Hook SecurityHook Docs

Sync users from Microsoft Entra

Connect Hook to Microsoft Entra (Azure AD), choose which groups to sync, preview the members, and confirm, so your user list stays current on its own.

Microsoft Entra (Azure AD) is the best way to keep your Hook user list current. Once it's connected, Hook pulls the groups you choose straight from Entra, so you stop chasing CSV exports every time someone joins or leaves.

It takes a few minutes. You'll need the org admin role in Hook, someone who can grant consent for your Entra tenant, and a rough idea of which groups match how you target campaigns and training.

Not using a directory?

If your organization doesn't use Microsoft Entra or Google Workspace, you can import users with a CSV instead and manage learners and groups directly in Hook.

Connect Hook to Entra

Start the connect

Go to Settings, then Integrations. Find the Microsoft Entra tile under Sync new directories, and click Connect. Hook hands you off to Microsoft.

Sign in with an account that can grant consent for your tenant. Hook asks for four read-only permissions: read your groups, read the members of those groups, read users, and read basic organization details. It never asks for write access.

The consent link is only good for 10 minutes, so if you get pulled away, start again rather than reusing the old tab. If Microsoft refuses, the usual cause is signing in with an account that can't consent for the whole tenant, so hand this step to your identity admin.

Confirm it landed

Back on Integrations, the Entra tile shows a Connected badge with your tenant name and a new row appears in Synced directories. Counts stay at zero until you pick groups.

Pick the groups to sync

Expand your directory row and click Manage groups in the Synced groups footer.

Find the groups you want

The picker loads up to 1,000 groups, with each group's member count and its type: Microsoft 365, Security, or Distribution. If your tenant has more than that, Hook says the list was truncated, so use the search box rather than scrolling.

Select them and continue

Tick each group you want, up to 200. Past 100, Hook warns that a selection this large takes longer to preview, which is a heads-up rather than a limit. Select-all only applies to the rows on screen, so with a search active it takes the matches you're looking at, not the whole tenant.

Groups containing other groups carry a badge, because Hook syncs direct members only. To get the people inside a nested group, select that group too. When the selection looks right, click Continue to preview.

Unsyncing a group deactivates people, it doesn't delete them

If you uncheck a group that's already saved, Hook asks you to confirm. Anyone left without a synced group is deactivated, not removed. Their campaign and training history stays intact, and re-selecting the group brings them back.

Preview and save

The preview lists each selected group with its full member list and a count of how many members it holds. Read down it for two things: guests and service accounts, since Entra often mixes in external collaborators and shared mailboxes that shouldn't receive simulations, and people you expected but can't see, usually a recently deactivated account or someone who changed groups. Neither has to be solved now. Fix it in Entra and the next sync catches up.

Hook gives itself about 10 seconds to load members. If it runs out of time on some groups, a banner says the preview is partial and that you can save anyway. Counts are still right, and anything that didn't load is picked up by the first real sync.

Click Save selection. Hook walks you through a short progress view, then confirms the initial sync has started. It runs in the background, so you can leave the page.

After the first sync

Your row in Synced directories now shows how many groups are in scope. Expand it for three columns: the synced groups, the members of whichever group you select, and the email domains those users receive mail on. Those domains need approving before anyone on them can be sent a simulation. See Authorize recipient domains.

Hook refreshes membership nightly from here on, so routine joiners and leavers need nothing from you. To change which groups are synced, reopen Manage groups; your current selection is pre-checked.

One thing to know: people are deactivated in Hook when they drop out of every synced group, which isn't the same as being blocked in Entra. A blocked account stays active here until it also leaves the group. If something looks wrong after a sync, see Troubleshoot directory sync.

On this page