Skip to content
  • There are no suggestions because the search field is empty.

Microsoft Entra ID Integration Guide

This guide describes how to sync users from Microsoft Entra ID (Azure Active Directory) to your Nimblr Security Awareness account.

Before you start: once synchronization is enabled, you can no longer add or remove users manually in the Nimblr portal. Any user who can't be matched to an Entra ID user gets removed. Your Entra ID portal may look slightly different depending on your organization's settings and license — this integration doesn't require an E5 or P2 license.

 

Register Nimblr in Entra

  • Log in to the Azure portal and search for Microsoft Entra ID.

entra_integration_1 

 

 

  • In the left menu, under Manage, select App registrations, then click New registration.

entra_integration_2 

 

  • Give the registration a name, for example Nimblr.

  • Select Accounts in this organizational directory only.

  • Under Redirect URL, choose Web, enter https://nimblr.net/go/ad/reg, then click Register.

entra_integration_3
  • Three values appear: Application (client) ID, Directory (tenant) ID, and Object ID. Copy the Application (client) ID and Directory (tenant) ID somewhere safe. You'll need them in a later step.

entra_integration_4 

 

Create a client secret

  • Select Certificates & secrets, then click New client secret.

entra_integration_5 

 

  • Add a description, for example Nimblr Secret, set the expiration to 24 months or longer, then click Add.

entra_integration_6 

  • Copy the Value and save it somewhere safe. This is your client secret. It's shown once, and Entra replaces it with asterisks afterward.

Make sure you save the Value as it’s only shown once and later will be replaced by “****” in the Entra portal.

entra_integration_7

 

Grant API permissions 

  • Select API permissions. User.Read should already be listed. Click Add a permission.

entra_integration_8 

 

  • Select Microsoft Graph, then Application permissions.

entra_integration_9 

Choose Application Permissions on the next screen.

entra_integration_10 

  • Search for and select User.Read.All and GroupMember.Read.All (you can select both before continuing), then click Add permissions.

 

entra_integration_11 

 

  • Your selected permissions now appear in the list. Click Grant admin consent for [organization], then confirm.

Nimblr_-_Azure_Integration_permissions 

 

If you plan to sync specific Entra groups rather than your whole directory, consider creating a dedicated Entra group first. Nested groups aren't currently supported by the Microsoft API, so only direct members sync.

Connect Entra to Nimblr 

  • Log in to your Nimblr account, go to Settings > Integrations, and select Microsoft Entra ID as the integration type.

entra_integration_13 

  • Paste the Application ID, Client Secret, and Directory ID you saved earlier, then click Save Changes. A confirmation appears once it's connected.
entra_integration_14

Choose how users are activated 

Choose how new users from the directory sync get activated. You can change this at any time.

  • Activate new users manually. New users get a "Pending" status, and an admin has to activate them before training starts.

  • Activate new users automatically. New users are activated right away, and training invitations or simulations start immediately.


Integration Settings

Choose a group membership method 

  • Linked. Assign one or more external directory groups to a Nimblr group. This works well for multi-language organizations, since it can place employees in a Nimblr group with the right language already set. You assign groups from Groups > Integration after finishing this setup.

  • Manually. Synchronizes all new users from the selected Entra groups into the Nimblr default group. You can then move users into different Nimblr groups yourself.

    • If you chose Manually, select which Entra groups to sync. Add the external directory group or groups that should sync into the Nimblr default group. You can still create additional Nimblr groups and move users into them by hand; to do that, enter the Entra group name directly in the Nimblr configuration window.

    • Turn on Auto-Create Group Auditors if you want Nimblr to automatically create group auditors with read-only access to reporting and statistics, based on each user's manager attribute. By default, these auditors get a monthly summary report by email covering their scope.


    Assign groups with the Linked method

    This section applies only if you chose the Linked group membership method above.

    Once the integration is set up, you can assign Entra groups to a Nimblr group.

    Before assigning groups, you may want to create additional Nimblr groups first. Go to the Groups menu and click Add New Group. A new group inherits its settings from the default group, and you can change them independently afterward.

    To assign users from a specific external directory group to a Nimblr group, go to that group, click Edit, then open the Integration tab. Add one or more external directory groups, then click Save Changes.

    Managing AD Groups in Nimblr

    Any user in an Entra AD group assigned to Nimblr uses a Nimblr license, regardless of their status in Active Directory.

    A few things worth knowing:

    • Every user in an assigned AD group counts toward license usage.

    • Nimblr treats every user in the group as active, even if they're paused, disabled, or inactive in AD.

    • Pausing or disabling a user in AD doesn't stop them from using a license in Nimblr.

    To keep license usage and access under control:

    • Create AD groups specifically for Nimblr, containing only the users who should have access.

    • Review these groups regularly to make sure they still reflect the right users.

    • Avoid assigning broad groups like "All Employees" unless everyone in that group should actually have access.

    For example, a broad group like All_Company_Users, which might include interns, paused staff, or system accounts, isn't a good fit. A group like Nimblr_Active_Users, containing only the people who need training, works better.

    Important: once an integration is active, manual user management through the portal turns off. From then on, adding, removing, or editing users happens through Active Directory.


    If you have any further questions, feedback or requests just reach out to us here:
    Submit a Ticket