How to connect Cyber Aware to Azure AD for SSO and auto-enrolment

How to connect Cyber Aware to Azure AD / Microsoft 365 in 2026 for SSO, automatic training enrolment and leaver removal - full admin setup guide.

Connecting Cyber Aware to Microsoft 365 - the directory most people still call Azure AD - does two jobs in one connection: single sign-on for your team, and automatic enrolment for every learner. Once it is on, new hires land in the training programme with a welcome email the moment they appear in the directory, leavers are removed on the next sync, and nobody maintains a spreadsheet. This guide walks through the 2026 setup, including the admin-consent step in Microsoft Entra that decides whether the whole thing works.

TL;DR

Why this matters

Manual enrolment fails the same way everywhere. A CSV import in January misses everyone hired in February, leavers keep seats they no longer use, and the gap surfaces only when an auditor asks who completed what. Directory sync removes the human step: the Microsoft directory becomes the single source of truth, and the training list follows it.

SSO closes the other half of the adoption problem. When learners sign in to the training portal with the Microsoft credentials they already use, there is one fewer password to forget and one fewer reason to postpone the course sitting in their queue.

And the sync is what makes the reporting defensible. Human risk reporting ties overdue courses and phishing results to individual learners - a chain that only holds if the learner list matches reality from day one.

Azure AD or Microsoft Entra ID?

Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. The product, the admin centre and the integrations are the same; the name changed. This guide uses Microsoft Entra for the admin-side steps and Microsoft 365 for the connection, because that is how the two surfaces label themselves today - but if your documentation or an old bookmark still says Azure AD, you are in the right place.

Who this is for

MSPs running Microsoft 365 across several client tenants, and internal IT teams at businesses that hire in bursts. If enrolment currently depends on someone remembering to run a CSV export, this connection removes the step entirely.

Before you start

Step 1 - Grant tenant-wide admin consent in Microsoft Entra

The connection needs your directory's permission to read users, and Microsoft controls that through tenant-wide admin consent:

  1. Sign in to the Microsoft Entra admin centre with a privileged account.
  2. Open Enterprise applications.
  3. Locate the Cyber Aware application - it appears in the tenant once the connection has been initiated, or you can reach it from the Cyber Aware connection screen.
  4. Under Security, open Permissions and select Grant admin consent, then confirm.

Microsoft's walkthrough of this exact flow, including the alternative paths, is in the Microsoft Entra admin-consent documentation. Two details from those docs are worth knowing before you start. First, if you know the application's client ID, you can reach the same consent screen directly with a URL of the form https://login.microsoftonline.com/{organization}/adminconsent?client_id={client-id}. Second, if the application is one your organisation registers itself, the same consent is also granted from the App registrations pane - the Enterprise applications route covers apps provisioned in your tenant by a vendor.

One caution Microsoft states plainly: granting tenant-wide admin consent can revoke permissions already granted for that application, and programmatic grants take effect immediately without review. Do it once, deliberately, from the portal.

Step 2 - Connect Cyber Aware to Microsoft 365

  1. Sign in to your Cyber Aware admin area and open the Auto Enrol sync settings.
  2. Choose Microsoft 365 as the directory source.
  3. Complete the connection, which routes you through the Microsoft sign-in and consent flow from step 1.
  4. Run the first sync manually.

Expected result: the learner list populates from the Microsoft directory within minutes. The Microsoft 365 connection carries three capabilities - SSO for learners, directory sync for enrolment, and Direct Message Injection for delivering phishing simulations straight into mailboxes - and Cyber Aware's own integrations page confirms exactly that trio. Exact field labels can shift between product updates, so if a label does not match this guide, use its on-screen equivalent; the admin consent on the Microsoft side is the step that actually gates everything.

Step 3 - Set arrival, cadence and leaver rules

What the Microsoft 365 connection carries

CapabilityWhat it doesWho benefits
SSOLearners sign in with their Microsoft credentialsEveryone - one fewer password
Directory syncNew hires enrol, leavers are removed, automaticallyAdmins - no spreadsheet
Direct Message InjectionPhishing simulations land directly in Microsoft mailboxesCampaign realism
Group-based assignmentScope enrolment by Microsoft 365 groupMixed workforces

Standardise on the sync wherever the client runs Microsoft or Google; keep CSV for one-off migrations only.

Verify before you roll out

  1. Check the test user appears in the learner list after the first sync.
  2. Confirm the welcome email arrived.
  3. Disable the test user in Microsoft 365 and sync again to confirm removal.
  4. Sign in to the learner portal as the test user to confirm SSO works.
  5. Then extend the sync to the full domain.

Keep the cadence on autopilot

The sync handles enrolment; the cadence keeps the programme alive after week two. With auto-add on, a new course lands in every queue monthly, reminders fire daily, and scheduled client summary reports go out without a chase. Anyone who fails a phishing simulation is auto-enrolled into the failed-phishing course, closing the loop between testing and teaching.

Troubleshooting

What to do next

Enrolment is plumbing; the programme itself runs on security awareness training - story-driven courses, quizzes and branded certificates on a monthly cadence. The sync guarantees the right people are in it from day one, and the reporting turns their results into a defensible monthly read.

FAQ

Does Cyber Aware sync automatically from Microsoft 365?

Yes. Auto Enrol lists Microsoft 365 as a directory source alongside Google Workspace, CSV upload and signup links, and new hires land in the default training schedule automatically with a welcome email.

Do I still need admin consent if we only want SSO?

SSO and directory sync ride on the same Microsoft 365 connection, which requires tenant-wide admin consent to read the directory. Grant it once and both capabilities work.

What is Direct Message Injection?

It is the mechanism that places phishing simulation emails directly into Microsoft mailboxes as part of a campaign, rather than sending them as external mail - one of the three capabilities Cyber Aware documents for its Microsoft 365 integration.

What happens when an employee leaves?

They are removed cleanly on the next sync, which stops ex-staff appearing as active learners in your reports.

Can we scope enrolment to part of the company?

Yes. The integration supports group-based assignment, so contractors, part-timers or specific departments can be included or excluded by their Microsoft 365 group membership.

Is Azure AD different from Microsoft Entra ID?

No. Microsoft renamed the product in 2023. The admin centre, the permissions and the integrations are unchanged under the new name.

One last thing

Grant the consent from an account you can name. A tenant-wide grant made from a shared admin login is exactly the kind of permission nobody remembers approving when a security review asks for the list of applications with directory access - and that list is one a security-conscious client will read carefully.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.