Views:

Limit Microsoft Entra ID data synchronization to members of specific groups to control which users are synced to TrendAI Vision One™. This is useful when your organization shares a tenant with other entities and you do not want to sync users outside your organization. For more information about groups in Microsoft Entra ID, see Manage groups.

Before you begin

At least one of the following Microsoft Entra ID permission sets must have a status of Granted. For more information, see Configure Microsoft Entra ID integration.
  • Read directory data
  • Read user and device information, cloud app data, and activity data
  • Read directory data and perform account management actions
  • Read security posture, compliance, and directory data from connected SaaS applications

Procedure

  1. Go to Workflow and AutomationThird-Party Integrations.
  2. Click the Microsoft Entra ID card.
  3. Locate the tenant you want to configure and click Data sync scope (group lists).
    The link text indicates the current synchronization scope for that tenant:
    Link text
    Meaning
    Data sync scope (group lists):
    No groups have been selected for synchronization.
    Data sync scope (group lists): All
    All groups in the tenant are included in data synchronization.
    Data sync scope (group lists): N
    N groups have been selected for synchronization.
    Data sync scope (group lists): progress icon
    Data synchronization is in progress.
    The Configure group list dialog appears.
  4. Under Data sync scope, select one of the following options:
    • All groups: Automatically synchronizes all groups in the tenant.
    • Selected groups (default): Synchronizes only the groups you specify. Continue to the next step to select groups.
  5. If you selected Selected groups, search for the groups you want to synchronize in the Available groups panel.
    You can search by group name or object ID. Searches by group name return a maximum of 100 results.
  6. Select the groups you want to synchronize and move them to the Selected groups panel.
  7. Click Save.
    TrendAI Vision One™ synchronizes the members of the selected groups. Results are reflected in Identity Inventory (Identity SecurityIdentity Inventory). This process may take up to several hours to complete.
    Important
    Important
    Any data synchronized between the previous and current save is dropped when you update Group List settings mid-synchronization.