay opens where you can map your Entra ID fields to the sproof Sign target areas and define via switches whether plan members are allowed to edit the fields.
-
Start the synchronization by clicking "Save & Synchronize".
-
Using the "Manage synchronization" button you can return to the overlay at any time and make desired changes.
Error analysis and troubleshooting
If synchronization fails for individual people, the affected plan member is marked red in the list and a red cloud appears. Hovering the mouse over this cloud displays information that states the specific reason:
-
Not enough User licenses: The available quota for standard licenses in the plan is exhausted.
-
Not enough User+ licenses: There are no free User+ licenses available for a required upgrade.
-
Multiple group membership: The plan member is assigned to multiple groups in Entra ID that are synchronized with different sproof Sign roles.
In these cases you must either purchase additional licenses or correct the group assignment in Entra ID and then synchronize again.
Synchronization in combination with rights and role management
You can link synchronization directly with role management. When creating a new role in the general settings, simply assign the corresponding Microsoft Group ID. This way, permissions are automatically granted based on group membership in Microsoft Entra ID.
Important note: Adding a Microsoft Group ID changes the prioritization of roles. On a subsequent synchronization, the group role will overwrite your default role in role management. Newly synchronized members will therefore automatically receive the role assigned to the group ID instead of the default role.
Example: The role "Entra ID Sync" has been assigned a group ID. On a subsequent synchronization, new members will therefore automatically be created in sproof Sign with the role "Entra ID Sync", even if "Signer" was actually set as the default role.