FAQs: Microsoft Entra ID for Smartsheet

Who can use this?

Plans:

  • Enterprise

Permissions:

  • System Admin

Find out if this capability is included in Smartsheet Regions or Smartsheet Gov.

How long will it take to provision users via Directory Integration? 

Entra ID has different sync times for provisioning depending on the sync configuration,
number of users and groups, and sync type (initial or incremental). Refer to this Microsoft Support article for details.

How are users provisioned in Smartsheet through Entra ID?

This depends on your plan model:

  • User model: All new Entra ID users are automatically provisioned based on their Entra ID group membership. Seat types—Member or Contributor—are automatically assigned based on the group they belong to. Users who have the Smartsheet app assigned in Entra ID but who don’t fit into a specific group default to a Contributor seat type on the first sync. System Admins can be provisioned as Contributors. Learn more about Smartsheet’s user model and provisional membership.
  • Legacy model: Unlicensed users added through Entra ID don't appear in Admin Center immediately—they're only visible after signing in or being added to a group.

If you're unsure about your model type, learn how to determine the model your plan is on.

What will happen to our existing groups in Entra ID or Smartsheet if I enable auto-provisioning?

The Entra ID provisioning service only updates users assigned to the Smartsheet app. Users are assigned by being included in specified role-mapped Entra ID groups.

  • Users not added to any Smartsheet role groups in Entra ID don't get updated or affected in Smartsheet and receive a Contributor seat type.
  • If users are assigned to a Smartsheet role group in Entra ID, provisioned into Smartsheet as a result, and later removed from that group, they’ll be deactivated during the next provisioning cycle.
  • If a Smartsheet user has an account in Entra ID but isn’t assigned to the Smartsheet app or any Entra ID groups mapped to Smartsheet roles, Entra ID ignores the user during provisioning.

What happens to deprovisioned users? Do their Smartsheet accounts get automatically deleted?

Deprovisioned users are deactivated. Their accounts still exist, but you can remove them from your plan. Deactivated users can't sign in to Smartsheet and are no longer assigned a Member seat (license in the legacy model).

If you're unsure about your model type, learn how to determine the model your plan is on.

To remove a user's Smartsheet account from your plan:

  1. Deactivate the Entra ID integration with Smartsheet.
  2. Manually remove the user in Admin Center.

To reactivate a deactivated user, a System Admin must temporarily turn off Directory Integration, reactivate the user, and then re-enable DI.

What happens if someone without a Member seat (license in the legacy model) tries to access Smartsheet but hasn't been provisioned through Entra ID?

  • User model: A Contributor can request a higher level of permissions on a sheet, report, dashboard, or workspace. When an item admin grants the permissions, the user can take a qualifying action and become a Provisional Member. Learn more about Provisional Members.
  • Legacy model: Unlicensed users can request a license in-app. System Admins can then grant it via Entra ID.

If you're unsure about your model type, learn how to determine the model your plan is on.

How do I troubleshoot provisioning errors in Entra ID? 

See this Microsoft Support article for information on troubleshooting errors in Entra ID. 

Can I integrate with Smartsheet from a self-hosted (on premises) AD server? 

You can use Entra ID Connect to sync your self-hosted AD instance with your Entra ID  instance. You can then use your Entra ID  instance for directory integration with Smartsheet. 

What happens when someone in Active Directory has their email changed?

The email change request is sent to Smartsheet and their primary email address is updated with the new email address. Similar to in-app primary email address changes, this does not impact any shared Smartsheet items and items they own, or other existing references to them in Smartsheet.

The old email address will be completely removed from the account. If you want to set up your original email address as a secondary alias, you can manually add it to your user profile. For more information, see Change the email address used with your Smartsheet account.

How do we ensure users are added (similar to User Auto Provisioning) when they sign into Smartsheet for the first time?

Once you have your groups configured and everything running, we suggest treating your SMARTSHEET_USER user group as an all users group. By adding all of your users to this user group, you're ensuring that they'll be automatically added to your company plan upon sign-in.

We have a number of Smartsheet tiles in our Enterprise Applications section in Entra ID. How do I know which one controls Entra ID Provisioning?

When viewing All applications in your Entra ID environment, look for the Smartsheet Enterprise Tile with application ID 3290e3f7-d3ac-4165-bcef-cf4874fc4270.

Is User Auto Provisioning (UAP) required for Directory Integration?

Yes. You must enable User Auto Provisioning to make sure you add new users to your organization. If you don't enable User Auto Provisioning, new users aren't added. This leads to provisioning errors.