SCIM provisioning
With SCIM, your identity provider creates DeskAI agent accounts, keeps names and email addresses up to date, and deactivates people who leave. Available on the Enterprise plan.
Create a token
- Go to Admin Portal → Security → User provisioning (SCIM) and click Create token.
- Copy the token straight away. DeskAI only keeps a fingerprint of it, so it can’t be shown again. Copy the SCIM base URL too.
Microsoft Entra ID
- Open your DeskAI enterprise application → Provisioning → set the mode to Automatic.
- Paste the SCIM base URL as the Tenant URL and the token as the Secret Token, then Test Connection.
- Under Mappings, turn off group provisioning. Keep the user mappings for userName, active, displayName, name and email.
- Assign the people who should have DeskAI accounts, and start provisioning.
Okta
- In the app’s Provisioning tab, enable SCIM provisioning with the SCIM base URL as the connector base URL and
userNameas the unique identifier. - Choose HTTP Header authentication and paste the token.
- Turn on Push New Users, Push Profile Updates and Push User Deactivation. Leave group push off.
What happens in DeskAI
- New people become agents in your company, up to your plan’s technician limit. Roles and teams are still managed in DeskAI.
- Name and email changes are applied as they happen.
- A deactivated person can’t sign in, and any session they have stops working within seconds.
- Someone removed in the identity provider is deactivated in DeskAI and kept, so the tickets they worked on still show who did the work. Adding them back restores the same account.
- MSP admin accounts can’t be deactivated or renamed over SCIM.
- Every change is listed under Admin Portal → Audit Log → Security events. Revoking a token stops syncing at once.