What is Generic Onboarding?
Generic onboarding allows partner-level administrators to connect a Microsoft 365 customer to the Control Panel without booking 365 Total Protection for the customer. Generic onboarding is particularly suitable for customers who want to use services such as the Security Awareness Service and therefore need user, mailbox, domain, and group information from Microsoft 365 in the Control Panel.
During generic onboarding, relevant information from the Microsoft 365 tenant is automatically and continuously transferred to the Control Panel.
Important! Generic onboarding must be distinguished from full onboarding for 365 Total Protection. Generic onboarding alone only establishes the aforementioned synchronization with Microsoft.
What is configured during generic onboarding?
Information about the following objects is transferred from Microsoft 365:
- Domains
- Mailboxes
- Groups and group memberships, provided that the requirements for group synchronization are met
- Basic data of synchronized mailboxes
No content from the mailboxes is transferred. In particular, no email text or other email content is transferred to the Control Panel as part of generic onboarding. Synchronization also does not change any configuration settings in the Microsoft 365 tenant.
Requirements
The following are required for generic onboarding:
- A Microsoft 365 organization
- Administrative credentials for the customer's Microsoft 365 tenant.
Onboarding options
Generic onboarding can be performed in two ways:
Onboarding by the partner: The partner opens the onboarding form in the Control Panel and connects it to the customer's Microsoft 365 tenant. This option is suitable if the partner has the required administrative credentials for Microsoft 365 and is to handle the setup for the customer.
To do this, navigate to 365 Total Protection > 365 Total Protection. There, select the option for generic onboarding and click Onboard customers.
Onboarding via an onboarding link: Alternatively, the partner can create a link for generic onboarding and provide it to the customer. The customer then opens the onboarding form, signs in with an administrative Microsoft 365 account, and grants the required permissions.
Connect a Microsoft 365 tenant
After the onboarding form has been opened, enter the required contact information. Then confirm the corresponding privacy checkbox and click Start now.
You will then be redirected to the Microsoft sign-in page. Sign in with an administrative account for the Microsoft 365 tenant and accept the requested permissions so that the connection between Microsoft 365 and the Control Panel can be established.
After successful authorization, the domains and mailboxes of the Microsoft 365 tenant are displayed in the Control Panel.
Special feature for the Security Awareness Service
Information that is important for the Security Awareness Service is also transferred during synchronization. The positions and languages of the users play a special role in the training; these are synchronized to the Control Panel using special custom attributes.
To assign these attributes, you must enter the following value in an “extensionAttribute” in your Active Directory:
sas_language={language code};sas_position={position}Note that you must replace the placeholders {language code} and {position} with the appropriate position and language code. You can find the positions and language codes that you can use in the following guide entry: Language codes and positions for synchronization
To ensure that the correct attributes can be read in our Control Panel, you can select the appropriate extensionAttribute field in the directory service.