> For the complete documentation index, see [llms.txt](https://docs.material.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.material.security/getting-started/deployment-guides/your-first-30-days/1-connect-and-sync.md).

# 1: Connect & Sync

## Connect Your First Email Tenant

To begin, connect your first email tenant so Material can begin detecting and creating issues.

{% @arcade/embed url="<https://app.arcade.software/share/Eqk1j6ezvasXFh2fRKii>" flowId="Eqk1j6ezvasXFh2fRKii" %}

<details>

<summary>Connect to Google Workspace</summary>

1. Log in to Material with the Super Admin account we created for you when we set up your trial.
2. Next, invite a new account to enroll the new tenant. This account needs to already have a [Google Workspace Super Admin](https://support.google.com/a/answer/2405986) role, and will become the first account in the new tenant.\
   \
   **Invite a new account**
3. From the workspace, click **Explorer.**

   <div align="left"><figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FMkC9oVnOSDdPL6cKc45H%2Fimage.png?alt=media&#x26;token=a13f7032-569a-4172-b4df-1e74d06a679f" alt="workspace explorer accounts" width="112"><figcaption></figcaption></figure></div>
4. Click **Accounts**.
5. On the top right, click **Enroll Accounts**.
6. From the drop-down, choose **Invite Account**.
7. From the drop-down, choose [Super Admin or Tenant Enroller](/learn-more/administration/admin-roles.md).
8. Select Google, then enter the email address for the [Google Workspace Super Admin account](https://support.google.com/a/answer/2405986) you're inviting.
9. Click **Get Invite Link**.

   <div align="left"><figure><img src="https://content.gitbook.com/content/ksjM8NywYRSHu1IlfxdP/blobs/yF1V73Xa1QC0NbzL6bcY/image.png" alt="" width="188"><figcaption></figcaption></figure></div>
10. Copy the **invite link**, then share it with the Google Workspace Super Admin account associated with the email address entered above. (This can be you if you invited another one of your accounts.) No email invite is sent. If you need to resend the invite link, follow steps 1–8 again and send a new link.

    \
    **The new Google Workspace Super Admin account performs the remaining steps below:**
11. Open an incognito browser window to avoid session conflicts.
12. Log in as the new Super Admin/Tenant Enroller via the invite link you sent (or received) in step 8 above.
13. From the left navigation, expand **Explorer**, then click **Accounts.**
14. On the top right, click **Enroll** **Accounts.**
15. Click **Enroll Google Workspace Tenant.**
16. The steps to complete enrollment, including links to the Google Workspace destinations, appear. Follow those steps to complete the connection **using the same new account you just used to log in to Material.**

    <div align="left"><figure><img src="https://content.gitbook.com/content/ksjM8NywYRSHu1IlfxdP/blobs/soxVjgWxKVKxZYPHO20V/image.png" alt="" width="375"><figcaption><p>Instructions in app</p></figcaption></figure></div>

{% hint style="warning" %}
Next Steps

* In some cases it can take up to 30 minutes for your email tenant to reflect the changes and give Material access.
* If you have additional email tenants to connect to Material, repeat the steps above for each one.
* User accounts will sync shortly and appear in Material in the Explorer. They will also be visible as a new domain in the Global drop-down.
  * Admin roles are **not** inherited from the email provider. After your enrollment is complete, the next section will help you assign admin roles.
    {% endhint %}

</details>

<details>

<summary>Connect to Microsoft 365</summary>

1. Log in to Material with a Super Admin account.
2. Next, invite a new account to enroll the new tenant. This account needs to already have the [Microsoft 365 Global Administrator](https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide) role, and will become the first account in the new tenant:

**Invite a new account**

1. From the workspace, click **Explorer.**

   <div align="left"><figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FMkC9oVnOSDdPL6cKc45H%2Fimage.png?alt=media&#x26;token=a13f7032-569a-4172-b4df-1e74d06a679f" alt="" width="112"><figcaption></figcaption></figure></div>
2. Click **Accounts**.
3. On the top right, click **Enroll Accounts**.
4. From the drop-down, choose **Invite Account**.
5. From the drop-down, choose [Super Admin or Tenant Enroller](/learn-more/administration/admin-roles.md).
6. Select Microsoft, then enter the email address for the [Microsoft 365 Global Administrator](https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide) account you're inviting.
   1. Click **Get Invite Link**.

      <div align="left"><figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2F2Nch7n6eyULhGlwEiX6A%2Fimage.png?alt=media&#x26;token=d87fa201-0a9d-429a-a22b-dc1781e3eb6d" alt="" width="375"><figcaption></figcaption></figure></div>
   2. Copy the **invite link**, then share it with the Microsoft 365 Global Administrator account associated with the email address entered above. (This can be you if you invited another one of your accounts.) No email invite is sent. If you need to resend the invite link, follow steps 1–6 again and send a new link.

**The new Microsoft 365 Global Administrator account performs the remaining steps below:**

1. Open an incognito browser window to avoid session conflicts.
2. Log in as the new Super Admin/Tenant Enroller via the invite link you sent (or received) in step 6 above.
3. From the left navigation, expand **Explorer**, then click **Accounts.**
4. On the top right, click **Enroll** **Accounts.**
5. Click **Enroll Microsoft 365 Tenant.**
6. The steps to complete enrollment appear. Follow those steps to complete the connection **using the same new account you just used to log in to Material.**

{% hint style="warning" %}
**Next Steps**

* In some cases it can take up to 30 minutes for your email tenant to reflect the changes and give Material access.
* If you have additional email tenants to connect to Material, repeat the steps above for each one.
* User accounts will sync shortly and appear in Material in the Explorer. They will also be visible as a new domain in the Global drop-down.
  * Admin roles are **not** inherited from the email provider.
    {% endhint %}

</details>

{% hint style="info" %}
Tenants on the same shared instance will have the same Material URLs. The account (Google or Microsoft) you are logged in as determines the tenant you can access.
{% endhint %}

{% hint style="warning" %}
To unenroll or remove a tenant, contact support.
{% endhint %}

***

{% @arcade/embed url="<https://app.arcade.software/share/NXFHOfYdGQWzKH9lZRY7>" flowId="NXFHOfYdGQWzKH9lZRY7" %}

## Default Account Settings

After you've connected an email tenant, you need to enable a few things to allow Material to sync messages and files from an account's mailbox.

From Settings, click **Default Account Settings**.

<figure><img src="https://content.gitbook.com/content/ksjM8NywYRSHu1IlfxdP/blobs/cE9ayOqpgDwoRQW4XKc3/image.png" alt="click default account settings" width="236"><figcaption><p>Click Default Account Settings</p></figcaption></figure>

### Syncing

1. Toggle Email Sync to **On**.

   <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FvwxRYJeBCWruQuG8ZNL4%2Fimage.png?alt=media&#x26;token=6e2d75d9-0c1d-4d04-a092-be36efef6349" alt="" width="230"><figcaption></figcaption></figure>

{% hint style="warning" %}
Once toggled on, Material begins syncing email messages and populating your Material dashboards. This process can take up to a few days depending on the number of accounts processed.
{% endhint %}

2. Toggle File Sync to **On**.

   <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FUSBxnzCvWbKmEEU2QTaH%2Fimage.png?alt=media&#x26;token=3c06439c-29a9-4ab9-991a-1c926da34a30" alt="" width="291"><figcaption></figcaption></figure>

{% hint style="warning" %}
Once toggled on, Material begins syncing files from Google Drive and populating your Material dashboards. This process can take up to a few days depending on the number of accounts processed.
{% endhint %}

{% hint style="danger" %}
You'll see remediation settings following **Syncing** in Material. Don't touch these just yet, we'll review those in [6: Enable Email Security](/getting-started/deployment-guides/your-first-30-days/6-enable-email-remediation.md).
{% endhint %}

***

## Google Drive Settings

For Google Workspace tenants:

1. From the top toolbar, confirm you're on a Google Tenant. (If you only have one tenant synced, you'll only see Global).

   <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FkE3RmFauiI1juo3RAP4S%2Fimage.png?alt=media&#x26;token=6219a4c2-d129-444c-8b4a-e62427929bfd" alt="" width="290"><figcaption></figcaption></figure>
2. From Settings, click **Google Drive**.
3. Toggle **Connect to Google Drive** to **On**.

   <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2Fti4EZOb8WjwrlWYDOcjw%2Fimage.png?alt=media&#x26;token=fef566ef-dc90-4b07-8505-653d25e6a689" alt="" width="375"><figcaption></figcaption></figure>

<details>

<summary>How to enable or disable syncing for an individual account or group:</summary>

1. From the workspace, click **Explorer.**
2. Click **Accounts** or **Groups**.
3. Open an account or group, then click the **Settings** tab.
4. Under Syncing, select **Set custom...**, then toggle the option and save.

   <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FKnfqmmNE0AjxVH1gvoMI%2Fimage.png?alt=media&#x26;token=fc012558-ffa8-48f4-9a9d-64d525cd0022" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
To bulk update settings, select multiple accounts/groups, then from the bottom toolbar, click **Edit Settings**: ![](https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FdXxfiYSAP01etwrEir81%2Fimage.png?alt=media\&token=852906b1-72a7-48b3-8fb0-837ee87e2e8f)
{% endhint %}

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.material.security/getting-started/deployment-guides/your-first-30-days/1-connect-and-sync.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
