- Documentation
- Set up
Import your people
Bringing your team in from Microsoft Entra ID, how personal details are held separately, and why an unlinked person silently receives nothing.
Audience: ISMS Admin.
Where: the Certaria app, which reads your people from Microsoft Entra ID.
Do this early. Almost everything else in Certaria addresses a person: acknowledgements, task reminders, training records, overdue chases. A person who is not in the register, or is in it without a linked account, is invisible to all of it and produces no error.
Importing from Entra ID
Section titled “Importing from Entra ID”The import runs from the setup wizard.
- Open the user picker. Certaria reads the list of accounts in your Entra ID directory. It only reads your directory and never changes it.
- Choose which people to bring in. The picker offers only accounts that can sensibly become a person: enabled Microsoft 365 member accounts with a real name. Service accounts, shared mailboxes, guests and disabled accounts are recorded in your User Accounts register but are never offered for import.
- Choose the task templates to apply. Each imported person gets their opening compliance tasks from the templates you select.
- Run the import. Certaria creates a People record for each account.
Any account that could not be imported is reported back to the wizard rather than skipped quietly.
Privileged accounts are opt-in
Section titled “Privileged accounts are opt-in”Accounts that hold an Entra admin role appear in a separate, highlighted Privileged Accounts section beneath the main list, and are never ticked by default. Select all deliberately leaves them alone.
Import one only if it is that individual’s primary everyday login. In most organisations an administrator has a separate everyday account, which appears in the main list; importing the admin account as well would create a second person for the same human. Either way, the account itself stays in your User Accounts register with its Admin classification, so nothing is lost by leaving it unticked.
The daily directory sync
Section titled “The daily directory sync”Once a day Certaria reads your Microsoft 365 directory again and:
- Adds any new department to your Departments list.
- Creates or refreshes an entry in your User Accounts register for every account it finds.
- Classifies each account as Standard, Admin, Service, Shared Mailbox or External, from the directory itself: admin role membership, guest status, your Shared Mailboxes register, and whether the account carries a person’s name.
- Links each account to the right person.
- Fills in the department for people imported before that information was collected.
The classification is a starting point you can correct, not a verdict. Two fields are left entirely alone: multi-factor status and last review date. Reviewing an account is a judgement with consequences, and Certaria will not fake it on your behalf. See The registers you maintain.
Roles decide who is asked to acknowledge a policy
Section titled “Roles decide who is asked to acknowledge a policy”Every person carries one or more roles, such as Director, Staff or Contractor, and a person can hold several. Someone can be a Director and a member of staff at the same time, and should be given both.
Every document can name the roles it applies to. If it names none, it applies to everyone. If it names some, only people holding at least one of them are asked to read and confirm it.
These are two different fields on two different records, and mixing them up is easy:
| Where | Field | Meaning |
|---|---|---|
| A person’s record | Role | what this individual is |
| A document | Applies to role | who has to acknowledge this document |
Roles are set in People. Open the person, and Role sits alongside whether they are active, their department and their linked user account. Give someone every role that applies to them: a director who is also a member of staff should hold both, or they will miss anything addressed to staff.
The failure that produces no error
Section titled “The failure that produces no error”Who needs a licence
Section titled “Who needs a licence”Only ISMS administrators need a Power Apps licence, and Power Apps Premium (per user), Pay-As-You-Go or Per App (through a Microsoft CSP partner) all work. Everyone you import reads and acknowledges policies through SharePoint and receives messages through Teams, both covered by your existing Microsoft 365 subscription.
When someone leaves
Section titled “When someone leaves”Certaria does not remove people when their Entra account is disabled, and this is deliberate. Their acknowledgement history, training records and task history are evidence, and an auditor may ask about a period when that person was employed.
Mark them inactive rather than deleting them. That is the whole of routine offboarding. An inactive person is no longer asked to acknowledge anything and no longer appears in chases, and everything they did remains.
If they ask to be erased
Section titled “If they ask to be erased”A request to be erased under data protection law is a different and heavier thing, and Certaria performs it for you.
Before you begin: two steps in Microsoft 365, both required
Section titled “Before you begin: two steps in Microsoft 365, both required”- Delete the person’s account in Entra ID. Delete it, rather than disabling it.
- Retire their devices in Intune, so no enrolment remains recorded against their name.
Certaria reads your directory once a day and refreshes what it finds there. If the account or one of their devices still exists when you run the erasure, the next daily read can restore identifiers you have just removed. Deprovisioning first is what prevents that, and it is not optional.
Find the person’s identifier
Section titled “Find the person’s identifier”- Open the ISMS Management Hub app.
- Go to People and open the individual’s record.
- Copy the value of the
id=parameter from your browser’s address bar. It is a 36 character identifier.
Run the erasure
Section titled “Run the erasure”- Go to Solutions, then Certaria, then Cloud flows.
- Open Certaria: Erase Person.
- Select Test, choose Manually, then Save and Test.
- Paste the identifier from the previous step into TargetPersonId.
- Select Run flow, and wait for the run to finish.
Erasure cannot be undone. Check you have the right person before you run it. Running it twice on the same person is safe and changes nothing the second time.
What you should see afterwards
Section titled “What you should see afterwards”The person still appears in your registers, reading as their reference rather than their name. Their acknowledgement history and training records are intact and now show that reference. Their contact details are gone, and so are the identifiers that were held alongside them elsewhere.
That is the intended result. The individual is no longer identifiable, and the evidence that your ISMS was running survives.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| One person never receives anything | No linked user account, or no email address | Check the People record and its linked identity |
| The user picker is empty | The directory read failed, usually a Graph permission | See Graph consent |
| Someone appears twice | Imported by hand and then again by the sync | Merge onto the record carrying the acknowledgement history and deactivate the other |
| Departments list is empty | It populates from the daily sync, not the import | Wait for the next run |
| An imported person has no tasks | No task templates were selected at import | Assign tasks by hand, or re-run the import for that person |
- Who can see and do what, before anyone arrives on the site
- Publish a document, the first thing your people will be asked to do
- The registers you maintain