Connecting Cyber Aware to Microsoft 365 - the directory most people still call Azure AD - does two jobs in one connection: single sign-on for your team, and automatic enrolment for every learner. Once it is on, new hires land in the training programme with a welcome email the moment they appear in the directory, leavers are removed on the next sync, and nobody maintains a spreadsheet. This guide walks through the 2026 setup, including the admin-consent step in Microsoft Entra that decides whether the whole thing works.
TL;DR
- Microsoft renamed Azure AD to Microsoft Entra ID in 2023; the connection works the same under either name.
- Cyber Aware connects to Microsoft 365 with SSO, directory sync and Direct Message Injection.
- Auto Enrol places new learners in the default training schedule automatically - welcome email included - and removes leavers cleanly.
- The Microsoft side requires tenant-wide admin consent, granted in the Microsoft Entra admin centre.
- Review the requested permissions before consenting, and verify with one test user before rolling out domain-wide.
Why this matters
Manual enrolment fails the same way everywhere. A CSV import in January misses everyone hired in February, leavers keep seats they no longer use, and the gap surfaces only when an auditor asks who completed what. Directory sync removes the human step: the Microsoft directory becomes the single source of truth, and the training list follows it.
SSO closes the other half of the adoption problem. When learners sign in to the training portal with the Microsoft credentials they already use, there is one fewer password to forget and one fewer reason to postpone the course sitting in their queue.
And the sync is what makes the reporting defensible. Human risk reporting ties overdue courses and phishing results to individual learners - a chain that only holds if the learner list matches reality from day one.
Azure AD or Microsoft Entra ID?
Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. The product, the admin centre and the integrations are the same; the name changed. This guide uses Microsoft Entra for the admin-side steps and Microsoft 365 for the connection, because that is how the two surfaces label themselves today - but if your documentation or an old bookmark still says Azure AD, you are in the right place.
Who this is for
MSPs running Microsoft 365 across several client tenants, and internal IT teams at businesses that hire in bursts. If enrolment currently depends on someone remembering to run a CSV export, this connection removes the step entirely.
Before you start
- A privileged Microsoft Entra role. Granting tenant-wide admin consent requires signing in with an authorised role - Microsoft's documentation lists Cloud Application Administrator and Privileged Role Administrator among the roles that can consent on behalf of the organisation. A plain user account cannot complete this step.
- A Cyber Aware partner account with Auto Enrol available on the plan, and access to the Microsoft 365 connection settings.
- A test user in the Microsoft directory, so you can verify enrolment, the welcome email and removal end to end.
- The gotcha: tenant-wide admin consent is a sensitive operation - Microsoft's own guidance warns it can grant an application access to significant portions of your organisation's data. Review the permissions the connection requests before you click accept, not after.
Step 1 - Grant tenant-wide admin consent in Microsoft Entra
The connection needs your directory's permission to read users, and Microsoft controls that through tenant-wide admin consent:
- Sign in to the Microsoft Entra admin centre with a privileged account.
- Open Enterprise applications.
- Locate the Cyber Aware application - it appears in the tenant once the connection has been initiated, or you can reach it from the Cyber Aware connection screen.
- Under Security, open Permissions and select Grant admin consent, then confirm.
Microsoft's walkthrough of this exact flow, including the alternative paths, is in the Microsoft Entra admin-consent documentation. Two details from those docs are worth knowing before you start. First, if you know the application's client ID, you can reach the same consent screen directly with a URL of the form https://login.microsoftonline.com/{organization}/adminconsent?client_id={client-id}. Second, if the application is one your organisation registers itself, the same consent is also granted from the App registrations pane - the Enterprise applications route covers apps provisioned in your tenant by a vendor.
One caution Microsoft states plainly: granting tenant-wide admin consent can revoke permissions already granted for that application, and programmatic grants take effect immediately without review. Do it once, deliberately, from the portal.
Step 2 - Connect Cyber Aware to Microsoft 365
- Sign in to your Cyber Aware admin area and open the Auto Enrol sync settings.
- Choose Microsoft 365 as the directory source.
- Complete the connection, which routes you through the Microsoft sign-in and consent flow from step 1.
- Run the first sync manually.
Expected result: the learner list populates from the Microsoft directory within minutes. The Microsoft 365 connection carries three capabilities - SSO for learners, directory sync for enrolment, and Direct Message Injection for delivering phishing simulations straight into mailboxes - and Cyber Aware's own integrations page confirms exactly that trio. Exact field labels can shift between product updates, so if a label does not match this guide, use its on-screen equivalent; the admin consent on the Microsoft side is the step that actually gates everything.
Step 3 - Set arrival, cadence and leaver rules
- Arrival: new hires picked up by the M365 sync land in the default training schedule automatically, welcome email included.
- Departure: leavers are removed cleanly on the next sync, so ex-staff stop counting as active learners.
- Cadence: enable auto-add to place a new course in every learner's queue each month, with due and overdue reminders queued on schedule.
- Group-based assignment: use Microsoft 365 groups to scope which learners enter the programme - contractors, part-timers and executives do not always need the same schedule.
- Branding: portals, notification emails and certificates carry your brand rather than Cyber Aware's - confirm it before the first client logs in.
What the Microsoft 365 connection carries
| Capability | What it does | Who benefits |
|---|---|---|
| SSO | Learners sign in with their Microsoft credentials | Everyone - one fewer password |
| Directory sync | New hires enrol, leavers are removed, automatically | Admins - no spreadsheet |
| Direct Message Injection | Phishing simulations land directly in Microsoft mailboxes | Campaign realism |
| Group-based assignment | Scope enrolment by Microsoft 365 group | Mixed workforces |
Standardise on the sync wherever the client runs Microsoft or Google; keep CSV for one-off migrations only.
Verify before you roll out
- Check the test user appears in the learner list after the first sync.
- Confirm the welcome email arrived.
- Disable the test user in Microsoft 365 and sync again to confirm removal.
- Sign in to the learner portal as the test user to confirm SSO works.
- Then extend the sync to the full domain.
Keep the cadence on autopilot
The sync handles enrolment; the cadence keeps the programme alive after week two. With auto-add on, a new course lands in every queue monthly, reminders fire daily, and scheduled client summary reports go out without a chase. Anyone who fails a phishing simulation is auto-enrolled into the failed-phishing course, closing the loop between testing and teaching.
Troubleshooting
- Consent fails or the button is unavailable. The signed-in account lacks a consenting role. Microsoft requires a role authorised to consent on behalf of the organisation - Cloud Application Administrator or above.
- The connection errors right after setup. Re-check that consent was granted tenant-wide, not just for one user. Individual consent does not let a sync read the directory.
- Some users are missing. Check they sit inside the sync scope or the assigned Microsoft 365 groups, and that their accounts are enabled.
- Duplicate learners. A stale CSV import plus the live sync list the same person twice. Make the directory the single source of truth and remove imported duplicates.
- Learners cannot sign in with SSO. Confirm their account is licensed and enabled in Microsoft 365, and that the Enterprise application is not restricted to specific users or groups in your tenant.
What to do next
Enrolment is plumbing; the programme itself runs on security awareness training - story-driven courses, quizzes and branded certificates on a monthly cadence. The sync guarantees the right people are in it from day one, and the reporting turns their results into a defensible monthly read.
FAQ
Does Cyber Aware sync automatically from Microsoft 365?
Yes. Auto Enrol lists Microsoft 365 as a directory source alongside Google Workspace, CSV upload and signup links, and new hires land in the default training schedule automatically with a welcome email.
Do I still need admin consent if we only want SSO?
SSO and directory sync ride on the same Microsoft 365 connection, which requires tenant-wide admin consent to read the directory. Grant it once and both capabilities work.
What is Direct Message Injection?
It is the mechanism that places phishing simulation emails directly into Microsoft mailboxes as part of a campaign, rather than sending them as external mail - one of the three capabilities Cyber Aware documents for its Microsoft 365 integration.
What happens when an employee leaves?
They are removed cleanly on the next sync, which stops ex-staff appearing as active learners in your reports.
Can we scope enrolment to part of the company?
Yes. The integration supports group-based assignment, so contractors, part-timers or specific departments can be included or excluded by their Microsoft 365 group membership.
Is Azure AD different from Microsoft Entra ID?
No. Microsoft renamed the product in 2023. The admin centre, the permissions and the integrations are unchanged under the new name.
One last thing
Grant the consent from an account you can name. A tenant-wide grant made from a shared admin login is exactly the kind of permission nobody remembers approving when a security review asks for the list of applications with directory access - and that list is one a security-conscious client will read carefully.