This guide describes how to configure the General Settings of LibraCyber for an organization using a Microsoft 365 tenant with Microsoft Entra ID (Azure AD) and Single Sign-On (SSO). It covers granting Microsoft consents, provisioning users from the directory, configuring Company Scan, mapping groups and departments, managing administrators, and integrations (Webhook and Microsoft Defender).
NOTE: this guide assumes Microsoft Entra ID as the identity provider, SSO already active, and automatic provisioning via application consent in the Microsoft tenant (no CSV import). If your organization uses Google Workspace, Okta, or CSV-only provisioning, refer to the complete General Settings guide.
1. Guide metadata
| Audience | Customer administrator, MSP, integrator. |
| Required role | Microsoft administrator with privileges to grant application consent at the tenant level (typically Global Administrator or a role enabled for administrative consent); LibraCyber administrator with the Edit permissions permission to manage other admins. |
| Estimated time | 30–45 minutes. |
| Difficulty | Intermediate. |
| Tested environment | Microsoft 365 tenant with Entra ID (Azure AD) and SSO enabled. |
| Last verified | June 2026. |
| Owner | INTERNAL USE Solutions / Integration Engineer, with periodic verification. |
2. Prerequisites
- A Microsoft 365 tenant with Microsoft Entra ID (Azure AD).
- SSO already active for access to the LibraCyber platform.
- A Microsoft administrator account with sufficient privileges to grant application consents at the tenant level.
- A LibraCyber administrator account with the Edit permissions permission (necessary to add admins and assign permissions).
- Microsoft licenses assigned to users to be synchronized.
- For delivery of simulation and transactional emails: delivery configured in API mode (as an alternative to SMTP).
- For integrations: reachability of the Microsoft Defender portal (
security.microsoft.com) from the administrator.
3. Before you start (warnings and considerations)
- Microsoft application consents apply to the entire tenant. Grant them only through an authorized administrator: they enable LibraCyber to read users/groups, deliver emails, and (for Smart Banners) process incoming emails.
- The first provisioning may deactivate out-of-scope users. By default, all licensed users and all shared mailboxes are provisioned (the latter are excluded from awareness modules). Verify groups and exclusions before the first run.
- User deactivation is reversible (soft): the user loses access but historical data remains; if the user reappears in the directory, they are reactivated at the next sync.
- Without the Email injection consent, for tenants in API mode, simulation and transactional emails are not delivered.
- No maintenance window is required: operations have limited impact on end users.
4. Configuration procedure
From the side menu, open General Settings. The section is organized into tabs: Setup Checklist, Office Users Provisioning, User Management, Company Scan, Groups & Departments, Admins, Integrations.
Step 1 — Review the Setup Checklist. The Setup Checklist tab is a step-by-step guide that summarizes the status of initial configuration. Each item shows the status and redirects to the corresponding tab.
Step 2 — Grant Microsoft consents. In the Office Users Provisioning tab (named this way for Microsoft tenants), three consents are available to grant based on active modules.
| Button | Permission | Required for |
| Grant User Sync Consent to LibraCyber | Provisioning permissions | All modules — synchronization of users and groups from Entra ID. |
| Grant Direct Message Injection Consent to LibraCyber | Email injection permissions | Email delivery for organizations configured in API mode (not SMTP): phishing simulations and other transactional emails (threat alerts and feedback, awareness reminders, banner test emails, onboarding emails…). |
| Grant Email Process Consent to LibraCyber | Email processing permissions | Smart Banners module — reading for signal analysis and writing to apply banners to suspicious emails. |
NOTE: by default, provisioning is applied to all licensed users and all shared mailboxes; shared mailboxes are excluded from awareness modules.
Step 3 — (Optional) Define the provisioning scope.
In the Excluded users section, you can explicitly exclude individual users from provisioning. This is especially useful when you choose to include unlicensed users, to avoid unwanted entries in the list.
In the Provisioned groups section, you can specify which directory groups to import: only users belonging to the listed groups will be provisioned.
Step 4 — Start provisioning. You can start synchronization at any time with the Start User Provisioning button (immediate sync). By enabling daily user provisioning, synchronization runs automatically once per day: this is the recommended mode, so changes made to the directory are picked up at the next sync without manual actions.
NOTE: deprovisioning — at each run, users present in LibraCyber but no longer present in Entra ID (or no longer included in the selected scope / groups) are deactivated (soft deprovisioning), not deleted. If the user reappears in the directory scope, the next sync will reactivate them.
Step 5 — Verify users in User Management. The User Management tab lists all provisioned users. The Active status is a prerequisite for access to any LibraCyber module.
Step 6 — Complete Company Scan. The Company Scan tab collects general information about the organization, reused in various contexts: phishing simulations, awareness lessons, banner tests.
Company Info
- Name: name of the organization.
- Company Logo: organization logo (max 2 MB, any image format). For crisp rendering in emails, a horizontal logo of approximately 400×100 px or smaller is recommended. The preview logo button opens a test page showing the logo in the top left.
- URL: organization website (informational).
- Domain: organization domain (informational).
Key people — business contacts (e.g., CEO, HR Director) are used by multiple products:
- Simulations: spear phishing simulations can cite or impersonate key people. If the field is empty, the corresponding templates are excluded from the catalog.
- Banners: used for sending demo banners (a sample email impersonates the CEO) and for a detection signal based on key people. WARNING: if CEO information is missing, the sample email sending function returns an error.
- Awareness: HR Director and CEO are the only key people usable in chatbot lessons. When personalizing a lesson, you can use key people macros.
If Key people fields are empty, lessons using them display a placeholder value (in English, not translated):
| Macro | Value shown if field is empty |
| ceo_first_name | My_CEO_first_name |
| ceo_last_name | My_CEO_last_name |
| hr_director_first_name | My_HR_director_first_name |
| hr_director_last_name | My_HR_director_last_name |
NOTE: for a POC or test, it is sufficient to enter any user in place of the CEO. Alternatively, for awareness, do not subscribe to courses/lessons that use the problematic macro, or clone and modify the content to remove or change the macro.
Company signature — the company signature can be customized by administrators to reflect the organization's branding and is reused in simulation templates that reference it.
Key customers — key customers can be added by administrators to increase the realism of phishing simulations.
Step 7 — Map Groups & Departments. The Groups & Departments tab allows you to associate directory groups with custom LibraCyber departments.
NOTE: once imported via provisioning, groups must be assigned to departments. Departments are created manually by administrators and assigned to the corresponding group. A user belongs to all departments derived from the groups they are a member of: they can therefore be in multiple departments, or in none.
Step 8 — Manage Admins. The Admins tab allows you to add new administrators and grant or revoke specific permissions to them.
NOTE: only administrators with the Edit permissions permission can grant or revoke permissions to other admins. Permissions are not automatically assigned upon admin creation or promotion: a new administrator starts with zero permissions until explicitly assigned in this tab.
Below are the permissions assignable to administrators from the console:
| Permission | Area | What it allows |
| Edit permissions | Permissions | Add and remove permissions to other users (you cannot modify your own). |
| Risk Score | Risk Score | Access to Risk Score across products; includes the 5 read permissions for individual products. |
| Corporate Admin | Corporate | Navigate between group companies and access aggregate corporate dashboards. |
| Dashboard | Cyber Awareness | Access to the Cyber Awareness dashboard of the organization. |
| Manage Users | Cyber Awareness | User management. |
| Lessons Admin | Cyber Awareness | Management of lesson content and assignments. |
| Setup | Cyber Awareness | Access to chatbot preferences and setup. |
| Export certificates | Cyber Awareness | Export of lesson completion certificates. |
| Dashboard | Phishing Simulation | Access to the Phishing Simulation dashboard of the organization. |
| Custom Campaign | Phishing Simulation | Creation and sending of custom phishing campaigns. |
| Audit | Phishing Simulation | Access to the simulations audit page. |
| Setup | Phishing Simulation | Access to preferences and simulation delivery test. |
| Video Training Admin | Video Training | Management of video training content. |
| Smart Banners | Smart Banners | Access to the Smart Banners section. |
| Browser Defender | Browser Defender | Access to the Browser Defender section. |
| Threats | Threats | View and categorize real emails reported by users. |
| General Settings | General Settings | Access to the user list and provisioning management from the directory. |
| Company Scan | General Settings | Management of company information, group/department mapping, and SaaS attribution. |
Step 9 — Configure Integrations. The Integrations tab collects settings and instructions for optional integrations.
API and Webhook. The section provides the link to the technical API documentation. Through Webhooks, you can have LibraCyber notifications delivered to a third-party application: the administrator configures a webhook in the third-party app and enters its URL in the settings. Events generated in LibraCyber are routed to that URL.
Currently one webhook event is available:
- Threat reported: sent each time a user reports a threat (equivalent to the threat reported email notification). Payload: report date, threat ID, threat URL.
Microsoft Defender integration. Integration with MS Defender allows you to:
- automatically forward user reports from LibraCyber to MS Defender (Threat Submission);
- block senders or domains directly from the LibraCyber console (Tenant Allow/Block List — TABL).
MS Defender — Threat submission. Sends threats reported by users to Microsoft Defender (via the report button, add-in, or other report channels). Threats appear in Microsoft Defender under Submissions > Email, facilitating remediation for organizations using Defender. Requires the corresponding consent.
MS Defender — Blocking senders/domains (TABL). After granting permission and configuring the Microsoft tenant, you can block senders and domains directly from the LibraCyber console. Blocked senders and domains appear in the Tenant Allow/Block List of Microsoft (accessible at security.microsoft.com/tenantAllowBlockList).
Setup. The administrator must enable the permission and complete the dedicated setup documentation.
5. Verification and acceptance testing
- In the Office Users Provisioning tab, the three consents show the indication Already granted.
- After Start User Provisioning, expected users appear in User Management with Active status.
- In the Setup Checklist, the "Map groups to departments" item is completed and groups are associated with departments in Groups & Departments.
- (Smart Banners) banners appear on incoming emails; (API mode simulations) a test simulation is delivered correctly.
- (MS Defender) a test report appears in Submissions > Email of Microsoft Defender; a sender/domain blocked from the console appears in the Tenant Allow/Block List.
6. Common errors and solutions
| Symptom | Cause | Solution |
| Simulation or transactional emails are not delivered. | Email injection consent missing (tenant in API mode). | Grant Grant Direct Message Injection Consent to LibraCyber in Office Users Provisioning. |
| The sample email sending function (banner demo) returns an error. | CEO information missing in Company Scan. | Fill in the Key people fields (CEO); for a POC enter any user as CEO. |
| Expected users absent after provisioning. | Users outside Provisioned groups, unlicensed, or in Excluded users. | Verify provisioned groups, licenses, and exclusion list. |
| Unwanted entries in the user list. | Inclusion of unlicensed users. | Add unwanted users to Excluded users. |
| Lessons display placeholders like "My_CEO_first_name". | Key people fields empty. | Fill in Key people fields in Company Scan. |
| A user cannot access modules. | Status other than Active in User Management. | Verify the user is in the directory and within provisioning scope; re-run synchronization. |
| Banners do not appear on emails. | Email Process consent missing. | Grant Grant Email Process Consent to LibraCyber. |
7. Rollback / Cancellation
- Reduce scope (reversible): remove groups from Provisioned groups or add users to Excluded users. At the next sync, out-of-scope users are deactivated (soft), with historical data preserved.
- Stop automatic synchronization: disable daily user provisioning.
- Remove admins or permissions: from the Admins tab (requires Edit permissions permission).
- Revoke Microsoft consents (irreversible in effect): revoking application consent on the Microsoft tenant side interrupts provisioning, email delivery, and banners respectively. Revocation is done from the Microsoft Entra ID portal, in enterprise application management.
- Data cleanup: deactivation is soft and does not delete data. For permanent removals, contact support.
NOTE: rollback does not require actions from end users, except for new administrative consent if you revoke and want to restore Microsoft permissions.
8. Security considerations
- The granted consents are OAuth application permissions at the tenant level (Microsoft Graph): user/group synchronization (read), Email injection (delivery to mailboxes), Email Process (read/write on incoming emails for banners). No passwords are shared with LibraCyber.
- No secrets to manage manually: authorization occurs through Microsoft's OAuth consent; consents are revocable at any time from the Microsoft portal and do not require manual rotation.
- Principle of least privilege: limit scope with Provisioned groups and Excluded users, and assign administrators only the permissions they need (new admins start with no permissions).
- Audit: consent grants are tracked in the Microsoft tenant audit log (Entra ID / Defender); changes to admin permissions are controlled through the Admins tab.
9. Maintenance
- Daily automatic provisioning keeps users and groups aligned with the directory; verify periodically that it remains enabled.
- Periodically review Provisioned groups, Excluded users, and Groups & Departments mapping as the organization changes.
- Verify that the three consents remain Already granted: revocation on the Microsoft side interrupts related functionality.
- Review the list of Admins and their permissions (additions, removals, role changes).
- Keep Company Scan data up to date (Key people, company signature, key customers).
10. Related guides and further reading
- Complete General Settings guide (for Google Workspace, Okta, or CSV provisioning).
- Setup Checklist — initial platform configuration before activating individual modules.
- Technical documentation of API and Webhooks.
- Setup documentation for Microsoft Defender integration (Threat submission and TABL).
- Microsoft — Tenant Allow/Block List (Microsoft Defender portal).