Direct Answer: How to Manage AD Synchronization in OnePlan
To manage AD synchronization in OnePlan, go to the Resource Center, click the … menu, select Configure, and expand the AD Synchronization section. Click Load Groups Now to pull in your Microsoft Entra ID Security and Microsoft 365 groups, select the groups you want to sync from the AD Groups to Synch drop-down, and click Synchronize Now to bring those users’ names and email addresses into the Resource Center.
What This Article Covers: AD Synchronization
This article explains how to set up and manage the synchronization between your Microsoft Entra ID directory and the OnePlan Resource Center. It covers enabling app permissions, loading and selecting AD groups to sync, running an on-demand sync, and what happens to synchronized users afterward.
What you will accomplish: By the end of this article, you will be able to enable AD synchronization, select which AD groups to sync, run a sync on demand, and understand how synced users are added to the Resource Center.
Before You Begin: AD Synchronization
- Confirm you have Owner or Administrator permissions in OnePlan — this is required to access Configure in the Resource Center.
- Have your Microsoft tenant administrator available — enabling AD synchronization requires them to grant app permissions before you can load or sync AD groups.
- Confirm the default Enterprise Security Group is configured the way you want, since all newly synchronized users are assigned that group at the time Synchronize Now is run. See How to Grant Users Access to OnePlan via Entra Groups for related permission concepts.
- Review Resource Center Administration in OnePlan - Overview if you are not yet familiar with how resources are managed in the Resource Center.
Why This Matters: AD Synchronization
Keep the Resource Center current without manual entry
AD synchronization pulls user names and email addresses directly from your Microsoft Entra ID groups into the Resource Center, reducing the manual work of adding each named resource one at a time.
This is a push, not a true two-way sync
Despite the name, AD Synchronization is a one-way push from Microsoft Entra ID into the Resource Center, not a live two-way sync. It is add-only in two respects: removing a group from the AD Groups to Synch selection does not delete users already synced into the Resource Center, and removing an individual user from a synced Microsoft Entra ID group has no effect at all on that user’s resource record in OnePlan — they are not removed, deactivated, or otherwise flagged. This differs from how some other tools (including Project Server) handle AD sync, where removing a user from the source AD group would mark them inactive automatically. In OnePlan, an administrator must manually mark a resource Inactive (see How to Remove a User from the OnePlan License Count) if they leave the source Microsoft Entra ID group and should no longer be an active resource.
Consistent default permissions for new users
Every user brought in through Synchronize Now is assigned the default Enterprise Security Group configured at the time of that sync, so newly synced users have predictable, consistent access until an admin adjusts their permissions.
Step-by-Step: Managing AD Synchronization in OnePlan
Task: Enable AD Synchronization
Go to the Resource Center, click the … menu, then select Configure. Expand the AD Synchronization topic heading. Confirm you have permission to access Configure in the Resource Center.[[administration/users-and-resources/How to Manage AD Synchronization in OnePlan/attachments/Access Users Settings.png]]
Have your Microsoft tenant administrator click To synchronize users you must enable app permissions here to grant the required app permissions. This step must be completed before AD groups can be loaded or synced.
### Task: Load and Select AD Groups to Sync
Click Load Groups Now to query your Microsoft Entra ID directory and retrieve all Security and Microsoft 365 groups. This populates the AD Groups to Synch drop-down.
This action is not instantaneous. The more groups within your tenant, the longer the process can take.
- Expand the AD Groups to Synch drop-down to see all available AD groups.
- Multi-select the groups you want to sync.
Synchronization is add-only. If you later remove groups from this selection, users already synced from those groups will not be deleted from the Resource Center.
Task: Run an On-Demand Synchronization
- Click Synchronize Now to sync on demand. The
following fields come over from AD to the Resource Center:
- Name
- Email Address
- Check the Last Status field — it displays Complete once processing finishes.
All newly synchronized users are assigned the default Enterprise Security Group configured in the Enterprise Security Groups tab at the time the Synchronize Now process is initiated.
Frequently Asked Questions: AD Synchronization
Q: What happens if I remove a group from the AD Groups to Synch selection?
A: In OnePlan, removing a group from the selection stops future syncs from that group, but it does not delete users who were already synced into the Resource Center. The synchronization is add-only.
Q: If I remove a user from a synced AD group, are they removed or deactivated in OnePlan?
A: In OnePlan, no. AD Synchronization is a one-way push, not a true two-way sync — removing a user from the source Microsoft Entra ID group has no automatic effect on their resource record. An administrator must manually mark the resource Inactive if it should no longer be active.
Q: Is OnePlan’s AD Synchronization the same as a true Microsoft Entra ID sync?
A: In OnePlan, no. It only pushes new users into the Resource Center when Synchronize Now is run; it does not continuously monitor group membership or remove/deactivate users automatically when they leave the source Microsoft Entra ID group.
Q: What information does AD synchronization bring into the Resource Center?
A: In OnePlan, synchronization brings over the Name and Email Address fields for each synced user from Microsoft Entra ID.
Q: What permission level do newly synced users get?
A: In OnePlan, newly synchronized users are assigned the default Enterprise Security Group configured in the Enterprise Security Groups tab at the time the sync runs.
Q: Who needs to grant permissions before I can sync AD groups?
A: In OnePlan, your Microsoft tenant administrator must click To synchronize users you must enable app permissions here to enable the required app permissions before groups can be loaded or synced.
What to Do Next: AD Synchronization
Manage the resources and permissions that result from a sync:
- How to Grant Users Access to OnePlan via Entra Groups
- How to Add Named Resources in OnePlan
- How to Resend a OnePlan Invite
Review the broader Resource Center administration process:
Comments
1 comment
Suggestion: Cross-reference “AD” today with the new term “Entra”.
I still call it AD, but my clients are calling it Entra; I need to get used to it. :-)
Please sign in to leave a comment.