Hook SecurityHook Docs

Manage your directory connection

Run a manual sync, change which groups you sync, check what landed, and disconnect or reconnect Microsoft Entra.

Once Microsoft Entra is connected, the Synced directories table on the Integrations page is where you look after it. Expand a row to work on that connection. You'll come back here whenever your org structure changes or a sync needs a nudge.

You need to be an org admin with the right organization selected in the sidebar switcher. If you haven't connected a directory yet, start with Sync users from Microsoft Entra.

Open the connection workspace

Go to Settings, then Integrations, and click your Microsoft Entra row to expand its workspace.

The header summarizes the connection: when it was connected, how many Synced groups are in scope, how many Synced users those groups bring in, and how many Authorized domains are approved for sending.

Expanded Microsoft Entra workspace with synced groups, the selected group's members, and the authorized domains list

Below the header sits the sync block, and under that a three-column pane: your synced groups on the left, the members of whichever group you click in the middle, and authorized domains on the right. A search box filters the member list once you've selected a group.

The domains column lists the email domains your synced users receive mail on, each marked Authorized, Pending review, Unauthorized, or Awaiting sync, with an Authorize domain button on the rows that need one. For the full workflow, see Authorize recipient domains.

Hook supports one active directory connection per organization, so you can't run two providers side by side. Google Workspace appears as a provider tile but is marked coming soon and can't be connected yet.

Run a manual sync

Hook re-reads membership from Entra every night at 2:00 AM UTC. When you don't want to wait, click Sync now in the sync block.

Directory sync block showing the last sync time and the Sync now button

The button only works with at least one group in scope, and only one sync runs per directory at a time, so while a run is in flight the workspace shows a syncing state and a second attempt is turned away. When the run ends you get either a fresh "last synced" timestamp or a failure state, and the workspace metrics and domain list refresh on their own.

Change which groups you sync

Click Manage groups in the Synced groups footer to reopen the picker with your current selections already checked. Adjust the selection and continue, and instead of the first-run preview you'll get a confirmation screen showing exactly what your edit changes.

Review the diff

The screen splits your edit into Adding and Removing. Each group expands: added groups list the members coming in, and removed groups show how many users currently reach Hook through them and which of those will be deactivated.

Confirm scope changes screen with Adding and Removing sections and a removed user tagged for deactivation

Check who loses access

If removing a group would leave someone with no synced group at all, Hook warns you and names how many people that affects. Anyone who is also in a group you're adding doesn't count, because the sync reattaches them.

A single group can't bring in more than 50,000 members. If one does, the save is blocked and Hook names the group so you can drop it from the selection.

Save the change

Click Save scope change. Hook queues the resync in the background and returns you to Integrations. If your selection matches what's already saved, it tells you there's nothing to apply instead.

Removing every group deactivates every synced user

An empty scope leaves nobody with a directory membership, so everyone who came from this connection is deactivated. Hook makes you tick an acknowledgement checkbox naming how many people that is before it will let you save. You can bring them back by re-selecting their groups.

Retry a failed scope sync

A scope change runs in the background after you save, and Sync now can't replay it, so a regular sync won't recover one that failed. When the most recent run is a failed scope change, the sync block offers a Retry scope sync button that re-queues the same change without making you redo the picker.

Directory sync block in the failed scope resync state with Sync now and Retry scope sync buttons

Actions on the directory row

The buttons on the right of each Synced directories row follow the connection's status badge:

  • Connected gives you Disconnect, with a confirmation dialog first.
  • Connecting gives you Cancel connection, for a consent handshake still in flight.
  • Error gives you both Retry and Disconnect. Retry sends you back through Microsoft's consent screen to repair the connection.
  • Disconnected gives you Reconnect.

Synced directories table showing connected, connecting, failed, and disconnected rows with their action buttons

Disconnect

Click Disconnect and confirm. Syncing stops, but your previously synced groups are preserved, so you don't lose your selection and you can reconnect later.

Reconnect

Click Reconnect on a disconnected row. If the original consent is still good, Hook reactivates the connection and starts a sync straight away. If it isn't, you'll go back through Microsoft's consent screen first. Either way the connection reuses your saved group selection, so you don't re-pick groups.

Cancel a connection that's stuck connecting

A connection sits in Connecting when you started a connect but never finished the Microsoft consent step. The consent link expires after 10 minutes, so an abandoned handshake has to be restarted anyway. Click Cancel connection to clear it, then connect again.

Common pitfalls

  • Sync now does nothing with zero groups in scope. Pick at least one group through Manage groups first.
  • A failed scope change won't fix itself from Sync now. Use Retry scope sync in the sync block instead.
  • Nested groups aren't expanded. Hook syncs direct members only, so if a group contains other groups, select those nested groups as well.

On this page