Authoritative integration documentation

Microsoft Entra ID, SSO and SCIM capability status

CardIQ provides company-controlled professional identity and lifecycle controls. Repository implementation, tenant configuration and production deployment are separate states and are identified separately below.

Current capability matrix

Last reviewed: 2026-09-05. “Where configured” means the required CardIQ entitlement, tenant configuration, Microsoft permissions and deployment prerequisites are in place. Features present in the repository must not be assumed to be deployed for every production tenant.

CapabilityCurrent status
Microsoft Entra OIDC authenticationImplemented and available where deployed and configured, for active pre-mapped CardIQ users
Entra sign-in policy enforcementImplemented in v209. A company can require Entra sign-in for tenant-scoped users where the release is deployed and the integration is ready; Super Admin is exempt. Existing sessions are not automatically revoked.
Entra directory preview / selected-group previewImplemented and available where configured
Controlled employee synchronizationImplemented where configured and administrator-reviewed
Scheduled reconciliationImplemented where configured; requires deployment scheduling / an external scheduler
Optional automated deactivationImplemented as an opt-in, policy-controlled workflow with safeguards for explicitly disabled Entra accounts
SCIM 2.0 Users provisioningImplemented in the develop codebase for Enterprise tenants, including discovery endpoints and Users create/read/update/deactivate flows. Staging interoperability validation is still required before general production availability is claimed.
SCIM Groups / BulkNot currently supported
SAML loginNot currently active; stored SAML metadata remains configuration foundation only
Just-in-Time (JIT) login-user creationNot currently supported
Native Okta provisioningNot currently supported
Generic tested OIDC/SAML compatibilityNot currently claimed

Microsoft Entra workflow

Connect → Preview → Review → Controlled Sync → Reconcile

Company configuration

An administrator configures the company-specific Microsoft Entra ID integration and selected groups. Authentication, sign-in policy and directory synchronization are related but separate controls.

Preview and review

Entra directory information from selected groups can be previewed and reviewed before supported employee data is linked, created or updated. Controlled creation creates an employee record; it does not imply JIT creation of a CardIQ login user, role or invitation.

Reconciliation and safeguards

Optional automated reconciliation can monitor changes or apply configured low-risk updates. Optional employee deactivation for an explicitly disabled Entra account requires configured policy and safeguards. A user missing from selected-group results is not treated as proven deleted from Entra.

Required Entra sign-in

Where v209 is deployed and readiness checks pass, a company can require Entra sign-in for its tenant-scoped users. Local password authentication is then blocked after valid credentials are checked, while Super Admin remains exempt.

SCIM 2.0 Users implementation status

CardIQ now contains a tenant-scoped SCIM 2.0 Users implementation in the develop codebase. This is an implementation-status statement, not a claim of general production availability.

Implemented surface

ServiceProviderConfig, ResourceTypes, Schemas and Users endpoints are implemented, with bearer-token authentication, tenant isolation, audit logging, filtering and pagination support for the documented Users scope.

Lifecycle behavior

The Users flow supports create, read, update and active=false deactivation through CardIQ employee lifecycle controls. Stable SCIM mappings are maintained for tenant-scoped identities.

Security model

SCIM credentials are tenant-scoped, hashed at rest and checked with constant-time comparison. Enterprise entitlement, enabled state, revocation state and active-company eligibility are enforced server-side.

Validation boundary

Real Microsoft Entra provisioning interoperability must be validated in staging before CardIQ describes SCIM Users as generally production-ready. Groups and Bulk are not part of the current supported scope.

Authentication is not provisioning

Microsoft Entra OIDC authenticates an existing mapped login user where configured. SCIM manages employee identity lifecycle records. These are separate capabilities, and neither implies SAML login or JIT login-user creation.

SCIM disclosure

SCIM 2.0 Users is implemented in the develop codebase and remains subject to staging interoperability validation before general production availability is claimed. Controlled Entra synchronization remains a separate Microsoft Graph-based workflow.

SAML and Entra SSO

SAML metadata can be stored, but SAML login is not active. Separately, Microsoft Entra OIDC sign-in policy enforcement is implemented in v209 and can be required where that release is deployed and the tenant is ready.

Okta and other providers

CardIQ does not currently claim native Okta provisioning or tested generic OIDC/SAML compatibility. Additional enterprise identity integrations may be evaluated as part of an Enterprise deployment.

Control how employees represent your company externally

Explore the CardIQ Identity platform or review the workflow from verification through identity deactivation.

See how CardIQ Identity works View pricing