Connect your Microsoft directory and let Whalemate bring in your employees and groups, instead of uploading them by hand or by file.
Bring in your employees from the Microsoft directory that your organization already maintains, without uploading them again.
Convert the Microsoft groups you choose into Whalemate groups, to use them as audiences for simulations and training.
Keep the roster up to date without manual work: the sync runs on its own once a day.
Keep a record of every addition, change, and removal that comes from Microsoft.
In Settings → Integrations, within the Automatic Employee Import block, several ways to bring in the roster coexist, and each one is enabled per company:
G Suite — the Google directory.
Azure AD | Legacy — the one this guide explains.
Azure AD | SCIM — SCIM provisioning from Microsoft Entra ID, which has its own documentation.
Okta — SCIM provisioning from Okta.
Manual import — file upload using the Whalemate template.
If you don't see the Azure AD | Legacy card, it's because your company doesn't have it enabled yet. Write to us and we'll make it available.
The difference with Azure AD | SCIM, which is the most common question when both are seen: this integration brings in the roster once a day from the groups you choose. SCIM, on the other hand, makes Microsoft Entra ID notify Whalemate every time there's a change, so additions and removals arrive instantly. Which one suits you best depends on how up to date you need the roster to be and on the Microsoft licenses you have.
Navigation: Settings → Integrations
On the Azure AD | Legacy card, click Import.
The Microsoft Import dialog opens, letting you know you'll be redirected to the Microsoft sign-in page to allow Whalemate to import users and groups. Click Grant access.
You sign in to Microsoft and grant the permissions.
You return to Whalemate, straight to the Groups screen.
Upon returning from consent, no one has been synced yet: the integration is connected but no groups have been selected.
On the Groups screen you choose which of your Microsoft groups you want to bring in. The employees that come in are those belonging to those groups, and each chosen group becomes a Whalemate group that you can later use as an audience.
As long as you don't choose any group, the integration won't bring in any employees. This is the step that's most often forgotten after connecting.
Once a day, during the platform's nightly process (around midnight, Argentina time). It's not configurable.
Between one sync and the next, changes you make in Microsoft aren't yet in Whalemate. If you need an addition to arrive immediately, upload it by hand and the sync will recognize it afterward.
When granting access, Microsoft will ask you to authorize these permissions:
User.Read.All — read the directory's user list.
Group.Read.All — read the group list.
GroupMember.Read.All — read who belongs to each group.
User.Read — read the profile of the account you use to grant access.
offline_access — keep the connection active, so the daily sync can run without you having to re-authorize it.
The three directory permissions are read-only. Whalemate cannot create, modify, or delete anything in your Microsoft account, nor does it access email content or files.
If your organization requires an administrator to approve app permissions, the person making this connection needs to have that level of access in Microsoft.
In Settings → Integrations you'll find access to Integration Logs, the screen where the details of every addition, update, and removal are recorded: which field changed, its previous and new value, the result, and, if something failed, the cause.
The Source field distinguishes changes that came from the integration from those made by hand by someone, so it's the place to confirm whether a piece of data was changed by Microsoft or by your team.
I connected the integration and no employees showed up.
You probably haven't chosen the groups yet. Upon returning from consent, the integration is connected but no group is selected, and without groups it won't bring in anyone. Go to the Groups screen and choose the ones you want to sync.
What's the difference with Azure AD | SCIM?
This one brings in the roster once a day from the groups you choose. SCIM makes Microsoft Entra ID notify Whalemate the moment there's a change, so additions and removals arrive right away. SCIM also requires a specific Microsoft license.
Can Whalemate modify anything in my Microsoft account?
No. The permissions granted over the directory are read-only: users, groups, and group membership are read, and nothing more.
I moved someone to a different group in Microsoft and it's still the same in Whalemate.
The sync runs once a day, at night. The change will be reflected the following day. If you need to verify what was applied and when, check the Integration Logs.
Can I use this integration and manual import at the same time?
Yes, but it's best to avoid it for the same employees: if the roster comes from Microsoft, the daily sync is the source of truth and will overwrite that data for those people. Manual upload is more useful for adding people who aren't in the directory.
Have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap