Let your directory decide who has access.
Connect your identity provider once and let it do the work: users are created, updated, and deactivated automatically over SCIM 2.0, and your Entra security groups map straight to CloudOptify roles. It is fully self-service — generate a token in-app, point your IdP at it, and you are done. No CloudOptify deployment changes required.
SCIM 2.0 provisioning
Joiners, movers, and leavers flow in from Entra / Azure AD automatically — no manual invites to keep up with.
Automatic deprovisioning
When someone leaves a group or the directory, their CloudOptify access is revoked in the same sync.
Entra group mapping (BYOAG)
Map your existing security groups to roles — a “…_admin” group becomes an admin, a “…_reader” group a reader.
Self-service setup
Generate a provisioning token, revoke it anytime, and see when it was last used — all from the app.
How access works
Three ways people get in — pick what fits your plan
Manual invites ship on every plan. Automated directory provisioning is self-service on Business. Federated single sign-on is set up with your Enterprise instance.