Clockwise Timesheets

Microsoft Entra ID Directory Sync

Keep your Clockwise roster matched to your Entra ID (Azure AD) directory. Included on

every plan — you don't need SCIM for this.

What Syncs

  • Names, email addresses, job titles, departments, and reporting lines.
  • Disabled in Entra → deactivated in Clockwise.
  • Optionally, users removed from Entra can be deactivated too.
  • Clockwise never deletes anyone and never writes to Entra. It doesn't set a person's

    Clockwise role or employment type, and it ignores 1099 contractors and subcontractors.

    Setup

  • In the Azure portal → App registrations, create an app registration and a
  • client secret. Copy the secret's *Value* — Azure shows it only once.

  • Under API permissions, add the Microsoft Graph application permission
  • User.Read.All, then click Grant admin consent. A delegated permission of the

    same name will not work.

  • In Clockwise, go to Settings > Integrations and choose Microsoft Entra ID.
  • Enter the Directory (tenant) ID, Application (client) ID, and the client
  • secret, then click Test connection.

  • Review the sample, then Import users.
  • Credentials are stored encrypted. Entra client secrets expire — Clockwise warns you

    on this page a month ahead, because an expired secret makes every sync fail.

    Guests, Rooms, and Service Accounts

    An Entra directory usually holds more than employees:

  • Guests are skipped by default. B2B guests from partner organisations aren't
  • staff, and their email addresses belong to another company.

  • Conference rooms, shared mailboxes, and service accounts look like ordinary
  • users to Entra — nothing marks them out. Put their addresses in **What gets synced

    → Never sync these addresses**. Excluded addresses are left completely alone: not

    created, not updated, not deactivated.

  • Limit to a group is the alternative if you'd rather say who *is* staff. Give a
  • group's display name or object ID.

    If something was imported before you excluded it, deactivate it once under

    Settings > Users — the exclusion stops the sync turning it back on.

    Keeping It Current

  • Nightly sync — pick a time on the integration page.
  • Sync now — pulls immediately, for when you've just changed someone in Entra.
  • Checking One Person

    The review step has a lookup box: search an address or name to see exactly what Entra

    returns for that person, rather than relying on the short sample list.