Directory sync

SCIM directory sync manages your organization's users and group memberships from your identity provider.

You must connect SSO before connecting a directory. Directory sync matches users through the verified email domains on your SSO connection.

Connect a directory

An organization admin with the org:manage permission can set up directory sync here.

Once you complete the setup in the WorkOS portal, you'll see the directory groups in RWX and be able to map them to the groups in your identity provider.

Map directory groups

You can map one or more identity provider groups to the same RWX group.

When making a mapping, you'll be able to see a preview of the combined membership changes. When you're done mapping, you can review the changes and enable directory sync. Users will not be impacted until you have explicitly enabled directory sync.

Once you've activated directory sync, you can add or remove users in your identity provider rather than in RWX.

Service accounts are not managed by directory sync, and can still be added or removed in RWX.