Sync your company directory
Keep People, managers, departments and home locations current from Microsoft Entra ID or Google Workspace.
In the app:Company directory
On this page
Directory sync keeps People current without another spreadsheet. Conduit TEM reads your Microsoft Entra ID or Google Workspace directory each day. It can add people, update their details and mark disabled or removed accounts as having left.
Only owners and admins can connect or manage a directory. Your plan must include directory sync.
Before you connect
Add your locations and, if you use them, divisions or cost centres under Settings → Structure. Conduit TEM places people only when an office or department has one exact matching name or code. It leaves uncertain matches unplaced.
The first sync is always a preview. Nothing in People changes until an owner or admin reviews the totals and selects Apply first sync.
Connect Microsoft Entra ID
You need a Microsoft Entra Global Administrator, Privileged Role Administrator or Cloud Application Administrator who can grant tenant-wide admin consent.
- Go to Settings → Integrations → Directory.
- Select Connect Microsoft.
- Enter your Microsoft Entra tenant ID. This is the organization GUID, not its domain name.
- Select Continue to Microsoft and sign in with one of the administrator roles above. Conduit TEM verifies that sign-in and tenant before Microsoft shows the separate admin-consent request.
- Accept the tenant-wide request and return to Conduit TEM.
The Conduit TEM application asks for Microsoft Graph → User.Read.All → Application only. This is read-only and requires admin consent. It reads users, their managers, departments, office locations, employee ids and whether their accounts are enabled. It cannot change Microsoft accounts.

After Microsoft returns you to Conduit TEM, wait for the first preview. If your organization has its own address (see Your organization's own address), Microsoft passes you back there, still signed in.
Connect Google Workspace
You need a Google Cloud project and access to both its service accounts and the Google Admin console.
-
In Google Cloud, enable the Admin SDK API and create a dedicated service account for Conduit TEM.
-
Turn on domain-wide delegation for that service account, then create and download a JSON key.
-
In the Google Admin console, go to Security → Access and data control → API controls → Manage domain-wide delegation.
-
Add the service account's numeric Client ID. Give it only this OAuth scope:
https://www.googleapis.com/auth/admin.directory.user.readonly -
In Conduit TEM, go to Settings → Integrations → Directory and select Connect Google.
-
Enter a Google Workspace administrator email to impersonate and choose the service-account JSON file. Select Connect Google Workspace.
The JSON key is encrypted when saved and is never shown again. Conduit TEM uses it only to read directory users. Keep the original in your organization's secure credential store so you can rotate or revoke it in Google Cloud.

Review and apply the first sync
The preview shows how many people will be:
- added;
- updated;
- marked as having left;
- unchanged; or
- skipped for review.
It also calls out manual edits that will be kept and assigned lines that will be flagged for leavers. Select Apply first sync when the totals make sense. Conduit TEM reads the directory once more and applies that fresh result.
Later successful syncs apply automatically each day. Select Sync now when you need an update sooner. The card shows the last sync time and change summary.
Conduit TEM stops a later sync for review when it would mark more than 20% of linked people or more than 25 people as having left, using whichever limit is smaller. Owners and admins receive an email, and the connection card shows Needs review. Check that the provider still covers the whole organization, then select Apply reviewed sync. Conduit TEM reads the directory again; if the number has grown past the safety limit, it asks for confirmation again. A complete result with no users is never applied.
What changes, and what does not
- People are matched by email first, then by one unambiguous active full name.
- A disabled or removed directory account is marked Left the company. The person and their services are never deleted. Assigned lines stay attached so you can reassign or disconnect them.
- Office matches a location first; department can match a division or cost centre. The name or code must be an exact, unique match.
- Manual edits win. After a person is linked, Conduit TEM changes a field only while it still has the last value supplied by the directory. A manually changed title, department, location or manager is kept and counted in the summary.
- A restored directory account can reactivate a person when directory sync was what marked them as having left.
Pause or disconnect
Select Pause to stop daily and manual sync without forgetting the connection. Select Resume when you are ready.
Disconnect removes the saved connection, Google credential if applicable, and field source markers. It does not remove or change anyone in People, and it does not unassign lines. Reconnecting later starts with a new first preview.
Troubleshooting
- Microsoft consent link expired: start Connect Microsoft again. The consent link lasts 15 minutes.
- Microsoft sign-in could not be verified: use one of the listed administrator roles in the exact tenant ID entered, then start again.
- Needs review: check that a Google organizational-unit scope was not narrowed and that Microsoft or Google returned the full organization before applying.
- Permission refused: confirm the Microsoft app has
User.Read.Allas an Application permission, or that Google's domain-wide delegation has exactly the read-only scope above. - People are unplaced: make the office or department exactly match one active structure name or code, then sync again.
- A field did not update: check whether someone edited it in People. Manual changes are deliberately kept.
- Needs attention: fix the provider access or replace a revoked Google key by disconnecting and reconnecting, then select Sync now.