Users and groups syncing to Entra

JerryG
Here to help

Users and groups syncing to Entra

Curious if there is any documentation that really details how the Users and Groups Sync works with Entra ID for Access Manager. From the documentation, it seems that when you setup the Entra ID Integration, if you were to keep the "Enable Proactive Sync" toggle off, that it would not sync at all. I found that it still synced every group in the tenant. Then when I added a group to the Meraki/Microsoft Application it started adding users, but the users did not exactly line up with the users in the Microsoft group. I am going to open a ticket just in case it is some sort of bug, but I am just hoping there is some more documentation on the Sync side of things and when and how it all works.

 

 

14 Replies 14
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

AFAIK upon initial setup it does a sync and then if proactive sync is enabled it syncs every 6 hours.

 

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Organization_End_User...

JerryG
Here to help

You are probably right. The below documentation is what led me to believe that it might not sync at the start.

"If automatic syncs are not being used ("enable proactive sync" is disabled) then syncs from the IdP must be initated manually by an organization administrator. "

 

Also, it's weird that I have an Azure group that contains 4 users which I have added to the Meraki-IdP-Sync application I created, but now when I go into users, there are 20 something users that have been synced. It's just really unclear how the sync part is supposed to be working.

Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

Do they all show "source" as your IdP? The Users page will combine IdP synced users as well as Systems Manager and VPN users. If all from your IdP are they duplicates? 

JerryG
Here to help

All from IdP and no dupes. They are not using System Manager or VPN at this Org.

 

The number is counting up too. It seems like it adds 50 users every 6 hours (guessing on the time, as that is known the sync time interval) or something? Currently on with Meraki support and they don't seem to have an understanding of it yet, but they are still digging.

JerryG
Here to help

I know this is a somewhat new product and unfortunately tech support is not really up to speed on the ins and outs of Access Manager just yet. I am hoping my ticket gets escalated to someone more on the development side. Kind of surprised this has not come up before when testing the product. Would be nice if there was a way to actually control what gets synced with Entra and what does not.

alexpollard
Conversationalist

Having the same issue. Initially I didn't have any groups applied to the application and there were still 7 users synced. Assigned a group of users and now I have 32, still well short of then 1000 odd in that group...

JerryG
Here to help

I have a ticket open on this too and so far I am being told it is an Azure problem?!?!

alexpollard
Conversationalist

I ended up deleting the connection and recreating it and all appears fine now. Looks like it syncs EVERYTHING though..

JerryG
Here to help

Did you recognize anything different that you might have done?

alexpollard
Conversationalist

Nope, exactly the same, just worked this time. I'm guessing there might have been a delay with Entra getting all the permissions assigned etc as this can sometimes take a while to replicate around

JerryG
Here to help

I am not 100% certain, but I believe on my first install, I may have configured and turned on the Meraki side of the integration before fully completing everything on the Azure side. I deleted it and rebuilt it and this time I made sure all was complete on the Azure side prior to performing the Meraki side and everything came right up without issues. Curious if you might have done something similar?

linuxoid70
Comes here often

I am experiencing the same - only 1 group assigned to application in Entra ID, however entire directory is synced over to Meraki. Looks to me like groups and users assigned to the application in Entra ID is being ignored. Maybe it's because of API rights to read everything, and it ignores actual groups and users assigned to application?

JerryG
Here to help

Did you see my most recent reply before your post? I think "order of procedures" is critical. If you think there is any way that you kicked off the Meraki side before completing ALL permissions and configs on the Azure side, it might never "catch up". Try rebuilding from scratch with that in mind.

 

linuxoid70
Comes here often

Yes, and I did configure everything in Azure first, before doing anything in Meraki. Didn't make any difference.

Get notified when there are additional replies to this discussion.