User Directory Integration

Learn how to configure user directory integrations.

Kandji lets you assign users to specific devices. You can connect multiple Google Workspace, Azure Active Directory, or SCIM integrations in order to import your users. After the initial sync, new users will be imported from Google Workspace and Azure AD every four hours. 

Adding a New User Directory Integration

  1. Choose Settings in the left-hand navigation bar.
  2. Select the Integrations tab at the top. 

    CleanShot 2021-06-02 at 11.47.57@2x
  3. Under User Integration choose Add.

    CleanShot 2021-06-02 at 11.49.39 2@2x
  4. On the Add User Integration blade, select the directory service you want to integrate with. 
  5. Click Next.
     
    CleanShot 2021-06-02 at 11.53.44@2x
  6. For every user integration type, you will be required to give the user directory a name, which will be used to show which directory a user originates from.
  7. Click Next.

    CleanShot 2021-06-02 at 11.59.54@2x
  8. For both Azure Active Directory and Google Workspace, you will next be required to log in and authorize the integration. Once the connection is authorized you will be returned to the integrations page, and the new user directory will be in the list. 

    CleanShot 2021-06-02 at 13.04.40 2@2x
  9. For a SCIM connection, after specifying the user directory name you will be shown your SCIM API token and the base SCIM URL. Learn more about leveraging SCIM
    1. Copy the SCIM API token required to authenticate SCIM requests.
    2. Confirm that you have copied your SCIM API token.
    3. Copy the base SCIM API URL; this will be required by your identity provider.

      CleanShot 2021-06-02 at 13.11.12@2x-1

Removing a User Directory Integration

Removing the integration will remove users not assigned to devices from Kandji. Users currently assigned to devices will remain. 

  1. Select the More button next to an existing user directory. 
  2. From the More menu, click Delete.

    CleanShot 2021-06-02 at 13.18.02@2x

Forcing a User Directory Sync

When Azure Active Directory or Google Workspace integrations are configured, syncing automatically occurs every four hours. Forcing a sync is not possible with SCIM, as the identity provider initiates communication for a SCIM sync. 

  1. Select the More button next to an existing user directory. 
  2. From the More menu, choose Sync Now. The sync will start immediately.

    CleanShot 2021-06-02 at 13.23.42@2x

View Additional Information about a User Directory

By clicking View, you can access additional information about a user directory integration.

  1. Select the More button next to an existing user directory. 
  2. From the More menu choose View.
CleanShot 2021-06-02 at 13.25.56@2x
Google Workspace or Azure Active Directory
For a Google Workspace or Azure Active Directory integration, you will see the following additional information. The email listed is the Google Workspace admin account that was used to connect the directory.

CleanShot 2021-06-02 at 13.26.15@2x

SCIM 
For a SCIM-based integration, you will see the following additional information. The email listed is the Kandji admin account that was used to connect the directory. You will additionally find the base SCIM URL. 

CleanShot 2021-06-02 at 13.26.32@2x-1