Customer Onboarding - User Provisioning Options

Options

Type Supports 
SSO
Auto Provisioning Dynamic
 Groups
Organisation 
Size
Report 
Button
Teams App
1. SCIM
(Microsoft Azure 
EntraID or Okta)
✔️ ✔️ ✔️ 150+ ✔️ ✔️ 
Microsoft
2. Google Provisioning ✔️ ✔️ 150+ ✔️
3. Federated Upload ✔️ less than 150** ✔️ ✔️ Depends if you have MS license
4. Bulk Email Upload less than 150**

* Microsoft Azure: P1,P2, E3 or E5 Licence required. 
* Okta: Lifecycle Management Licence required.
** Supports more, but not recommended.


1. SCIM (Azure AD or Okta) (SSO)

Why choose SCIM?

Pros

✅ Automates the addition and removal of users.

✅ Automates the targeting of new users with content within your My Compliance library.

✅ Allows for SSO for safer, more secure login for your users.

✅ Supports the enabling of MFA via your SSO Identity Provider.

✅ Can support multiple EntraID tenants scim 

✅ Allows for the provisioning of pre-existing groups within either AAD or Okta.

✅ Has the option of enabling the MyCompliance Teams App.

Cons

❌ Requires your organisation to have the relevant licensing within either Azure Active Directory (Cloud AAD) or Okta.

❌ Does not support the provisioning of nested groups.

 

🚩 SCIM Prerequisites 

Azure AD

  • An Azure AD tenant with Azure AD Premium 1 or Premium 2 (or EMS E3 or E5) licence.
  • Completed the Discovery document that will be sent by MetaCompliance Support.
  • Have the relevant groups created within your Azure AD that you will provision to your MetaCompliance tenant. (These can be either Dynamic or Security Groups.)
  • An Azure Global Admin who is available to set up the SCIM provisioning and SSO applications.
  • Click here to view the AAD SCIM Configuration instructions.

Okta

  • An Okta tenant with a Lifecycle Management licence.
  • Complete the Discovery document that will be sent by MetaCompliance Support.
  • Have the relevant groups created within your Okta environment that you will provision to your MetaCompliance tenant.
  • A dedicated resource to configure the provisioning app and enable SSO within Okta.
  • Click here to view the Okta SCIM Configuration instructions.

3. Google Provisioning (SAML SSO)

Why choose Google Provisioning?

Pros

✅ Automated provisioning

✅ Offers the option of enabling the Gmail Report Button.

✅ Offers the option of creating your own groups and subgroups.

Cons

❌ You need to ensure the custom attribute 'MetaCompliance' is set to Yes for all of the users on your Google workspace that you plan to provision to the MetaCompliance Platform - Can be manual effort, unless you are familiar with Google Admin Command Line - GAM and you can script it.  

❌ Cannot support multiple Google tenants - we can only configure 1 x Google workspace tenant.
 

🚩 Federated Prerequisites 

  • Google Identity Provider (IDP) that will facilitate SSO for your users.
  • Dedicated personnel who can configure SSO via Google - Super Admin rights are required.
  • Dedicated personnel who will update user data via the MyCompliance Cloud site.

3. Federated Bulk Upload (SSO)

Why choose Federated?

Pros

✅ Does not require your organisation to have a cloud AD solution within AAD or Okta.

✅ Offers the option of enabling the Microsoft Teams App.

✅ Offers the option of creating your own groups and subgroups.

Cons

❌ Manual process that will require manual updating when users are onboarded and offboarded within your organisation.

❌ Will require the manual creation of Groups and Sub-groups within your MyCompliance tenant.

🚩 Federated Prerequisites 

  • An Identity Provider that will facilitate SSO for your users.
  • Dedicated personnel who can configure SSO via your Identity Provider.
  • Completed spreadsheet of user information as per the MyCompliance Cloud site instructions. 
  • Dedicated personnel who will update user data via the MyCompliance Cloud site.

4. Bulk Email Upload

Why choose Email?

Pros

✅ Does not require your organisation to have a cloud AD solution within AAD or Okta.

✅ The option of creating your own Groups and Subgroups.

Cons

❌ Will require manual updating of when users are onboarded and offboarded within your organisation.

❌ Will require the manual creation of Groups and Subgroups within your MyCompliance tenant.

❌ Your users cannot use SSO to log in to their MyCompliance account. A separate password will have to be created upon registration.

🚩 Email Prerequisites 

  • Completed spreadsheet of user information as per the MyCompliance Cloud site instructions. 
  • Dedicated personnel who will update user data as and when required via the MyCompliance Cloud site.
  • Trigger 'registration email' to all users so that they can set up a password for their MyCompliance account.
Back to all articles