Directory Sync
Let Microsoft Entra, Okta or any SCIM 2.0 directory create, update and deactivate people in Deliverd, and keep teams in step with its groups. Account management modes, setup, group mappings, deprovisioning and the provisioning log.
Directory Sync keeps Deliverd in step with your company directory. Your IT team assigns people and groups to the Deliverd application in Microsoft Entra (or Okta, or any directory that speaks SCIM 2.0); they appear here, join the right teams, and lose access the moment they are removed. It is set up on Admin → Identity & SSO → Directory Sync by an owner or admin, and is included in Enterprise.
Account management
Choose once how people get an account here. Nothing changes until you save: an organisation that has never chosen keeps working exactly as it did.
- Deliverd invitations
- Only people you invite can join. Signing in through your identity provider never creates a membership on its own.
- SSO with automatic account creation
- Anyone your identity provider signs in, at a domain you have verified, gets a membership with the default role the first time they arrive.
- Enterprise directory
- Your directory decides who has an account. Directory Sync creates, updates and deactivates people; signing in creates nobody. Invite outside guests here.
- Hybrid
- Directory Sync manages the people it knows about, and anyone else your identity provider signs in is created on arrival.
Directory Sync only accepts requests while the mode is Enterprise directory or Hybrid. Invitations keep working in every mode — they are how you add consultants, partners and anyone else outside your directory.
Set it up
- 1
Connect single sign-on and verify your domain
On Sign-in. Only people whose address is at a domain you have verified can be provisioned, so a directory cannot add a stranger.
- 2
Choose Enterprise directory or Hybrid
Under Account management, and pick the role newly provisioned people get. Viewer is the default.
- 3
Generate a token
Under Credentials. Copy the Tenant URL and the Secret token — the token is shown once. An organisation can hold 2 live tokens; Rotate issues a new one and keeps the old one working for 24 hours while you paste it in.
- 4
Configure provisioning in your directory
In Microsoft Entra: Enterprise applications → your Deliverd app → Provisioning, mode Automatic, then paste the tenant URL and secret token and select Test Connection. Map objectId to externalId under attribute mappings, so a sign-in is matched on the object ID rather than the address.
- 5
Assign users and groups
Assign the groups whose people should use Deliverd directly to the application, and set the scope to Sync only assigned users and groups. Nested groups are not expanded — assign the group that holds the people.
- 6
Start provisioning, then test
Turn provisioning on and wait for the first cycle, or use Provision on demand for one person. Then run Test connection here: it checks the endpoint, the token, the plan and the settings, and changes nothing.
Map groups to teams and roles
A directory group grants nothing until you map it, on Group mappings. Each mapping gives one thing:
- Team membership
- Members of the directory group become members of a Deliverd group, such as Finance. Share reports with that group or name it as approvers before anyone has signed in.
- Workspace access
- Members join a workspace as a viewer, publisher or workspace admin.
- Organisation role
- Members get an organisation role. Once any role mapping exists, provisioned people get the highest role their groups map to, or the default role when none does, and their role is changed in your directory rather than here.
- Nobody is made an owner by a directory, and an owner is never demoted by one. Keep at least one owner who is not managed by your directory.
- Approvers are not a role. Map a group such as Approvers to a team, and name the team in approval policies.
- Somebody you add to a team by hand stays when the directory removes them; the directory only ever removes what it added.
- Removing a mapping, or deleting the group in your directory, withdraws what the mapping gave. The team or workspace itself is never deleted.
- Microsoft Entra app roles (such as
Deliverd.Approver) can be mapped to an organisation role too. They arrive in the sign-in token and apply at the person's next sign-in. - A role that takes a seat is only given while the plan has one free. Otherwise the person is left a viewer and the provisioning log says why.
When somebody leaves
When your directory deactivates someone — or removes them from the application — their membership is suspended at once. A suspended member cannot open anything in the organisation, including reports shared with them by name or through a team; is not asked to approve or review; and is not notified.
- Their API keys and app connections in this organisation are revoked, and out-of-office arrangements naming them end.
- Their sessions end, unless they still belong to another organisation.
- Their approvals, reports, comments and audit history are kept and still name them.
- If your directory assigns them again, their membership is reinstated — unless an administrator suspended them here, which only an administrator can undo.
On People and Groups
People shows where each member came from — your directory, an invitation, an SSO sign-in or added here — and whether your directory manages them. In Enterprise directory mode the page offers Manage users in Microsoft Entra and Invite external guest instead of inviting your own staff. A team member who came from a directory group is marked, and is removed in the directory rather than here.
Troubleshooting
Provisioning log lists every change your directory made and every request that failed for the last 90 days, with a message written for whoever is fixing it and a request ID to quote to us. Common ones:
| Message | What to do |
|---|---|
| …is not a domain this organisation has verified… | Verify the domain on Sign-in, or invite the person as a guest. |
| Directory Sync is not switched on… | Set Account management to Enterprise directory or Hybrid. |
| The bearer token is missing, invalid, expired or revoked. | Generate a token and paste it into your directory again. |
| …the plan has no free seat… | Free a seat or upgrade; the role is applied on the next change. |
| …has not been provisioned by Directory Sync… | Assign the person to the Deliverd application in your directory. |
What is recorded
| Event | When |
|---|---|
identity.scim.user_created, identity.scim.user_updated | Your directory provisions or changes a person. |
identity.scim.user_disabled, identity.scim.user_reactivated, identity.scim.user_deleted | Your directory deactivates, reactivates or removes a person. |
identity.access_revoked | A deprovisioned person's sessions, keys and app connections were ended. |
identity.scim.group_created, identity.scim.group_updated, identity.scim.group_deleted | Your directory creates, renames or deletes a group. |
identity.scim.group_member_added, identity.scim.group_member_removed | Group membership changes. |
identity.role_synced | A mapping changed somebody's organisation role. |
identity.mapping.created, identity.mapping.updated, identity.mapping.deleted | An administrator changes a mapping. |
identity.scim.token_created, identity.scim.token_rotated, identity.scim.token_revoked | Directory Sync credentials change. |
identity.configuration.updated | Account management settings change. |