Company configuration
An administrator configures the company-specific Microsoft Entra ID integration and selected groups. Authentication, sign-in policy and directory synchronization are related but separate controls.
Authoritative integration documentation
CardIQ provides company-controlled professional identity and lifecycle controls. Repository implementation, tenant configuration and production deployment are separate states and are identified separately below.
Last reviewed: 2026-09-05. “Where configured” means the required CardIQ entitlement, tenant configuration, Microsoft permissions and deployment prerequisites are in place. Features present in the repository must not be assumed to be deployed for every production tenant.
| Capability | Current status |
|---|---|
| Microsoft Entra OIDC authentication | Implemented and available where deployed and configured, for active pre-mapped CardIQ users |
| Entra sign-in policy enforcement | Implemented in v209. A company can require Entra sign-in for tenant-scoped users where the release is deployed and the integration is ready; Super Admin is exempt. Existing sessions are not automatically revoked. |
| Entra directory preview / selected-group preview | Implemented and available where configured |
| Controlled employee synchronization | Implemented where configured and administrator-reviewed |
| Scheduled reconciliation | Implemented where configured; requires deployment scheduling / an external scheduler |
| Optional automated deactivation | Implemented as an opt-in, policy-controlled workflow with safeguards for explicitly disabled Entra accounts |
| SCIM 2.0 Users provisioning | Implemented in the develop codebase for Enterprise tenants, including discovery endpoints and Users create/read/update/deactivate flows. Staging interoperability validation is still required before general production availability is claimed. |
| SCIM Groups / Bulk | Not currently supported |
| SAML login | Not currently active; stored SAML metadata remains configuration foundation only |
| Just-in-Time (JIT) login-user creation | Not currently supported |
| Native Okta provisioning | Not currently supported |
| Generic tested OIDC/SAML compatibility | Not currently claimed |
Connect → Preview → Review → Controlled Sync → Reconcile
An administrator configures the company-specific Microsoft Entra ID integration and selected groups. Authentication, sign-in policy and directory synchronization are related but separate controls.
Entra directory information from selected groups can be previewed and reviewed before supported employee data is linked, created or updated. Controlled creation creates an employee record; it does not imply JIT creation of a CardIQ login user, role or invitation.
Optional automated reconciliation can monitor changes or apply configured low-risk updates. Optional employee deactivation for an explicitly disabled Entra account requires configured policy and safeguards. A user missing from selected-group results is not treated as proven deleted from Entra.
Where v209 is deployed and readiness checks pass, a company can require Entra sign-in for its tenant-scoped users. Local password authentication is then blocked after valid credentials are checked, while Super Admin remains exempt.
CardIQ now contains a tenant-scoped SCIM 2.0 Users implementation in the develop codebase. This is an implementation-status statement, not a claim of general production availability.
ServiceProviderConfig, ResourceTypes, Schemas and Users endpoints are implemented, with bearer-token authentication, tenant isolation, audit logging, filtering and pagination support for the documented Users scope.
The Users flow supports create, read, update and active=false deactivation through CardIQ employee lifecycle controls. Stable SCIM mappings are maintained for tenant-scoped identities.
SCIM credentials are tenant-scoped, hashed at rest and checked with constant-time comparison. Enterprise entitlement, enabled state, revocation state and active-company eligibility are enforced server-side.
Real Microsoft Entra provisioning interoperability must be validated in staging before CardIQ describes SCIM Users as generally production-ready. Groups and Bulk are not part of the current supported scope.
Microsoft Entra OIDC authenticates an existing mapped login user where configured. SCIM manages employee identity lifecycle records. These are separate capabilities, and neither implies SAML login or JIT login-user creation.
SCIM 2.0 Users is implemented in the develop codebase and remains subject to staging interoperability validation before general production availability is claimed. Controlled Entra synchronization remains a separate Microsoft Graph-based workflow.
SAML metadata can be stored, but SAML login is not active. Separately, Microsoft Entra OIDC sign-in policy enforcement is implemented in v209 and can be required where that release is deployed and the tenant is ready.
CardIQ does not currently claim native Okta provisioning or tested generic OIDC/SAML compatibility. Additional enterprise identity integrations may be evaluated as part of an Enterprise deployment.
Explore the CardIQ Identity platform or review the workflow from verification through identity deactivation.
See how CardIQ Identity works View pricing