Adding an Entra ID directory configuration
FortiDLP can integrate with one or more Entra ID directories.
You must have the following operator permissions to be able to configure an Entra ID integration in FortiDLP:
|
Prerequisites
You must first complete the credential setup steps in Microsoft credentials.
How to add an Entra ID directory
- In the FortiDLP Console, on the left-hand sidebar, click .
- Do one of the following:
- Under Users, select MicrosoftEntra ID.
- Under Integrations > Microsoft, select Entra ID.
- Click Add new directory.
- In the Add new directory modal, do the following:
- Under Authentication settings, in the Credentials menu, select the set of credentials you want to use.
- Under Details, enter a name to identify the directory sync configuration.
- Optionally, under User sync, do the following:
- To filter the users you want to sync, in the Filter field, type the search filter.
For example, entering:
country eq 'USA'
would filter by users who have USA set as their country of residence.createdDateTime ge 2022-05-09T16:59:09Z
would filter by users whose Entra ID accounts were created after the date and time provided.
- To enable daily auto-syncs, turn the Enable daily auto-sync toggle on. For more information, see Syncing Entra ID directories.
- To enable auto-archiving of users deleted from the directory, turn the Enable auto-archiving of directory-deleted users toggle on. For more information, see Auto-archiving Entra ID directory-deleted users.
- To remove directory labels from auto-archived directory-deleted users, turn the Remove directory labels from auto-archived users toggle on.
- To sync users' usernames to the Infrastructure and allow them to be mapped to events that contain a matching username, turn the Sync username mapping toggle on. For more information, see User-event mapping.
- To filter the users you want to sync, in the Filter field, type the search filter.
- Optionally, under Label import, do the following:
- To create and assign user property directory labels:
- In the User properties list, select one or more user properties. If you select the Hire date checkbox, you must also set the number of days an employee is a new hire in the Days field.
- To pseudonymize user property label values, select the corresponding Pseudonymize values checkboxes.
- To create and assign group membership directory labels:
- In the Group membership list, select one or more group memberships.
- To flag group membership labels, select the corresponding Flag label checkboxes.
- To pseudonymize group membership label values, select the corresponding Pseudonymize values checkboxes.
- To create and assign user property directory labels:
- Click Add new directory.