How to connect Cyber Aware to Microsoft 365 for auto-provisioning

Connecting Cyber Aware to Microsoft 365 takes about ten minutes of admin time and removes the manual enrolment loop entirely: once directory sync is on, every learner in your tenant is enrolled into the default training schedule automatically, new starters are picked up the day they appear in Microsoft Entra ID, and leavers drop out of reporting without anyone raising a ticket. This guide walks through the connection, what syncs and what does not, and the settings that decide whether provisioning stays hands-off or quietly becomes a spreadsheet job again.

What the Microsoft 365 integration actually does

Microsoft 365 is one of Cyber Aware's two native directory integrations (Google Workspace is the other), and the connection covers three things rather than one:

Everything else in the stack — PSA tools, CRMs, Slack and Teams notifications — connects through Zapier or the full API rather than the directory connection, so the Microsoft 365 link stays focused on identity and enrolment.

What you need before you start

Step by step: connecting the directory

  1. Open the integrations settings in your Cyber Aware workspace and choose Microsoft 365 as the directory source.
  2. Grant admin consent for the directory read permissions when the Microsoft consent screen appears. The platform reads user accounts and group membership — it does not need mailbox access to run training.
  3. Choose the sync scope. Sync the whole tenant, or pick specific security groups for group-based assignment. Scoped sync is the right default when contractors, shop-floor accounts or shared mailboxes should not receive training.
  4. Map the attributes. First name, last name and work email flow from Entra ID into the learner record; these are the fields that appear in emails and reports, so check them on a few test learners.
  5. Run the initial sync. The learner list populates, and every synced learner is enrolled into the default schedule immediately — welcome email queued, first courses available.
  6. Turn on phishing-fail auto enrolment. When a learner fails a simulated phishing campaign, they are automatically enrolled into the remedial course that matches the lure. No follow-up email, no chase.
  7. Enable SSO. With SAML SSO enabled, learners sign in from every email with their Microsoft account, and the separate-learner-password problem disappears entirely.
  8. Widen the scope once the pilot group's enrolment, emails and branding check out.

What syncs, and how fast new hires land

The sync is what makes provisioning genuinely automatic. The workflow for a new hire looks like this: HR creates the account in Microsoft 365 as part of normal onboarding, the directory sync picks the joiner up, Auto Enrol assigns the baseline schedule the moment they appear, and the welcome email goes out the same day — with two courses available on signup so training starts before the first monthly cycle. Nobody raises a ticket, nobody maintains a spreadsheet, and the new hire shows up in human risk reporting without a manual step.

For a 50-person business hiring ten people a year, that is 15-30 minutes of admin saved per hire, plus the consistency win: every starter gets the identical baseline whether they join in January or November.

Leavers matter just as much. When an account is disabled or removed in Microsoft 365, the learner drops out of the sync on the next pass — reporting stays accurate, and per-seat billing does not keep paying for ex-employees. Stale leaver data is one of the quietest ways a human risk score stops telling the truth.

Phishing-fail auto enrolment: the loop that matters most

Directory sync handles joiners and leavers, but the highest-value automation in the Microsoft 365 connection is the failure loop. A learner who clicks a simulated phish is enrolled into the relevant remedial course automatically — no manager email, no awkward chase, no gap of weeks between the mistake and the lesson. Paired with Auto Phish running continuous campaigns on a cadence, the programme becomes a closed loop: simulate, catch the click, teach the lesson, measure the change. Programs that only run quarterly campaigns with manual remediation consistently leave that gap open.

Role-based personalisation

The first time a learner opens their training portal, they pick their role in the company, and the curriculum personalises to it. Finance staff see business email compromise content weighted differently from warehouse staff, and the assignment still ran itself — the personalisation rides on top of the automated enrolment rather than replacing it.

Troubleshooting: the three common snags

FAQ

Does Microsoft 365 sync cost extra? No — directory sync for Microsoft 365 and Google Workspace is part of the platform and powers Auto Enrol. Other tools connect via Zapier or the API.

Can I sync only some staff? Yes. Scope the sync to specific security groups for group-based assignment, which is the right approach for contractors or shared accounts you want excluded.

How quickly are new hires enrolled? They are picked up automatically by the directory sync the day they appear in Microsoft 365, and enrolment, the welcome email and their first courses are all assigned on arrival.

What about Google Workspace? It is the other native integration with the same behaviour — SSO, directory sync and Direct Message Injection. One directory is enough; you do not need both.

Does this replace Microsoft's own Attack Simulation Training? It can, and most organisations should choose one source of truth for simulations. Running two phishing programmes doubles the noise in user inboxes and splits the click data you report on.

What happens to a leaver's training history? They stop syncing as soon as their directory account is removed, which keeps active reporting and per-seat billing accurate. Historical records remain available per the platform's retention settings.

Is provisioning SCIM-based? Cyber Aware's identity category covers SCIM provisioning, SAML SSO and group-based assignment across Microsoft 365, Entra ID, Google Workspace, Okta and JumpCloud — for Microsoft 365 tenants the native connection handles it without custom SCIM setup.

One last thing

The most common provisioning mistake is syncing everyone and letting the defaults assign everything — including the contractors who should never receive client-branded emails. Scope first, sync second: it takes one extra minute and saves the retraction email.

Related guides

For the enrolment defaults themselves — schedules, cadence and branded emails — see Auto Enrol; for how Microsoft's own provisioning engine works underneath, Microsoft documents it at learn.microsoft.com.

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.