# Provision users with SCIM (Okta, Microsoft Entra)

**Category:** [Employee Directory](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/employee-directory)
**Updated:** 2026-08-19

Connect your identity provider so users are created, updated, and deactivated in the directory automatically — no manual upkeep.
## How it works

TotalCtrl is a **SCIM 2.0 provisioning target**. Your IdP (Okta, Microsoft Entra) pushes user and group changes to TotalCtrl over a secure, token-authenticated endpoint.
## Set it up

- In the directory, open *Integrations* and generate a **SCIM bearer token**. Copy it — it's shown only once.
- Copy the **SCIM Base URL** shown on the same page.
- In your IdP, add TotalCtrl as a SCIM app: paste the base URL and the bearer token.
- Map attributes (name, email, title, department, manager) and enable provisioning.

## What syncs

New users are created as active employees; updates change their details; deactivation in your IdP disables them in the directory. Groups map to departments. Tokens can be revoked at any time from *Integrations*.

---

## Related Articles

- [Employee Directory overview](https://help.totalctrl.app/en-US/articles/employee-directory-overview)
- [Profiles and self-service editing](https://help.totalctrl.app/en-US/articles/profiles-and-self-service)
- [API, webhooks, and AI tools](https://help.totalctrl.app/en-US/articles/directory-integrations)
- [The org chart](https://help.totalctrl.app/en-US/articles/directory-org-chart)
- [Sync your HRIS (BambooHR)](https://help.totalctrl.app/en-US/articles/hris-sync)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)