Skip to main content
Identity Provisioning Hero

Your Directory Is the Source of Truth for WiFi Access

Sync users and groups from Microsoft Entra ID and Okta over SCIM 2.0, or from Google Workspace with the directory connector. When someone is deactivated in Okta over SCIM, IronWiFi disables the user. Deactivating a user in your directory does not revoke their device certificates or disconnect a session that is already connected, and it may not stop their devices from signing in again.

Securing WiFi networks worldwide since 2014

IronWiFi keeps WiFi access in step with your directory. SCIM 2.0 provisioning is available now for Microsoft Entra ID and Okta; Google Workspace users and groups sync through IronWiFi's Google Workspace directory connector, because Google does not support outbound SCIM. When employees join, their WiFi access is provisioned with group-based policies. SCIM deactivation disables the user in IronWiFi. Deactivating a user in your directory does not revoke their device certificates or disconnect a session that is already connected, and it may not stop their devices from signing in again. It also does not remove devices. Revoke certificates, remove devices and end live sessions on supported controllers in the IronWiFi console as part of your offboarding process. Also remove the device from your MDM so it does not request a new certificate. Suspending or deleting a user in Google Workspace does not currently disable them in IronWiFi, and it doesn't revoke certificates or end a live session. Confirm the user is disabled in IronWiFi, use Disable & Revoke Certs, and check the authentication logs before treating WiFi access as cut off.

Identity-Driven WiFi Access Control

Six capabilities that keep your WiFi access in step with your directory

Microsoft Entra ID Sync

User and group provisioning from Microsoft Entra ID over SCIM 2.0, set up as a non-gallery enterprise app. Users and groups sync on Entra's provisioning cycle - no manual imports or CSV uploads. Microsoft Entra ID: a known issue can currently undo deactivations sent in Entra's default format, so they may not take effect today. Until it is fixed, confirm the user shows as disabled in IronWiFi, use Disable & Revoke Certs and check the authentication logs for leavers.

  • SCIM 2.0 push from Entra provisioning
  • User & group sync
  • Works with Entra Conditional Access at Microsoft sign-in

Okta Integration

SCIM 2.0 push from Okta through a custom app integration you create with a bearer token from the IronWiFi console.

  • SCIM 2.0 push
  • Group push and mapping
  • Custom app integration setup
  • Profile attribute sync

Google Workspace Sync

Google Workspace does not support outbound SCIM, so IronWiFi pulls users and groups through its Google Workspace directory connector. Suspending or deleting a user in Google Workspace does not currently disable them in IronWiFi, and it doesn't revoke certificates or end a live session. Confirm the user is disabled in IronWiFi, use Disable & Revoke Certs, and check the authentication logs before treating WiFi access as cut off.

  • Directory connector (not SCIM)
  • User and group sync
  • Suspending or deleting a user in Google Workspace does not currently disable them in IronWiFi, and it doesn't revoke certificates or end a live session. Confirm the user is disabled in IronWiFi, use Disable & Revoke Certs, and check the authentication logs before treating WiFi access as cut off.
  • Sync Now on demand

Deactivation via SCIM

SCIM deactivation disables the user in IronWiFi. Deactivating a user in your directory does not revoke their device certificates or disconnect a session that is already connected, and it may not stop their devices from signing in again. It also does not remove devices. Certificate logins where the device sends a different identity than the username are not blocked by SCIM deactivation alone. Microsoft Entra ID: a known issue can currently undo deactivations sent in Entra's default format, so they may not take effect today. Until it is fixed, confirm the user shows as disabled in IronWiFi, use Disable & Revoke Certs and check the authentication logs for leavers.

  • User deactivation via SCIM
  • Certificates and sessions: separate admin steps
  • Group membership kept in step
  • Disable & Revoke Certs in the console

Group-Based Policies

Map directory groups to IronWiFi groups that set VLAN and bandwidth limits (where your AP or switch supports it); add time-of-day rules with the policy engine.

  • Group-to-VLAN mapping
  • Group bandwidth limits, where your AP or switch supports it
  • Time-of-day rules in the policy engine
  • Group changes apply at next login

Provisioning Activity

See recently added and deactivated users, check SCIM token health, and export a user CSV for a date range.

  • Recently added and deactivated users
  • SCIM token health (last sync seen)
  • CSV export of provisioned users

MSP-ready: each customer tenant gets its own SCIM token and isolated users.

What Happens When Someone Leaves

How directory deactivation flows through to WiFi access

1

Employee Leaves

HR starts offboarding in your identity provider.

2

IdP Disables Account

The user account is deactivated in your identity provider, for example Okta.

3

Change Reaches IronWiFi

Okta and Entra ID send the change over SCIM on their provisioning cycle. Microsoft Entra ID: a known issue can currently undo deactivations sent in Entra's default format, so they may not take effect today. Until it is fixed, confirm the user shows as disabled in IronWiFi, use Disable & Revoke Certs and check the authentication logs for leavers. Suspending or deleting a user in Google Workspace does not currently disable them in IronWiFi, and it doesn't revoke certificates or end a live session. Confirm the user is disabled in IronWiFi, use Disable & Revoke Certs, and check the authentication logs before treating WiFi access as cut off.

4

User Disabled in IronWiFi

IronWiFi disables the user. Deactivating a user in your directory does not revoke their device certificates or disconnect a session that is already connected, and it may not stop their devices from signing in again.

5

Clean Up Certificates and Devices

Revoke the user's certificates (Disable & Revoke Certs), remove their registered devices and, on controllers that support it, disconnect live sessions in the IronWiFi console as part of your offboarding checklist. Also remove the device from your MDM so it does not request a new certificate. SCIM does not do these steps.

Close the Zombie-Account Gap

WiFi accounts that outlive the people they belong to are a common gap. Directory sync narrows it: every user account in your directory maps to the right level of WiFi access, and a deactivated user is disabled in IronWiFi. That may not stop their devices from signing in again, so revoke their certificates, remove their devices and check the authentication logs as part of offboarding.

Frequently Asked Questions

What is SCIM provisioning?

SCIM 2.0 (System for Cross-domain Identity Management) is a standard protocol that syncs user and group data from your identity provider to IronWiFi. When you add, update or deactivate a user in your IdP, the IdP sends the change to IronWiFi without manual imports.

Which identity providers do you support?

SCIM 2.0 provisioning is available now for Microsoft Entra ID (set up as a non-gallery enterprise app) and Okta (set up as a custom app integration). Google Workspace does not support outbound SCIM, so Google users and groups sync through IronWiFi's Google Workspace directory connector instead.

What happens when a user is offboarded?

SCIM deactivation disables the user in IronWiFi. Deactivating a user in your directory does not revoke their device certificates or disconnect a session that is already connected, and it may not stop their devices from signing in again. It also does not remove devices. Do these steps in the IronWiFi console as part of your offboarding checklist: Disable & Revoke Certs on the user, remove registered devices and, on supported controllers, Disconnect live sessions. Also remove the device from your MDM so it does not request a new certificate. Certificate logins where the device sends a different identity than the username are not blocked by SCIM deactivation alone. Microsoft Entra ID: a known issue can currently undo deactivations sent in Entra's default format, so they may not take effect today. Until it is fixed, confirm the user shows as disabled in IronWiFi, use Disable & Revoke Certs and check the authentication logs for leavers. Suspending or deleting a user in Google Workspace does not currently disable them in IronWiFi, and it doesn't revoke certificates or end a live session. Confirm the user is disabled in IronWiFi, use Disable & Revoke Certs, and check the authentication logs before treating WiFi access as cut off.

How often does sync happen?

SCIM changes arrive on your identity provider's provisioning schedule. Microsoft Entra ID, for example, provisions in cycles rather than instantly. Google Workspace changes arrive on the connector's next sync, and you can also run Sync Now on demand. Suspending or deleting a user in Google Workspace does not currently disable them in IronWiFi, and it doesn't revoke certificates or end a live session. Confirm the user is disabled in IronWiFi, use Disable & Revoke Certs, and check the authentication logs before treating WiFi access as cut off.

Microsoft Entra ID, Okta and Google Workspace are trademarks of their respective owners. They are named to describe compatibility only and do not imply affiliation, endorsement or a certified integration.

Talk to a WiFi Identity Specialist

  • See IronWiFi working with your hardware
  • Get a deployment plan for your network
  • Answers by email - no pitch deck

Step-by-step setup guides for Entra ID, Okta and Google Workspace