Navigation

20.10. Sync Microsoft Entra Tenants and Contacts for MSP Clients

Connect Microsoft Entra to discover managed client tenants, map them to AlgaPSA clients, and sync Entra users into client contacts.

20.10. Sync Microsoft Entra Tenants and Contacts for MSP Clients
Connect Microsoft Entra to discover managed client tenants, map them to AlgaPSA clients, and sync Entra users into client contacts.
20. IntegrationsUpdated: 8/6/2026

Availability: Microsoft Entra sync is currently enabled per organization on request. Contact us and we will turn it on for your AlgaPSA tenant.

Microsoft Entra sync helps MSPs keep client contacts current without manually recreating every user from Microsoft 365. After you connect your partner identity source, AlgaPSA can discover managed Entra tenants, match them to client records, and create or update contacts for those clients.

Throughout this guide, the client names are fictional MSP examples. Use this workflow when your MSP manages clients like GreenLeaf Dental Group, Northstar Accounting, or Pioneer Law Group through Microsoft partner access and wants cleaner contact records for tickets, billing contacts, approvals, and client communication.

Figure 1: The Entra integration opens as a guided setup wizard: Connect, Find tenants, Match to clients, then Preview & pilot.

The Connect step states the permissions requested and the effect on your contacts before you authorize anything — Alga reads tenants and user names, emails, phone numbers, and job titles, and never writes back to Microsoft, reads mail, files, calendars, or Teams messages. Copy for a change record puts that summary on the clipboard for your change-management process.

Two connection methods are offered. Most MSPs should choose Direct Microsoft partner, where Alga talks to Microsoft Graph through your partner relationship. Choose CIPP (CyberDrain Improved Partner Portal) only if you already run a CIPP instance.


What Entra sync does

AreaWhat AlgaPSA doesMSP benefit
Tenant discoveryFinds managed Microsoft Entra tenants visible to your partner connection.Reduces manual setup when onboarding multiple Microsoft 365 clients.
Client mappingSuggests matches between Entra tenants and AlgaPSA clients by domain or name.Helps avoid syncing GreenLeaf users into the wrong client record.
Contact syncCreates contacts or links existing contacts by email address.Keeps service desk and billing contact records aligned with Microsoft 365 users.
Field updates and portal provisioningOptionally updates name, phone, job title, and related identity fields from Entra. Where enabled, mappings can also control Entra-managed client-portal user provisioning, auto-link SSO behavior, and default portal role assignment.Lets your MSP choose which system is authoritative for contact details while keeping portal access aligned with Microsoft identity.
ReconciliationQueues ambiguous matches for human review.Prevents unsafe merges when more than one contact could match the same Entra user.

Entra sync is designed to be non-destructive. It creates, links, updates, or marks contacts inactive when an Entra account is disabled; it does not delete contacts.


Prerequisites

Before you start, confirm the following:

  1. AlgaPSA access: You are an AlgaPSA administrator with permission to update system settings.
  2. Edition, add-on, and feature access: Microsoft Entra sync requires the appropriate Enterprise/Premium identity access and the Entra integration UI enabled for the tenant. Navigate to Settings > General in the sidebar to open Admin Settings, then select Integrations under Data & Integration. If the Identity category is not visible, the Entra UI is not enabled for that tenant; contact your AlgaPSA administrator, account owner, or operator before continuing.
  3. Microsoft access: Your Microsoft partner tenant has access to the client tenants you want to sync.
  4. Microsoft partner connection: Use Microsoft delegated partner access for managed tenants.
  5. Client records: Create or review AlgaPSA clients before mapping. Add clear websites, billing email domains, or client names so matching works well.

Recommended setup scenario

For this guide, assume your MSP, Northwind MSP, supports these clients:

Entra tenantAlgaPSA clientExample sync outcome
GreenLeaf Dental GroupGreenLeaf Dental GroupCreates and links dental office contacts for support tickets and billing questions.
Northstar AccountingNorthstar AccountingKeeps Microsoft 365 user names and phone numbers current for tax-season support.
Pioneer Legal ServicesPioneer Law GroupRequires review because the Entra tenant name differs from the AlgaPSA client name.
Harbor ClinicNo matching client yetCan be imported as a new client or skipped until onboarding is ready.

Step 1: Open the Entra integration

  1. Navigate to Settings > General in the sidebar to open Admin Settings.
  2. Select Integrations (under Data & Integration).
  3. If the tenant has Entra access enabled, open the Identity category. If Identity is not visible, stop here and have the tenant owner or operator enable the Entra integration UI before continuing.
  4. Review the Microsoft Entra Integration card.

The setup mode shows four guided steps: Connect, Find tenants, Match to clients, and Preview & pilot. Complete them in order. Nothing is written to your contacts until you have seen a preview and approved it.


Step 2: Connect Microsoft Entra

In the Connection Options area, choose the direct Microsoft partner connection.

  1. Click the direct Microsoft connection option.
  2. Sign in with the appropriate Microsoft partner administrator account.
  3. Review and approve the requested Microsoft permissions.
  4. Return to AlgaPSA and confirm the connection health shows connected.

Operational check: Use a named integration owner, such as your service operations manager or identity lead, so token rotations and permission reviews have a clear owner.


Step 3: Discover managed tenants

After the connection is active, click Run Discovery.

AlgaPSA loads the managed Entra tenants visible to your connection and records the last discovery time. Discovery does not create contacts yet. It only prepares the tenant list for mapping.

Use Run Discovery Again later when you add a new Microsoft 365 client, complete GDAP setup, or change partner tenant access.


Step 4: Map Entra tenants to AlgaPSA clients

Open Review Mappings to confirm how discovered Entra tenants should connect to AlgaPSA client records.

Figure 2: Review auto-matched tenants, choose a client for unmatched tenants, import a new client, or skip tenants that are not ready for sync.

Mapping statuses you may see:

StatusMeaningRecommended action
Auto-matchedAlgaPSA found a strong match, usually by domain.Review it, then confirm if correct.
Needs reviewAlgaPSA found a possible match but is not confident enough to choose automatically.Select the correct client manually.
UnmatchedNo likely client was found.Select a client, import as a new client, or skip.
SkippedYou chose not to map this tenant right now.Remap later when the client is ready.

For example, greenleafdental.example may match GreenLeaf Dental Group automatically. A tenant named Pioneer Legal Services may need manual review if the AlgaPSA client is named Pioneer Law Group.

After reviewing rows, click Confirm Selected Mappings.

Operational check: Do not confirm mappings solely by display name. Check the primary domain, client billing domain, and client website before syncing contacts.


Step 5: Choose field sync controls

Field sync controls decide which Entra values can overwrite fields on already-linked AlgaPSA contacts.

Common MSP choices:

FieldTypical settingWhy
Display NameOnUseful when Microsoft 365 is the source of truth for staff names.
EmailUsually OffPrevents accidental contact routing changes if aliases or UPNs differ.
PhoneOnKeeps help desk callback details current.
RoleOnKeeps job titles such as Office Manager or Controller current.
UPNUsually OffEnable only if your team uses UPN for identity troubleshooting.

Click Save Field Sync Controls after changing the switches.


Step 6: Preview, pilot, then run the initial sync

After at least one tenant is mapped, do not sync everything at once. The Preview & pilot step exists to make the first sync boring.

  1. Preview a sync. AlgaPSA reports exactly what a run would do — contacts it would create, link, update, inactivate, and queue as ambiguous — without writing anything. Read it before you approve it.
  2. Pilot a single client. Run the sync against one mapped tenant only. Pick a client you know well, ideally a small one, and check the resulting contacts by hand.
  3. Run the rest. Once the pilot looks right, run the remaining tenants.

This sequence catches the two mistakes that are expensive to undo at scale: a tenant mapped to the wrong client, and field sync controls that overwrite contact details you meant to keep.

When you are ready, click Run Initial Sync.

During the sync, AlgaPSA processes each mapped tenant and handles users as follows:

  1. Ignored: Disabled accounts, users without valid email identities, and common service account patterns are skipped.
  2. Created: New people are created as contacts under the mapped AlgaPSA client.
  3. Linked: Existing contacts are linked when there is one clear email match.
  4. Updated: Enabled field sync controls may update linked contact fields.
  5. Queued: Ambiguous matches are sent to the reconciliation queue for review.
  6. Inactivated: Contacts linked to disabled Entra accounts may be marked inactive rather than deleted.

Step 7: The operations console

Once the first sync completes, the setup wizard is replaced permanently by an operations console. The wizard does not come back — the connection is now something you run rather than something you set up.

The console has five tabs:

TabWhat it is for
OverviewCurrent state at a glance: what is mapped, what synced last, what needs attention
Sync & scheduleRun discovery or a full sync now, preview a run, and set the sync schedule
ClientsEvery mapped tenant with its client, and per-client sync results
HistoryRecent sync runs with per-tenant outcomes
ConnectionCredential status, credential rotation, and the exportable connection record

Preview is still available after setup. Use it before any sync that follows a change to mappings or field controls — it is the same non-destructive dry run offered during onboarding.

Rotate a credential in place

The Connection tab rotates the Microsoft credential without dismantling the integration. Tenant mappings, client links, and sync history all survive the rotation, so a scheduled secret rotation is no longer a reason to rebuild the connection.

Export the connection record

Connection also exports the connection record — the permissions granted, when they were authorized, who authorized them, and the current credential state. This is the artifact to attach to a change ticket or hand to an auditor asking what access your PSA holds over client directories.

Monitor sync runs and resolve ambiguous matches

Use the History and Overview tabs to review recent sync runs and clear the ambiguous match queue.

Figure 3: After sync, review run results and resolve ambiguous contact matches before they affect service desk records.

Review sync history

The Recent Sync Runs panel shows:

  • Run type, such as initial or all-tenants.
  • Completion status.
  • Start and completion time.
  • Number of tenants processed.
  • Success and failure counts.

Click View details when you need per-client results, such as how many contacts were created, linked, updated, inactivated, or queued as ambiguous.

Resolve ambiguous matches

Ambiguous matches happen when AlgaPSA finds more than one possible contact for the same Entra user. For example, Jordan Lee at GreenLeaf Dental Group might match both an office manager contact and a billing contact.

For each queue item:

  1. Review the Entra user name and email.
  2. Review the candidate contacts.
  3. Choose an existing contact when one is correct, then click Resolve to Existing.
  4. Click Resolve to New if the Entra user should become a separate contact.

Operational check: Assign someone on the service desk or client success team to review ambiguous matches after each initial client onboarding sync.


Ongoing operations checklist

Use this checklist after the initial sync is complete:

  • Run discovery after adding a new Microsoft 365 client or changing Microsoft partner access.
  • Preview a sync after changing mappings or field sync controls, before running it.
  • Review unmapped and skipped tenants monthly.
  • Check recent sync runs for failed tenants on the History tab.
  • Clear the ambiguous match queue before major client communication campaigns.
  • Review field sync controls before turning on email or UPN updates.
  • Confirm inactive contacts before removing them from client-facing workflows.
  • Rotate the Microsoft credential on your normal schedule from the Connection tab, and export the connection record when your change process needs evidence.

Related identity features

Entra sync creates and maintains client contacts. Two related capabilities cover people signing in:

  • Client portal SSO lets client contacts sign in with their own Microsoft accounts, with an Entra access group deciding who gets portal access. Tenant mappings here can also drive portal provisioning mode and default portal role.
  • SCIM user provisioning lets Entra deactivate and reactivate your own internal AlgaPSA users.

Troubleshooting

ProblemWhat to check
The Identity category is missingConfirm Enterprise/Premium access and that the Entra integration is enabled for your tenant.
Discovery finds no tenantsConfirm Microsoft partner access and GDAP relationships.
A tenant matched the wrong clientDo not confirm it. Select the correct client manually or improve the client website/billing domain first.
A tenant is unmatchedSelect a client manually, import it as a new client, or skip it until onboarding is ready.
Contacts are not updatingCheck field sync controls; only enabled fields can overwrite linked contacts.
Service accounts appear in syncAdd exclusion patterns for naming conventions such as svc-, automation, or noreply.
A user matched multiple contactsResolve the item in the ambiguous match queue instead of creating duplicates.

Best practices for MSPs

  • Keep client domains accurate in AlgaPSA before running discovery.
  • Map tenants in batches and review each domain before confirming.
  • Leave email overwrite disabled unless your operations team has agreed that Entra should control contact email addresses.
  • Use the reconciliation queue as part of onboarding closeout for new managed clients.
  • Treat disabled Entra accounts as an offboarding signal, but review important billing or executive contacts before removing them from workflows.