Click the sync button () next to the search box at the top-right of the organization list to open the Organization Sync dialog.
2
Pick a data source
In the Data Source dropdown, pick the sync method — JSON Import (default) · Microsoft Graph · Keycloak · Google Workspace. For Entra ID integration, pick Microsoft Graph.When Microsoft Graph is selected, choose which items to fetch.
Option
Description
Default
Administrative Units (관리 단위)
Entra ID’s org management feature; suited to hierarchies
ON
Security Groups (보안 그룹)
Use security groups as organizational units; filter with OData query
OFF
Departments (부서)
Auto-extract department names from user profiles
OFF
Group Filter
Filter to specific groups (optional)
-
Sync options when Data Source = Microsoft Graph
3
Run sync
Click the Sync button at the bottom of the dialog.
Organization Sync dialog — data source selection (default: JSON Import)
Admins can review the resource permissions assigned to a specific OU. The items shown are:
A single consolidated list of a unit’s resource permissions is not included in the current release. For now, check permissions individually via each resource’s Access settings (Knowledge Base, Agents, Databases, etc.) by whether an OU is assigned.
Verify Azure App Registration has Directory.Read.All permission.
Verify environment variables MICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET, MICROSOFT_CLIENT_TENANT_ID are correctly set.
Check server logs for detailed error messages.
Do I need to use both organizations and groups?
Not necessarily. Permission management alone is fine with groups. Use organizations additionally when you need department-based access control with Entra ID integration.
Are members deleted when I delete an OU?
Deleting an OU doesn’t delete the user accounts in it. Only the resource access permissions configured for that OU are removed.