Available on an Enterprise agreement, alongside single sign-on. We support SCIM 2.0, which is what Entra ID, Okta and the others speak.
The point of it is leavers. Someone leaves, your directory deactivates them, their access here ends the same minute without anybody remembering to do anything.
Set it up
Settings to Directory provisioning. Generate a token. You see it once, so put it somewhere before you close the page.
In your own directory, create the provisioning connection and paste in the address we show you and the token. Then assign the group whose people should have access.
Test with one person before you assign the whole group.
What each action does
| In your directory | Here |
|---|---|
| Add a person to the group | Their account is created, a seat is used, and they are invited |
| Update their name or address | Updated here |
| Deactivate them | Their access ends and their sessions end with it |
| Remove them from the group | Their membership ends and the seat is freed |
What it deliberately does not do
Groups do not map to roles. Everyone provisioned arrives as a member, and a role change is made here. Roles here are a closed set of five, and mapping arbitrary directory groups onto them is a way to hand somebody more than you meant to. Setting a role here takes seconds; getting it wrong silently does not.
It never deletes an account. Removing someone ends their membership and frees the seat, and leaves the account inert rather than destroying it. Deleting an account is a separate decision with a thirty-day window behind it, and it is not something your directory should be able to trigger by accident.
It only reaches accounts it created. If someone already had their own account and you later added them to your organization, your directory can manage their membership but cannot end their sessions elsewhere or change their sign-in address. Your organization governs its membership; it does not govern a person's own account.
Rotating the token
Settings to Directory provisioning to Rotate.
The old token keeps working for a short window while you paste the new one in, because that paste is a manual step on your side and a connector that fails repeatedly gets quarantined by your directory.
When something looks wrong
Your directory's own provisioning log is the first place to look; it records every attempt and the response.
If it reports being refused, check the token first, then that the agreement is current. If a person exists here but has no access, check whether they are suspended rather than removed.
