Manage your directory connection
Run a manual sync, change which groups you sync, check what landed, and disconnect or reconnect Microsoft Entra.
Once Microsoft Entra is connected, the Synced directories table on the Integrations page is where you look after it. Expand a row to work on that connection. You'll come back here whenever your org structure changes or a sync needs a nudge.
You need to be an org admin with the right organization selected in the sidebar switcher. If you haven't connected a directory yet, start with Sync users from Microsoft Entra.
Open the connection workspace
Go to Settings, then Integrations, and click your Microsoft Entra row to expand its workspace.
The header summarizes the connection: when it was connected, how many Synced groups are in scope, how many Synced users those groups bring in, and how many Authorized domains are approved for sending.

Below the header sits the sync block, and under that a three-column pane: your synced groups on the left, the members of whichever group you click in the middle, and authorized domains on the right. A search box filters the member list once you've selected a group.
The domains column lists the email domains your synced users receive mail on, each marked Authorized, Pending review, Unauthorized, or Awaiting sync, with an Authorize domain button on the rows that need one. For the full workflow, see Authorize recipient domains.
Hook supports one active directory connection per organization, so you can't run two providers side by side. Google Workspace appears as a provider tile but is marked coming soon and can't be connected yet.
Run a manual sync
Hook re-reads membership from Entra every night at 2:00 AM UTC. When you don't want to wait, click Sync now in the sync block.

The button only works with at least one group in scope, and only one sync runs per directory at a time, so while a run is in flight the workspace shows a syncing state and a second attempt is turned away. When the run ends you get either a fresh "last synced" timestamp or a failure state, and the workspace metrics and domain list refresh on their own.
Change which groups you sync
Click Manage groups in the Synced groups footer to reopen the picker with your current selections already checked. Adjust the selection and continue, and instead of the first-run preview you'll get a confirmation screen showing exactly what your edit changes.
Review the diff
The screen splits your edit into Adding and Removing. Each group expands: added groups list the members coming in, and removed groups show how many users currently reach Hook through them and which of those will be deactivated.

Check who loses access
If removing a group would leave someone with no synced group at all, Hook warns you and names how many people that affects. Anyone who is also in a group you're adding doesn't count, because the sync reattaches them.
A single group can't bring in more than 50,000 members. If one does, the save is blocked and Hook names the group so you can drop it from the selection.
Save the change
Click Save scope change. Hook queues the resync in the background and returns you to Integrations. If your selection matches what's already saved, it tells you there's nothing to apply instead.
Removing every group deactivates every synced user
An empty scope leaves nobody with a directory membership, so everyone who came from this connection is deactivated. Hook makes you tick an acknowledgement checkbox naming how many people that is before it will let you save. You can bring them back by re-selecting their groups.
Retry a failed scope sync
A scope change runs in the background after you save, and Sync now can't replay it, so a regular sync won't recover one that failed. When the most recent run is a failed scope change, the sync block offers a Retry scope sync button that re-queues the same change without making you redo the picker.

Actions on the directory row
The buttons on the right of each Synced directories row follow the connection's status badge:
- Connected gives you Disconnect, with a confirmation dialog first.
- Connecting gives you Cancel connection, for a consent handshake still in flight.
- Error gives you both Retry and Disconnect. Retry sends you back through Microsoft's consent screen to repair the connection.
- Disconnected gives you Reconnect.

Disconnect
Click Disconnect and confirm. Syncing stops, but your previously synced groups are preserved, so you don't lose your selection and you can reconnect later.
Reconnect
Click Reconnect on a disconnected row. If the original consent is still good, Hook reactivates the connection and starts a sync straight away. If it isn't, you'll go back through Microsoft's consent screen first. Either way the connection reuses your saved group selection, so you don't re-pick groups.
Cancel a connection that's stuck connecting
A connection sits in Connecting when you started a connect but never finished the Microsoft consent step. The consent link expires after 10 minutes, so an abandoned handshake has to be restarted anyway. Click Cancel connection to clear it, then connect again.
Common pitfalls
- Sync now does nothing with zero groups in scope. Pick at least one group through Manage groups first.
- A failed scope change won't fix itself from Sync now. Use Retry scope sync in the sync block instead.
- Nested groups aren't expanded. Hook syncs direct members only, so if a group contains other groups, select those nested groups as well.
Related
Sync users from Microsoft Entra
Connect Hook to Entra, pick groups to sync, preview members, and confirm.
Authorize recipient domains
Approve the email domains your synced users share so simulations can reach them.
View users and groups
Browse the full roster of synced users and the groups that drive targeting.
Troubleshoot directory sync
Diagnose missing users, failed syncs, and stale group membership.
Sync users from Microsoft Entra
Connect Hook to Microsoft Entra (Azure AD), choose which groups to sync, preview the members, and confirm, so your user list stays current on its own.
Authorize recipient domains for phishing simulations
Approve the email domains your synced users receive mail on so Hook can deliver phishing simulations to them.