Before you migrate to Microsoft Entra ID Connector
Before you begin, make sure you have:
- A production Entra ID environment.
- A Dropbox sandbox environment for testing.
- A Microsoft Entra ID sandbox environment for testing and validation.
- Admin permissions for Dropbox and Microsoft Entra ID.
- A complete list of Dropbox members and groups.
If you need a Dropbox sandbox, contact your Customer Success Manager. You can also use a Microsoft developer sandbox for testing.
Before making changes, review the Microsoft instructions for provisioning Dropbox with Microsoft Entra ID.
How to prepare the Dropbox enterprise application in Microsoft Entra ID
Before switching connectors, configure the Dropbox enterprise application in Microsoft Entra ID.
Review these settings to understand which members and groups are included:
- Provisioning settings
- Scope settings
- Attribute mappings
For large environments, several factors can affect provisioning performance:
- The number of members, groups, and memberships in scope.
- Whether existing Dropbox accounts are matched or new accounts are created.
- Provisioning errors.
- Group size and complexity.
- Rate limiting during large syncs.
You can use Microsoft Entra ID scope filters to limit the first provisioning run. Limiting the scope can make the results easier to validate.
How to turn off Dropbox AD Connector
Turn off Dropbox AD Connector before turning on Microsoft Entra ID provisioning.
- Find the scheduled tasks that run Dropbox AD Connector.
- Check for other scheduled tasks that may run the connector.
- Turn off or delete all scheduled tasks that run the connector.
- Confirm that Dropbox AD connector can no longer make changes.
How to clear external IDs for Dropbox members and groups
The legacy AD Connector and Entra ID Connector both use identity-linking information between directory objects and Dropbox accounts. Remove the legacy associations so Entra ID can create the correct new associations.
You can’t manage external IDs from the Dropbox admin console.
Use one of the following methods:
- A custom script using the Dropbox API, including the set_profile endpoint.
- Watermint, an open-source command-line tool that can list objects and clear external IDs in bulk.
Test your chosen method in a Dropbox sandbox before using it in production. Confirm that the external IDs for all members and groups are cleared.
How to turn on Dropbox provisioning in Microsoft Entra ID
Before turning on provisioning, confirm that Dropbox AD Connector is off. You must also confirm that all member and group external IDs are cleared.
To turn on provisioning:
- Set the admin credentials.
- Define the provisioning scope.
- For the first run, limit the scope to a subset of members.
- Review the attribute mappings.
- Start provisioning.
- Monitor the first sync cycle and provisioning logs.
How to validate the migration
After turning on Microsoft Entra ID provisioning, confirm that:
- Existing Dropbox members are matched correctly and aren’t duplicates.
- The expected groups are synced.
- Group memberships are correct.
- No members are unexpectedly suspended.
- Successful syncs appear in the Microsoft Entra ID.
- Provisioning logs don’t contain many unresolved errors.
- Incremental syncs continue successfully after the first sync.
How to manage nested groups with Microsoft Entra ID
Microsoft Entra ID provisioning doesn’t support nested groups. A nested group is a group that contains other groups as members.
For example, your Microsoft Entra ID group structure might look like this:
- sg-dbx-all-engineering
- sg-dbx-platform
- sg-dbx-security
- sg-dbx-endpoint
Learn how to manage groups in Microsoft Entra ID.
With Dropbox AD Connector, assigning sg-dbx-all-engineering can provision members through the nested groups.
With Microsoft Entra ID provisioning, assigning only sg-dbx-all-engineering won’t provision members who belong to its nested groups. You must assign each group you want to provision individually.
Continue using Active Directory to manage your groups and members. Make sure the required security groups sync to Microsoft Entra ID using Microsoft Entra Connect or Microsoft Entra Cloud Sync.
After the groups sync:
- Open the Microsoft Entra admin center.
- Go to Enterprise applications.
- Open Dropbox Business.
- Select Users and groups.
- Select Add user/group.
- Assign each synced child group individually, such as sg-dbx-platform, sg-dbx-security, and sg-dbx-endpoint.
Don’t assign only a parent group such as sg-dbx-all-engineering if its members belong through nested child groups.
Review Microsoft identity governance best practices.
How to manage groups after migration
Continue managing group memberships in Active Directory after the migration. Make changes there when a team member joins a department, moves to another department, or leaves the organization.
Microsoft Entra ID syncs the updated groups. The Dropbox enterprise application then provisions the changes automatically. You don’t need to make these changes directly in Dropbox.
Troubleshoot migration issues
If you have problems after migration:
- Confirm that Dropbox AD Connector is no longer running.
- Confirm that external IDs were cleared for all members and groups.
- Check the Microsoft Entra provisioning logs for matching or scope errors.
- Reduce the provisioning scope and retry the migration in stages.
The initial provisioning sync may take longer for larger assignments. Allow approximately 0.01-0.08 minutes per assigned member, group, or group member.
Incremental syncs typically complete within 30 minutes.
Sync times depend on the third-party provisioning provider and may vary. If a sync takes longer than expected, check the status and logs in the provider’s admin console.