You will learn
- What the Microsoft Entra integration does
- What you need before you begin
- How to set up company-wide access
- How to grant consent in Microsoft
- How to troubleshoot incomplete consent
- How to switch from a Microsoft account connection
- Which fields sync by default
What the Microsoft Entra integration does
The integration syncs your users and distribution lists from Microsoft Entra (Azure Active Directory) into Workshop. You can then reach employees using the directory groups you already maintain.
With company-wide access, an Entra administrator approves Workshop once for your entire organization. Sync keeps running when people leave the company or change their password, because the connection doesn’t depend on any one person’s account.
Before you begin
- An Entra administrator must grant consent. They need one of these Entra ID roles: Global Administrator or Privileged Role Administrator.
- Give your Entra administrator a Workshop user account (recommended). They don’t need Workshop access to grant consent. Giving them access lets them complete setup themselves, so you avoid passing links back and forth.
- No service account is required. You also don’t need to request a password-policy exemption.
Tip: In many organizations, your IT contact is already an Entra administrator. Check with them first.
Set up company-wide access
- In Workshop, go to the Apps page and open Azure Active Directory Sync.
- Select the Manage tab, then click Manage Azure connection.
- In the Connect Azure Active Directory window, find Company-wide access and click Set up company-wide access.
- When asked Are you an Entra Admin?, select Yes.
Selecting Yes - We display the microsoft domain but present it in a text box in case the user needs to change that (in the case of a parent/sub brand possibly
- Confirm your Microsoft domain. Workshop fills this in for you, but you can edit it if needed. For example, your Microsoft organization may use a different domain than your Workshop account if you have a parent company or sub-brand.
- Click Grant consent. This opens the Microsoft consent screen.
Please note: If you selected No for step 4 'Are you an entra admin' you will see the same microsoft domain textbox.
If you selected No for step 4 'Are you an entra admin' you will see the same microsoft domain textbox, but the button now says "generate approval link"
clicking 'generate approval link' shows them the url that they can copy (below):
Grant consent in Microsoft
- Sign in with your Entra administrator account.
- Review the requested permissions for your organization, then click Accept.
- After you accept, you’re returned to a Consent granted page in Workshop. Click Return to Azure sync to finish setup.
Note: To see exactly which permissions Workshop requests, read Azure Active Directory technical syncing details.
Finalize setup in Workshop
- After consent is granted, return to Workshop.
- Activate at least one synced list to populate your directory. We recommend starting with an “All Employees” list.
For more on synced lists, see How to manage synced Microsoft Active Directory lists in Workshop.
Send the approval link to an Entra administrator
If you aren’t an Entra administrator, you can still start setup and have an administrator approve it.
- Follow steps 1–3 in Set up company-wide access.
- When asked Are you an Entra Admin?, select No.
- Send the approval link to your Entra administrator.
- Your administrator opens the link, signs in with their Entra account, and accepts the requested permissions.
Note: The approval link expires after 24 hours. If it expires before your administrator uses it, generate a new link from the same screen.
If consent isn’t completed
If something goes wrong, you’ll see a Consent was not completed page with a short explanation and a reference ID.
A common cause is granting consent for a different Microsoft organization than the one the link was created for. To fix it:
- Click Return to Azure sync.
- Check that the Microsoft domain matches the organization your administrator signs in to.
- Try granting consent again.
Tip: If the issue continues, contact Workshop Support and include the reference ID from the error page.
Switch from a Microsoft account connection
If you connected Azure Active Directory before company-wide access was available, the Manage Azure connection window shows your existing Microsoft account connection labeled Current connection.
This type of connection uses one person’s access. Sync stops if that person leaves the company, loses directory access, or changes their password, and someone will need to reconnect it.
- To switch (recommended): click Set up company-wide access and follow the steps above.
- To keep your current connection: click View or reconnect Microsoft account. From there, you can click Reconnect Microsoft account if sync has stopped.
Synced fields
Default fields
- First name
- Last name
Additional attributes
Workshop can sync any user profile attribute or extension attribute from Entra. To request more attributes, contact Workshop Support.
Need help? Contact Workshop Support through the help center request portal.