Our Azure Active Directory Synchronization feature allows you to manage users inside the PII/PHI Protect portal with ease. Add, Modify, or Deactivate users as soon as they’re in your client’s system so they can get up to speed on cybersecurity, without a hitch.
This guide focuses on our Azure Active Directory Sync Simple Setup. This option is only available for Partners with access to a Global Admin account within their client’s tenant. Simple Setup is faster, requires no Powershell script, and helps preview user counts before beginning.
Partners without Global Admin access to their client's Azure tenants can utilize the Classic Setup options available. Classic Setup provides PowerShell script options but initial syncs will take up to 4 hours. No instant verification of setup is available.
Note: Before using this user sync tool, we recommend reviewing or configuring your Welcome Message options.
Quickly access key sections within this guide:
Setup in Microsoft 365 Admin Center
Configuration in the PII Protect Portal
Setup in Microsoft 365 Admin Center
Creating Groups
1. Create Azure AD Sync Security Groups to define the portal access for each employee. The following two groups MUST be created:
BSN-Employees: Defines the users that will be enrolled in the portal as standard employees under that client.
BSN-Managers: Defines users in the manager role, and supersedes BSN-Employees.
- Managers get access to reporting and employee data inside the PII/PHI Protect portal.
Note: When entering the above security groups, spaces are NOT permitted before, after, or within the string.
Important: If Azure AD Sync is enabled and these groups are NOT defined after the initial synchronization, there is a risk of users becoming deactivated in the portal and the users will be notified.
2. Create the BSN-Employees group with the following parameters:
Group Type: Security
Group Name: BSN-Employees
Group Description: PII/PHI Protect Standard Users
3. Assign users to the group.
Note: Be sure not to assign non-user accounts to this group as portal accounts WILL be created for all users assigned to this group. If you assign users to this group and to the BSN-Manager group, the manager role will take precedence. See this article for more information on the Employee role.
Important: For those using On-Premise along with Azure Sync to synchronize with the free tier or Azure AD: Nested group memberships are not supported for group-based assignments at this time.
4. Create the BSN-Managers group with the following parameters:
Group Type: Security
Group Name: BSN-Managers
Group Description: PII/PHI Protect Manager Role
5. Assign users to the group. All managers will also have an employee account. See this article for more information on the Manager role.
Optional Groups
Optional Group: BSN-PartnerAdmins
Group Type: Security
Group Name: BSN-PartnerAdmins
Group Description: PII/PHI Protect Partner Administrator Role
- This user has the highest level of access and will have all administrative functions for all accounts within your portal. This group is to ONLY be used for your company’s internal Breach Prevention Platform (BPP) account. See this article for more information on the Partner Admin role.
Optional Group: Add the BSN-ManagerAdmins group to give select managers the ability to manage phishing campaigns, as well as the bulk, manage user functionality. Standard manager accounts do NOT have this functionality. See this article for more information on the Manager Admin role.
Follow steps 2 - 3 using Group Name: BSN-ManagerAdmins and Group Description: PII/PHI Protect Manager Admin Role.
Creating Tags
- Optional: Create Tag Groups.
Tags are used for creating specific groups, typically to separate users by department, to create groups you’d like to send specific phishing emails to, or to simplify tracking in the portal.
Group Type: Security
Group Name: BSN-TAG-tagname
*tagname will be the tag you want the users associated with.
Example: BSN-TAG-Executive Team, BSN-TAG-Finance, etc.
Group Description: Optional field if you would like to add details on the tag you created.
7. Assign users to the group.
8. Click “Create”.
Important: For those using On-Premise along with Azure Sync to synchronize with the free tier or Azure AD: Nested group memberships are not supported for group-based assignments at this time.
Configuration in the PII Protect Portal
- Log into the PII Protect portal as a Partner Administrator and select “Manage Clients” to access your client list
- Select the client you want to sync with Azure Active Directory.
- Select the "User Management" tab then click the “Directory Sync” button.
- Use the Sync Type drop-down selector to select “Azure Active Directory”
- For Simple Setup, click the “Enable” button to begin (not the “Enable Manual Setup” button)
- Select which option you would like to use as Portal Logon. We highly recommend “Email”
- When ready, select the “Authorize Directory Access” button
- You will be taken to the Microsoft sign-in page. You MUST select/sign in with an account that is Global Admin within the client’s tenant
- After signing into your Global Admin account within the tenant, you will be requested to accept the permissions required for this sync
- Review the permissions then click “Accept”
- A verification process will occur quickly to ensure that your account has the required access
- If successful, a “Verified Successfully!” notification will appear below the Azure Active Directory sync type
- Before Authorizing Directory Access, we recommend reviewing or configuring your Welcome Message options.
- After you’ve set up your Message configurations, click the “Verify Setup” button – this will return the number of users within the Azure tenant and will confirm the sync groups used within the tenant
- When you are ready, click the “Sync Azure Now” button. You will receive a confirmation at the bottom of the page that the sync has been run successfully!
You’re all set!
- Depending on the user count within the tenant, the users should begin appearing within the User tab within the portal in less than 5 minutes!
- If your sync is in progress, you can’t queue up multiple syncs. Please wait 15 minutes then retry if no users appear
Breach Secure Now Confidential - For use with resellers and customers only and should not be redistributed or disseminated.
Comments
0 comments
Article is closed for comments.