SCIM Provisioning & Entra SyncBusiness

Let your directory decide who has access.

Connect your identity provider once and let it do the work: users are created, updated, and deactivated automatically over SCIM 2.0, and your Entra security groups map straight to CloudOptify roles. It is fully self-service — generate a token in-app, point your IdP at it, and you are done. No CloudOptify deployment changes required.

SCIM 2.0 provisioning

Joiners, movers, and leavers flow in from Entra / Azure AD automatically — no manual invites to keep up with.

Automatic deprovisioning

When someone leaves a group or the directory, their CloudOptify access is revoked in the same sync.

Entra group mapping (BYOAG)

Map your existing security groups to roles — a “…_admin” group becomes an admin, a “…_reader” group a reader.

Self-service setup

Generate a provisioning token, revoke it anytime, and see when it was last used — all from the app.

How access works

Three ways people get in — pick what fits your plan

Manual invites ship on every plan. Automated directory provisioning is self-service on Business. Federated single sign-on is set up with your Enterprise instance.

Invite a teammateEvery paid plan · no setup
1Admin invitesEnter email, pick a role
2Email sentSecure invite link
3They acceptClick the link, sign in
4Member activeAccess at their role
SCIM provisioning & Entra syncBusinessSelf-service · no deployment changes
1Connect your IdPPaste the SCIM token
2Directory pushesSCIM 2.0, automatically
3CloudOptify provisionsCreate · update · deactivate
4Groups map to rolesYour Entra groups (BYOAG)
Federated single sign-onEnterpriseConfigured with your instance
1User opens CloudOptifyRedirected to your IdP
2Authenticate at your IdPYour MFA & policies apply
3Federated trustIdP vouches for the user
4Signed inNo separate password

See it on your numbers.

Early access — a new platform, onboarding teams now.