Deprovision users from your app via an IdP and IdLCM integration
This article describes how to remove users from your external apps via an IdP and IdLCM integration.
Deprovision users from your app via an IdP and IdLCM integration
Who can use this feature?
IT admins with a tenant in an identity provider
Workspace Owners , SuperAdmins , and Admins
As an IT admin collaborating with a workspace Owner , SuperAdmin , or Admin , you can deprovision users from your external apps via your identity provider (IdP) and an IdLCM integration.
After connecting an integration to your IdP, such as Okta or Entra ID, you can centralize user deprovisioning in your IdP. By establishing a SCIM connection, Cerby automatically detects when users are removed from an IdP app integration, either individually or through a group, triggering the automation jobs to propagate these changes to the external app.
Requirements
The following are the requirements to deprovision a user from your external apps via an IdP and IdLCM integration:
A user account in your IdP with privileges to manage an app integration.
An IdLCM integration connected to your IdP, to which you have management access. For more information, read the article Create an IdLCM integration for your app.
Deprovision users from your app via an IdP and IdLCM integration
To deprovision users from your external app via an IdP and IdLCM integration, you must complete the following steps:
Log in to the IdP admin console or center of your organization.
Remove users from the app integration. For instructions, read the official documentation of your IdP:
An automation job to deprovision users is triggered by Cerby. TIP: You can view the progress of the provisioning request in the integration Activity tab.