User Directory Integration

Learn how to configure user directory integrations.

Kandji lets you assign users to specific devices. To import users, you can connect multiple Google Workspace, Azure Active Directory (AD), or System for Cross-Domain Identity Management (SCIM) integrations.

This article covers adding Active Directory and Google Workspace user directories to Kandji. These native methods are simple to configure and require only a directory administrator account with access to the directory you are trying to integrate. After the initial user sync, Kandji will import users every four hours.

If you prefer user accounts be added and removed as they are created within your directory, use a SCIM integration. SCIM requires more upfront configuration but allows for Just-in-Time (JiT) account provisioning and de-provisioning. You can use SCIM with Azure Active Directory, Okta, and other directory systems that support it. Refer to SCIM Directory Integration for more information.

Add an Azure Active Directory Integration

  1. Navigate to Integrations in the left-hand navigation bar.
  2. Click Discover integrations in the upper-right of the Integrations page. 
  3. Under Directory integrations, click Add and configure under Azure Active Directory Directory.
  4. Click Get Started
  5. Enter a unique name, which will be used in Kandji to show the directory from which a user originates.
  6. Click Sign in with Azure.
  7. Sign in using an Azure account with admin access to the directory you want to integrate.
  8. Consent on behalf of your organization and click Accept. You will see the new user directory on the Integrations page.

    Active Directory integration@2x

Add a Google Workspace Integration

  1. Navigate to Integrations in the left-hand navigation bar.
  2. Click Discover integrations in the upper-right of the Integrations page. 
  3. Under Directory integrations, click Add and configure under Google Workspace.
  4. Click Get Started
  5. Enter a unique name; used in Kandji to show from which directory a user originates.
  6. Click Sign in with Google.
  7. Sign in using a Google account with admin access to the directory you want to integrate.
  8. Click Allow. You will see the new user directory on the Integrations page.

    Google workspace integration@2x

Add a SCIM Integration

If you prefer that user accounts should be added and removed as they are created within your directory, use a SCIM integration. Refer to SCIM Directory Integration for more information.

View Additional Information about a Directory Integration

  1. Click the ellipse on the Directory Integration you would like to view.
  2. Select View details.
    1. Azure Active Directory and Google Workspace integrations will show the administrator email account used to connect to the directory and the time of the last import.

      View AD integration details@2x edited
    2. SCIM integrations will show the Kandji email used to connect to the directory, the SCIM API URL, and the time of the last sync.

      View SCIM inegration details@2x edited

Force a User Directory Sync

Azure Active Directory and Google Workspace directories sync automatically every four hours, but you can force an immediate sync. It is not necessary to force-sync a SCIM directory integration. 

  1. Click the ellipse on the Directory Integration you would like to sync.
  2. Select Sync users.

    Sync Azure edited

Remove a Directory Integration

Removing the integration will remove users not assigned to devices from Kandji. Users assigned to devices will remain, but Kandji will no longer synchronize them with the directory.

  1. Click the ellipse on the Directory Integration you would like to delete.
  2. Select Delete integration.
  3. Confirm by typing the name of the integration.
  4.  Click Delete.
     
    Delete Azure edited