Skip to main content

Federate Entra ID To Files.com

If you already manage access in Entra ID, Files.com signs people in with it. It is the same Microsoft login your team uses for SharePoint and Teams. Provision someone in Entra and they get file access automatically. Deprovision them and their Files.com access is removed right away. You stop setting up file users by hand, and no one keeps access to your files after they leave.

Microsoft Entra IDFiles.com

Why Microsoft Teams Run Files.com Behind Entra ID

If your company runs on Microsoft 365, Entra ID is the login behind all of it. It checks who people are, applies your sign-in rules, and handles them from hire to leave. Files.com sits behind that same login. So your file transfer is governed by the same identity, the same rules, and the same offboarding as every other app. There is nothing separate to manage and no second list to keep in sync.

The Same Microsoft Login

People sign in to Files.com with their Entra ID. It is the same login behind Microsoft 365, Teams, and SharePoint. No second password to remember or manage.

Access Added On Hire, Removed On Exit

The moment you add someone in Entra, they get their Files.com access. The moment you turn them off, that access is removed from the web and the Desktop App at once. So a new hire is productive on day one, and a former employee can never still reach your files. Over SAML this provisioning is automatic and immediate, using the SCIM standard. The older LDAP path syncs once an hour instead.

You Only Pay for People Who Actually Sign In

You can sync your whole Entra directory into Files.com and not pay for the people who never log in. A seat starts counting only once that person signs in for the first time.

SAML, OAuth, or LDAP: Use SAML

SAML is the one to use. It brings the real-time new-hire and departure sync (SCIM). OAuth handles login only, with no sync. LDAP is for older setups that still run on-premises Active Directory.

Microsoft's Login Rules Still Apply

Keep your second-factor check (MFA) and Microsoft's access rules (Conditional Access) in Entra. They run before anyone reaches Files.com. For outside accounts Entra does not manage, add Files.com's own second factor (2FA).

Entra Decides Who Gets In. Files.com Decides What They Reach

Entra decides who gets in and under what conditions. Files.com decides what each person can reach once they are in: nine levels of access, set per person or per group, folder by folder, with the ability to block access and fence in junior admins. Because access maps from your Entra groups, people get exactly what their role allows and nothing more. Least-privilege holds on its own, with no second list to maintain, which is the kind of control an access review wants to see.

Accounts Synced in Real Time

Over SAML, Entra creates accounts, keeps them current, and turns them off in Files.com the instant it happens (SCIM). Turn someone off in Entra, and their Files.com access is gone on the next cycle.

A Clear Record on Both Sides

Files.com keeps a detailed log of every account it creates, changes, or turns off from Entra, so you can see exactly what Entra sent. Entra's own logs give the matching view from the Microsoft side.

Control Down to the Folder

Nine levels of access, set per person or per group, folder by folder. You can block access and fence in junior admins. Access stays defined where your security team manages it.

The Second-Factor Check Covers SFTP Too

Files.com’s second-factor check (2FA) reaches SFTP, FTP, and WebDAV, not just the browser. So outside accounts Entra does not manage still get a second login check on every way in.

The Details That Matter for Entra ID

Account Sync That Keeps Up With Entra

Over SAML, accounts are created, kept current, and turned off in real time (SCIM). The older LDAP path waits up to an hour. With SAML, a change in Entra reaches Files.com right away, so the account list is never out of date and access ends the moment you offboard someone.

Use Account Sync When Groups Map to Folders

Turn on account sync (SCIM) whenever an Entra group needs to land people in the right folders and admin level. A new person then gets exactly the access their group is meant to have, so you set no permissions by hand and no one starts with more access than their role allows. For people with no group, auto-create on first login (JIT) is enough.

Many Files.com Sites, One Entra

Run several Files.com sites from a single Entra setup. Separate teams, business units, or brands each get their own sign-in. You manage every site from one Microsoft directory and never keep a second one in sync.

Connect Entra ID the Way That Fits Your Workload

SAML SSO

The recommended way in. People sign in to Files.com with their Entra login. It is the only method that brings real-time account sync (SCIM), so this is the one path that provisions and deprovisions people automatically.

OAuth SSO

The other Microsoft sign-in standard. People log in with their Entra account. It handles login only, with no account sync (SCIM), so you still create and remove Files.com accounts yourself.

LDAP SSO

For older setups that still run on-premises Active Directory. Account sync runs once an hour, and the directory password works for SFTP, FTP, and WebDAV, so the protocols use the same login as the browser.

Automatic Account Sync (SCIM)

Turn this on for real-time create, update, and remove. New hires appear, changes follow, and people who leave are cut off, all automatically the instant Entra changes. So you never set up a file account by hand, and a departed employee can never still reach your files.

How Teams Use Entra ID on Files.com

Sign In With Your Microsoft 365 Login

Someone clicks Sign in with Entra ID and logs in with the same account behind Teams and SharePoint. They are in Files.com, with no separate password.

Add a New Hire, Their Account Appears

Add a new hire to the right Entra group, and their Files.com account appears right away, with the folders that group is meant to have. No waiting for an hourly sync.

Cut Off Access the Moment Someone Leaves

When someone leaves and Entra turns them off, the next sync turns off their Files.com account too. Web and Desktop App access, gone.

Move From On-Premises AD to Entra, Bit by Bit

A company on on-premises Active Directory signs in over LDAP. It stands up Entra SAML next to it, then moves people across one sign-in method at a time. The old LDAP setup retires last. So you move to Entra at your own pace, with no overnight cutover and no one locked out mid-migration.

Files.com Features Often Used With Entra ID

Microsoft Sentinel logo

Microsoft Sentinel

Feed Files.com audit events straight into the Microsoft security tool your team already watches, so a file-transfer alert shows up where your analysts are already looking.

Learn More

Groups & User Administration

The folder permissions your Entra groups map into. Nine levels of access per folder. You can block access and fence in junior admins.

Learn More

Audit Log & Forensic Trail

Every Entra sign-in, account sync, and permission change is written to a tamper-proof record you can export. When an auditor asks who reached what and when, you have the answer ready.

Learn More

SFTP & Protocol Access

Folder permissions and the second-factor check reach SFTP, FTP, and WebDAV, not just the browser an Entra user signs into.

Learn More

Data Retention & Governance

Set how long files stick around once an Entra user has put them in Files.com, so old data clears out on schedule and you meet a retention rule without anyone deleting files by hand.

Learn More

Files.com Will Be At Microsoft Ignite 2026

November 17–20, 2026 · San Francisco, CA

Files.com builds deeply on SharePoint, OneDrive, Azure, and Microsoft Entra ID, so of course we’ll be on the floor at Microsoft Ignite telling our File Orchestration story. The legacy MFT vendors won’t be there.

See Files.com At Microsoft Ignite
Files.com at a Microsoft event

Frequently Asked: Entra ID on Files.com

How Files.com connects to Entra ID, what it costs, and what the integration actually does.

Federate Entra ID To Files.com And Sign In Today

Start a free 7-day trial. Connect Entra over SAML and turn on real-time account sync. New hires and departures sync on their own, against your own Microsoft directory. No credit card required.

No credit card required • 7-day free trial • Setup in minutes