M365 SSO for existing extensions

Status
Not open for further replies.

Giuseppe Ravasio

Forum User
Joined
Apr 29, 2020
Messages
60
Reaction score
17
Hi,
I would like to enable M365 SSO on a 3CX install already in use where the extensions for all the users are already on the system and we already have an AAD synced with local AD:
- The extension number is the same as the Office Phone on AAD
- The "Email Address" in 3CX is the same as the "Email" field in AAD
- The "Email" field in AAD is not the same as the UPN (User Principal Name) on AAD

I don't want to auto create user extensions but I would like existing extensions to be assigned automatically to the right user.

From what I understood from the docs i should configure the M365 Integration with "User Sync" disabled and "Sign In" enabled.
Am I right? I miss something about fields that should match between the two systems?

I'm running an On-Premise 18.0 Update 2 (Build 314) Enterprise.

Thanks
Giuseppe
 
Hi!

This is a bit of strange situation due to the UPN and the email being different values (in recent years I believe MS has recommended that they be the same).

If they were the same, then yes, enabling only the "Sign In" option would be OK, but because they are different, I think you may have to first:
  1. Enabled "User Sync"
  2. Select the Extension
  3. Press OK
  4. Check that in the "Users" node, the "Sync with" column says MS 365.
  5. Disable "User Sync" again
The reason why this might be need is because during the sync, 3CX will download some background data and will also 'store' the UPN for those users. This way, when you log in with the UPN, it will recognize which extension it's for so even though the actual email is different, you will be logged in to the right user.

Also, if you have already created the Extension in 3CX manually with the Email in 3CX matching the Email (not UPN) that is in AAD, then when you enable "User Sync" it should not create a new extension, it should find the existing extension and sync that.
You can try it with only one user to make sure, and if the result satisfies you, you can proceed with the rest too.
 
Thanks for the answer, It's a domain coming from an old NT4 and that's the reason for the unaligned UPN, but we are considering to align them at some point :)
Just to be clear, if I will align UPN = AAD Email = 3CX email the system will automatically match the users without having to do anything manually? That's the expected behaviour?
Thanks
Giuseppe
 
Thanks for the answer, It's a domain coming from an old NT4 and that's the reason for the unaligned UPN, but we are considering to align them at some point :)
Just to be clear, if I will align UPN = AAD Email = 3CX email the system will automatically match the users without having to do anything manually? That's the expected behaviour?
Thanks
Giuseppe
Yes, if all 3 align, then "User Sync" won't be required to be enabled. I just double-checked it on V18 U2 to be sure. :)
 
  • Like
Reactions: Giuseppe Ravasio
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.