Microsoft Entra OIDC authentication
Implemented for active, pre-mapped CardIQ Identity users where the company integration is deployed and configured.
Enterprise identity documentation
CardIQ Identity separates authentication, provisioning and employee lifecycle control. Availability depends on deployed code, tenant entitlement and configuration.
Last reviewed: 2026-09-05. Repository implementation is not the same as production deployment. Where stated, staging or tenant validation is still required.
Implemented for active, pre-mapped CardIQ Identity users where the company integration is deployed and configured.
Implemented in the v209 code path. A company can use an optional or required Entra sign-in policy where the supporting release is deployed and readiness checks are satisfied. Existing sessions are not automatically revoked.
Not currently active. Stored SAML metadata is configuration foundation only and must not be described as working SAML login.
Implemented in the develop codebase for Enterprise tenant-scoped provisioning with bearer-token authentication, User discovery, create/update/deactivate/reactivate flows, filtering and audit controls. Real staging interoperability validation is still required before a general production-support claim.
Not currently supported.
Not currently supported. Entra authentication signs in an existing mapped user; it does not create a new CardIQ Identity login user automatically.
No native Okta provisioning or tested generic SAML/OIDC compatibility claim is currently made.
Microsoft Entra OIDC verifies the configured sign-in path for an existing mapped CardIQ Identity user. Enforced Entra sign-in is a tenant policy when the v209 path is deployed and enabled.
Provisioning creates, updates, deactivates or reactivates employee identity records. CardIQ Identity provides a Microsoft Graph-based controlled Entra synchronization workflow, and separately contains a SCIM 2.0 Users implementation in develop.
Offboarding and deactivation remain subject to company policy and safeguards. Missing membership in a selected Entra group is not treated as proof that an identity was deleted from Entra.
The current implementation is intentionally scoped to Users and conservative lifecycle behavior.
ServiceProviderConfig, ResourceTypes, Schemas, Users list/read/create, PUT/PATCH updates, active=false deactivation, reactivation, userName/externalId equality filters, pagination, tenant-scoped tokens, token revocation/rotation support, rate limiting and audit logging.
Groups, Bulk, SAML login, JIT login-user creation and a claim of broad third-party interoperability certification.
Until a real Enterprise staging pilot is completed, public wording should say that SCIM Users is implemented and under interoperability validation, not that CardIQ Identity provides generally available production SCIM.
A capability present in develop or main must still be released to the target environment before it is available to a tenant.
Microsoft tenant settings, permissions, selected groups, CardIQ Identity entitlement, mapping and policy configuration must be complete before Entra features can be used safely.
For SCIM, validate one Enterprise tenant end-to-end: connect, provision one user, update attributes, deactivate, verify public identity is inactive, reactivate with the same mapping, then rotate and revoke the token.
Explore the CardIQ Identity platform or review the workflow from verification through identity deactivation.
See how CardIQ Identity works View pricing