- Documentation
- Set up
Import your people
Bringing your team in from Microsoft Entra ID, how personal details are held separately, and why an unlinked person silently receives nothing.
Audience: ISMS Admin.
Where: the Certaria app, which reads your people from Microsoft Entra ID.
Do this early. Almost everything else in Certaria addresses a person: acknowledgements, task reminders, training records, overdue chases. A person who is not in the register, or is in it without a linked account, is invisible to all of it and produces no error.
Importing from Entra ID
Section titled “Importing from Entra ID”The import runs from the setup wizard.
- Open the user picker. Certaria reads the list of accounts in your Entra ID directory. It only reads your directory and never changes it.
- Choose which accounts to bring in. You are not obliged to take everyone: contractors, service accounts and shared mailboxes are usually better handled separately.
- Choose the task templates to apply. Each imported person gets their opening compliance tasks from the templates you select.
- Run the import. Certaria creates a People record for each account.
Any account that could not be imported is reported back to the wizard rather than skipped quietly.
The daily directory sync
Section titled “The daily directory sync”Once a day Certaria reads your Microsoft 365 directory again and:
- Adds any new department to your Departments list.
- Creates or refreshes an entry in your User Accounts register for every account it finds.
- Links each account to the right person.
- Fills in the department for people imported before that information was collected.
Three fields are left alone: account type, multi-factor status and last review date. Certaria will not guess these on your behalf, because judging whether an account is privileged or a service identity is a decision with consequences. See The registers you maintain.
The failure that produces no error
Section titled “The failure that produces no error”Who needs a licence
Section titled “Who needs a licence”Only ISMS administrators need a Power Apps licence, and Per App, Per User or Pay-As-You-Go all work. Everyone you import reads and acknowledges policies through SharePoint and receives messages through Teams, both covered by your existing Microsoft 365 subscription.
When someone leaves
Section titled “When someone leaves”Certaria does not remove people when their Entra account is disabled, and this is deliberate. Their acknowledgement history, training records and task history are evidence, and an auditor may ask about a period when that person was employed.
Mark them inactive rather than deleting them. If they ask to be anonymised, delete the linked Person Identity record, which removes the personal data and leaves the compliance history in place.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| One person never receives anything | No linked user account, or no email address | Check the People record and its linked identity |
| The user picker is empty | The directory read failed, usually a Graph permission | See Graph consent |
| Someone appears twice | Imported by hand and then again by the sync | Merge onto the record carrying the acknowledgement history and deactivate the other |
| Departments list is empty | It populates from the daily sync, not the import | Wait for the next run |
| An imported person has no tasks | No task templates were selected at import | Assign tasks by hand, or re-run the import for that person |
- Who can see and do what, before anyone arrives on the site
- Publish a policy, the first thing your people will be asked to do
- The registers you maintain