Microsoft Entra ID Directory Sync
Keep your Clockwise roster matched to your Entra ID (Azure AD) directory. Included on
every plan — you don't need SCIM for this.
What Syncs
Clockwise never deletes anyone and never writes to Entra. It doesn't set a person's
Clockwise role or employment type, and it ignores 1099 contractors and subcontractors.
Setup
client secret. Copy the secret's *Value* — Azure shows it only once.
User.Read.All, then click Grant admin consent. A delegated permission of the
same name will not work.
secret, then click Test connection.
Credentials are stored encrypted. Entra client secrets expire — Clockwise warns you
on this page a month ahead, because an expired secret makes every sync fail.
Guests, Rooms, and Service Accounts
An Entra directory usually holds more than employees:
staff, and their email addresses belong to another company.
users to Entra — nothing marks them out. Put their addresses in **What gets synced
→ Never sync these addresses**. Excluded addresses are left completely alone: not
created, not updated, not deactivated.
group's display name or object ID.
If something was imported before you excluded it, deactivate it once under
Settings > Users — the exclusion stops the sync turning it back on.
Keeping It Current
Checking One Person
The review step has a lookup box: search an address or name to see exactly what Entra
returns for that person, rather than relying on the short sample list.