Profile pictures and group-owner synchronization for department managers still require Microsoft Graph. SCIM only covers the profile manager used for the Sync approver with Microsoft Manager option.
Benefits of granting user synchronization permissions
Granting the User.Read.All permission to the absentify - Users Permission app provides multiple key benefits for your organization:- Automated manager-approver assignments: Managers defined in Microsoft are automatically synchronized as absence approvers in absentify, streamlining your approval workflows.
- Up-to-date profile information: Changes to user profiles in Microsoft, such as first name, last name, email, profile picture, business phone, and mobile phone, are automatically synchronized in absentify, ensuring consistent and current information across systems.
- Improved efficiency and performance: absentify stores profile information directly in its database. This ensures high application performance, avoids Microsoft Graph API throttling limits, and provides a smooth user experience.
Default functionality without permissions
If the User.Read.All permission is not granted, Microsoft Graph manager and profile synchronization are unavailable. As a result, the following limitations apply — unless profile managers are provisioned through SCIM:- Manual manager updates: HR teams must manually assign and update approvers within absentify, increasing workload and the risk of outdated information.
- Sign-in-based profile synchronization: User profiles are only updated in absentify when users sign out and sign back in. To avoid Microsoft Graph API throttling, profile updates are limited to one synchronization per user per hour.
How absentify uses the User.Read.All permission
To ensure transparency and build trust, here’s how absentify uses the User.Read.All permission in the absentify - Users Permission app:- Manager synchronization: This permission is used to pull manager information from Microsoft and assign managers as absence approvers in absentify.
- Profile synchronization: Changes in users’ first name, last name, email, profile picture, business phone, and mobile phone are automatically synchronized and stored in absentify’s database. This storage ensures that absentify functions with optimal performance while reducing reliance on frequent API requests.
- Secure storage: All profile data is stored GDPR-compliantly in our secure database hosted in Azure North Europe. No developers or members of other departments have access to the production database or stored data, which is limited exclusively to authorized personnel at absentify GmbH. Database access is restricted to the Azure environment with no external copies or unauthorized access.
Security and data protection
We prioritize security and data privacy, following rigorous standards to protect your organization’s information:- ISO 27001 certification: absentify is ISO 27001 certified, demonstrating compliance with international standards for information security management.
- Microsoft 365 App Certification: The absentify - Users Permission app has achieved Microsoft 365 App Certification, confirming compliance with Microsoft’s security, privacy, and compliance standards. This certification assures that absentify adheres to best practices for data handling and security.
- Secure key management: Access secrets required for synchronization are securely stored in an Azure Key Vault, restricted to authorized personnel at absentify GmbH. No unauthorized access is permitted, and access to all sensitive data is strictly limited to necessary personnel only.
Enabling manager and profile synchronization
Microsoft Graph: Grant User.Read.All for the absentify - Users Permission app from absentify. Do not open a public Microsoft consent URL. Go to Settings > Microsoft and turn on the feature. If the Microsoft permission is missing, Permissions Required opens. If someone sent you a consent link from that page, open that link instead. If you are a tenant administrator, select I am a Tenant Administrator, then Grant Permissions Now. You need a linked Microsoft account. Microsoft opens so you can grant the permission. If you are not a tenant administrator, select I am not a Tenant Administrator. Select Open Pre-Filled Email or Copy Consent Link, then send that request to your IT team. On the web, Grant Permissions Now takes you to Microsoft. You leave absentify and return to Settings > Microsoft with a result banner. If Microsoft confirmed consent but the permission is not visible to absentify yet, Settings > Microsoft shows Waiting for Microsoft… and Microsoft confirmed the consent. The permission usually shows up within a minute; this page checks every few seconds. Select Check now. In Microsoft Teams or SharePoint, Microsoft opens in another window. Settings > Microsoft then shows Waiting for Microsoft… and Grant the permission in the window that opened, then come back here. Select I have granted it. A banner on Settings > Microsoft reports the result after you return from the web. Copied or emailed links, and the window in Microsoft Teams or SharePoint, open a result page instead. That page may show Permission granted, Almost there, Permission was not granted, Wrong Microsoft 365 tenant, This link is no longer valid, or Something went wrong. If the feature was switched off in absentify, you see Permission was not activated. If you close Microsoft before consent, or if consent is declined, nothing changes. Granting the permission requires a Microsoft 365 administrator. A copied or emailed link belongs to your workspace and expires after 14 days. A request you start in the app expires after 15 minutes. Old public Microsoft consent URLs fail with This link is no longer valid. Start again from absentify. If your tenant later revokes the permission, the row shows a warning and Grant again. Manager synchronization must be on in Settings > Microsoft. If you started from that page, a successful grant turns it on. SCIM: Map the enterprisemanager attribute as described in the SCIM provisioning guide. You do not need to grant User.Read.All for manager-based approvers.
Changing a user’s manager in Microsoft
To update a user’s manager directly in Microsoft:- Sign in to the Microsoft Admin Portal.
- Go to Users > Active users.
- Select the user, then select Edit manager or Add manager.
Revoking permissions
If you need to revoke the User.Read.All permission for the absentify - Users Permission app, follow these steps:- Access Microsoft Entra ID: Sign in to the Azure portal with your Microsoft 365 administrator account.
- Navigate to Enterprise applications: In the left-hand menu, go to Microsoft Entra ID > Enterprise applications.
- Find and select absentify - Users Permission: Locate the absentify - Users Permission app (App ID: b163cce9-74dc-48b3-a04f-7a35ea72c451) in your list of applications.
- Manage permissions: Go to the Permissions section and select User.Read.All to revoke absentify’s Microsoft Graph access to manager and profile information.