[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Foperators\u002Fdirectory-sync":3,"docs:nav":494,"docs:surround:\u002Fdocs\u002Foperators\u002Fdirectory-sync":706},{"id":4,"title":5,"body":6,"description":484,"extension":485,"launchGate":486,"meta":487,"navigation":488,"path":489,"seo":490,"stem":491,"stub":492,"__hash__":493},"docs_en\u002Fdocs\u002F4.operators\u002F9.directory-sync.md","Directory sync: Entra ID and Okta",{"type":7,"value":8,"toc":472},"minimark",[9,13,16,35,38,41,46,70,74,145,148,152,281,287,291,377,381,405,408,412,418,438,442],[10,11,12],"p",{},"Directory sync connects your company directory to one Velrix organisation. The directory adds people, keeps their names, addresses and roles up to date, and removes them. It uses SCIM 2.0, the standard Microsoft Entra ID and Okta use to provision applications.",[10,14,15],{},"When the directory deactivates or deletes someone, Velrix does all of this at once:",[17,18,19,23,26,29,32],"ul",{},[20,21,22],"li",{},"suspends their account, so they can’t sign in with a password or through your identity provider;",[20,24,25],{},"signs them out of every session, on every screen;",[20,27,28],{},"revokes their personal API keys and the apps connected to their account;",[20,30,31],{},"removes them from the organisation, its teams and their roles;",[20,33,34],{},"records it in the organisation’s history and the audit log, with the token that asked and why.",[10,36,37],{},"Turning them active again lets them sign in. It does not bring back the keys that were revoked.",[10,39,40],{},"Deleting someone in the directory does not erase their account. Erasure is a separate step, because records such as invoices are kept for seven years.",[42,43,45],"h2",{"id":44},"before-you-start","Before you start",[17,47,48,56,67],{},[20,49,50,51,55],{},"You need to be the organisation’s ",[52,53,54],"strong",{},"Owner"," (directory sync changes who is in the organisation).",[20,57,58,59,62,63,66],{},"To give people roles from their groups, your operator must have added your company’s sign-in provider (Entra ID or Okta) under ",[52,60,61],{},"Manager › Sign-in providers",". Without one, everyone the directory adds joins as a ",[52,64,65],{},"Member",".",[20,68,69],{},"People sign in through that provider. An account the directory creates has no password.",[42,71,73],{"id":72},"turn-it-on-in-velrix","Turn it on in Velrix",[75,76,77,88,102,117],"ol",{},[20,78,79,80,83,84,87],{},"Open ",[52,81,82],{},"Organisations",", choose your organisation, and open the ",[52,85,86],{},"Directory sync"," tab.",[20,89,90,91,94,95,98,99,66],{},"Choose your ",[52,92,93],{},"Sign-in provider for group mapping",", turn ",[52,96,97],{},"Directory sync on",", and select ",[52,100,101],{},"Save",[20,103,104,105,108,109,112,113,116],{},"Select ",[52,106,107],{},"Make token",". Copy the ",[52,110,111],{},"SCIM URL"," and the ",[52,114,115],{},"Bearer token",". The token is shown only once: if you lose it, make a new one.",[20,118,119,120,123,124,141,144],{},"Under ",[52,121,122],{},"Groups and roles",", map each directory group to a role:",[17,125,126,135],{},[20,127,128,131,132,66],{},[52,129,130],{},"Entra ID",": the group’s ",[52,133,134],{},"Object ID",[20,136,137,140],{},[52,138,139],{},"Okta",": the group’s name.",[142,143],"br",{},"A person gets the highest role any of their groups maps to, otherwise Member. The directory never makes anyone an Owner, and never changes an Owner.",[10,146,147],{},"The mapping is the same one your sign-in provider uses, so signing in and directory sync always agree.",[42,149,151],{"id":150},"connect-microsoft-entra-id","Connect Microsoft Entra ID",[75,153,154,164,177,210,240,253,269],{},[20,155,156,157,160,161,66],{},"In the Microsoft Entra admin center, open ",[52,158,159],{},"Enterprise applications"," and the application you use to sign in to Velrix. If there is none, choose ",[52,162,163],{},"New application › Create your own application › Integrate any other application you don’t find in the gallery",[20,165,79,166,169,170,173,174,66],{},[52,167,168],{},"Provisioning"," and set ",[52,171,172],{},"Provisioning Mode"," to ",[52,175,176],{},"Automatic",[20,178,119,179,182,183,202,104,204,207,208,66],{},[52,180,181],{},"Admin Credentials",":",[17,184,185,196],{},[20,186,187,190,191,195],{},[52,188,189],{},"Tenant URL",": the SCIM URL, followed by ",[192,193,194],"code",{},"?aadOptscim062020",". This makes Entra ID follow the SCIM standard more closely. Velrix also accepts Entra’s older requests.",[20,197,198,201],{},[52,199,200],{},"Secret Token",": the bearer token.",[142,203],{},[52,205,206],{},"Test Connection",", then ",[52,209,101],{},[20,211,119,212,215,216,219,220,219,223,219,226,219,229,219,232,235,236,239],{},[52,213,214],{},"Mappings › Provision Microsoft Entra ID Users",", keep ",[192,217,218],{},"userName",", ",[192,221,222],{},"active",[192,224,225],{},"displayName",[192,227,228],{},"emails[type eq \"work\"].value",[192,230,231],{},"name.givenName",[192,233,234],{},"name.familyName"," and ",[192,237,238],{},"externalId",". Velrix ignores other attributes, such as the department or manager, so you can remove them.",[20,241,119,242,215,245,219,247,249,250,66],{},[52,243,244],{},"Mappings › Provision Microsoft Entra ID Groups",[192,246,225],{},[192,248,238],{}," (the object ID) and ",[192,251,252],{},"members",[20,254,119,255,258,259,173,262,265,266,66],{},[52,256,257],{},"Settings",", set ",[52,260,261],{},"Scope",[52,263,264],{},"Sync only assigned users and groups",". Assign the people and groups under ",[52,267,268],{},"Users and groups",[20,270,271,272,173,275,278,279,66],{},"Set ",[52,273,274],{},"Provisioning Status",[52,276,277],{},"On"," and select ",[52,280,101],{},[10,282,283,284,66],{},"Entra ID provisions every 40 minutes. To try one person at once, use ",[52,285,286],{},"Provision on demand",[42,288,290],{"id":289},"connect-okta","Connect Okta",[75,292,293,308,352,367],{},[20,294,295,296,299,300,169,303,173,305,66],{},"In the Okta Admin Console, open the application you use to sign in to Velrix. On ",[52,297,298],{},"General",", edit ",[52,301,302],{},"App Settings",[52,304,168],{},[52,306,307],{},"SCIM",[20,309,79,310,313,314,345,104,347,207,350,66],{},[52,311,312],{},"Provisioning › Integration"," and fill in:",[17,315,316,322,330,336],{},[20,317,318,321],{},[52,319,320],{},"SCIM connector base URL",": the SCIM URL.",[20,323,324,327,328,66],{},[52,325,326],{},"Unique identifier field for users",": ",[192,329,218],{},[20,331,332,335],{},[52,333,334],{},"Supported provisioning actions",": Push New Users, Push Profile Updates and Push Groups.",[20,337,338,341,342,66],{},[52,339,340],{},"Authentication Mode",": HTTP Header, with the bearer token as ",[52,343,344],{},"Authorization",[142,346],{},[52,348,349],{},"Test Connector Configuration",[52,351,101],{},[20,353,119,354,357,358,219,361,235,364,66],{},[52,355,356],{},"Provisioning › To App",", enable ",[52,359,360],{},"Create Users",[52,362,363],{},"Update User Attributes",[52,365,366],{},"Deactivate Users",[20,368,369,370,373,374,66],{},"Assign people under ",[52,371,372],{},"Assignments",", and push groups under ",[52,375,376],{},"Push Groups",[42,378,380],{"id":379},"who-the-directory-may-change","Who the directory may change",[17,382,383,389,395],{},[20,384,385,388],{},[52,386,387],{},"New people",": an address nobody uses gets a new account.",[20,390,391,394],{},[52,392,393],{},"People already in the organisation",": someone you invited before turning on directory sync is taken over by the directory when it first names them.",[20,396,397,400,401,404],{},[52,398,399],{},"Anyone else",": an address that belongs to an account outside your organisation is refused (",[192,402,403],{},"409","). Invite the person first if they should be managed.",[10,406,407],{},"An account belongs to one organisation’s directory at a time. The directory changes the sign-in address only of accounts it created.",[42,409,411],{"id":410},"status-and-errors","Status and errors",[10,413,414,415,417],{},"The ",[52,416,86],{}," tab shows when the directory last synced, how many people it manages, and its most recent errors, such as a refused token or an address that belongs to someone else.",[17,419,420,426,432],{},[20,421,422,425],{},[52,423,424],{},"Revoke token",": the directory is refused until you make a new token. Nobody is removed.",[20,427,428,431],{},[52,429,430],{},"New token",": the old token stops working at once.",[20,433,434,437],{},[52,435,436],{},"Directory sync off",": every request is refused and nothing changes.",[42,439,441],{"id":440},"what-is-not-supported","What is not supported",[17,443,444,447,469],{},[20,445,446],{},"Bulk requests, sorting and ETags.",[20,448,449,450,453,454,457,458,219,460,219,462,219,465,235,467,66],{},"Filters other than ",[192,451,452],{},"eq",", joined with ",[192,455,456],{},"and",", on ",[192,459,218],{},[192,461,238],{},[192,463,464],{},"id",[192,466,225],{},[192,468,252],{},[20,470,471],{},"Passwords: the directory can’t set one. People sign in through your identity provider.",{"title":473,"searchDepth":474,"depth":475,"links":476},"",2,3,[477,478,479,480,481,482,483],{"id":44,"depth":474,"text":45},{"id":72,"depth":474,"text":73},{"id":150,"depth":474,"text":151},{"id":289,"depth":474,"text":290},{"id":379,"depth":474,"text":380},{"id":410,"depth":474,"text":411},{"id":440,"depth":474,"text":441},"Let your company directory add, update and remove the people in your organisation over SCIM, so that someone who leaves loses access everywhere at once.","md",null,{},true,"\u002Fdocs\u002Foperators\u002Fdirectory-sync",{"title":5,"description":484},"docs\u002F4.operators\u002F9.directory-sync",false,"8zlXiWTqYDOzWuEM54b_VHrhEpx92kehSXxxT9n2EuA",[495],{"title":496,"path":497,"stem":498,"children":499,"page":-1},"Docs","\u002Fdocs","docs",[500,504,534,561,595,663,677,699],{"title":501,"path":497,"stem":502,"stub":492,"launchGate":486,"icon":503},"Overview","docs\u002Findex","i-lucide-house",{"title":505,"stub":492,"launchGate":486,"icon":506,"path":507,"stem":508,"children":509,"page":492},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[510,514,518,522,526,530],{"title":511,"path":512,"stem":513,"stub":492,"launchGate":486},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":515,"path":516,"stem":517,"stub":492,"launchGate":486},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":519,"path":520,"stem":521,"stub":492,"launchGate":486},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":523,"path":524,"stem":525,"stub":492,"launchGate":486},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":527,"path":528,"stem":529,"stub":492,"launchGate":486},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":531,"path":532,"stem":533,"stub":492,"launchGate":486},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":535,"stub":492,"launchGate":486,"icon":536,"path":537,"stem":538,"children":539,"page":492},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[540,544,548,552,556],{"title":541,"path":542,"stem":543,"stub":488,"launchGate":486},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":545,"path":546,"stem":547,"stub":488,"launchGate":486},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":549,"path":550,"stem":551,"stub":488,"launchGate":486},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":553,"path":554,"stem":555,"stub":488,"launchGate":486},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":557,"path":558,"stem":559,"stub":488,"launchGate":560},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":562,"stub":492,"launchGate":486,"icon":563,"path":564,"stem":565,"children":566,"page":492},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[567,571,575,579,583,587,591],{"title":568,"path":569,"stem":570,"stub":492,"launchGate":486},"Apps","\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":572,"path":573,"stem":574,"stub":488,"launchGate":486},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":576,"path":577,"stem":578,"stub":488,"launchGate":486},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":580,"path":581,"stem":582,"stub":492,"launchGate":486},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":584,"path":585,"stem":586,"stub":488,"launchGate":486},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":588,"path":589,"stem":590,"stub":492,"launchGate":486},"Registry","\u002Fdocs\u002Fguides\u002Fregistry","docs\u002F3.guides\u002F6.registry",{"title":592,"path":593,"stem":594,"stub":488,"launchGate":486},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":596,"stub":492,"launchGate":486,"icon":597,"path":598,"stem":599,"children":600,"page":492},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[601,605,609,613,617,621,625,629,633,637,642,646,650,654,658,662],{"title":602,"path":603,"stem":604,"stub":492,"launchGate":486},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":606,"path":607,"stem":608,"stub":492,"launchGate":486},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":610,"path":611,"stem":612,"stub":492,"launchGate":486},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":614,"path":615,"stem":616,"stub":492,"launchGate":486},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":618,"path":619,"stem":620,"stub":492,"launchGate":486},"Policies","\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":622,"path":623,"stem":624,"stub":492,"launchGate":486},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":626,"path":627,"stem":628,"stub":492,"launchGate":486},"Public address and app hostnames","\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":630,"path":631,"stem":632,"stub":492,"launchGate":486},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":634,"path":635,"stem":636,"stub":492,"launchGate":486},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":638,"path":639,"stem":640,"stub":488,"launchGate":641},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":643,"path":644,"stem":645,"stub":488,"launchGate":486},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":647,"path":648,"stem":649,"stub":488,"launchGate":486},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":651,"path":652,"stem":653,"stub":488,"launchGate":486},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":655,"path":656,"stem":657,"stub":488,"launchGate":486},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":659,"path":660,"stem":661,"stub":488,"launchGate":486},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":5,"path":489,"stem":491,"stub":492,"launchGate":486},{"title":664,"stub":492,"launchGate":486,"icon":665,"path":666,"stem":667,"children":668,"page":492},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[669,673],{"title":670,"path":671,"stem":672,"stub":492,"launchGate":486},"The API reference in your realm","\u002Fdocs\u002Freference\u002Fin-your-realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":674,"path":675,"stem":676,"stub":492,"launchGate":486},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":678,"stub":492,"launchGate":486,"icon":679,"path":680,"stem":681,"children":682,"page":492},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[683,687,691,695],{"title":684,"path":685,"stem":686,"stub":488,"launchGate":486},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":688,"path":689,"stem":690,"stub":488,"launchGate":486},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":692,"path":693,"stem":694,"stub":488,"launchGate":486},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":696,"path":697,"stem":698,"stub":488,"launchGate":486},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":700,"path":701,"stem":702,"children":703,"stub":492,"launchGate":486,"icon":705},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[704],{"title":700,"path":701,"stem":702,"stub":492,"launchGate":486},"i-lucide-scroll-text",[707,709],{"title":659,"path":660,"stem":661,"description":708,"children":-1},"What your apps, machines and job runs write: kept past restarts and deploys, with search, live tail and download.",{"title":670,"path":671,"stem":672,"description":710,"children":-1},"The HTTP API, Terraform, Ansible and MCP are documented in your realm's Docs window, at the versions it runs."]