TVTenvyrDocs
Identity & integrations

Identity integration overview

Choose an authentication and provisioning model without weakening Tenvyr's identity guarantees.

Tenvyr separates three jobs that are often bundled together:

  1. Authentication proves who is signing in. Use a local invitation or an OIDC provider such as Microsoft Entra ID.
  2. Provisioning supplies lifecycle state and group membership. Use SCIM 2.0 when your identity provider supports it.
  3. Authorization stays in Tenvyr. Tenant roles, access policies, host groups, approvals, and access reviews decide what a person may do.

An external identity provider does not replace Tenvyr MFA or recovery controls.

Use Entra OIDC and SCIM together:

Entra sign-in ──OIDC──▶ Tenvyr authentication
Entra lifecycle ─SCIM─▶ Tenvyr users and groups
Tenvyr policies ──────▶ SSH authorization

Enable first-sign-in provisioning only after SCIM users have stable external IDs and their Tenvyr roles are mapped. This gives new users a predictable path without permitting email-based account linking.

Identity linking is explicit

Tenvyr links an external identity by its provider and immutable subject—not by email address. Matching email addresses are not sufficient. This prevents an email reassignment or alias change from silently taking over an existing account.

If an invited account already exists, an administrator must use the explicit identity-linking workflow. Do not delete and recreate identities to work around a collision.

Choose the right setup

NeedConfigure
Workforce single sign-onOIDC provider
Joiner, mover, and leaver automationSCIM connector
Group-driven role assignmentSCIM groups plus Tenvyr role mappings
Local break-glass administrationA tightly controlled local owner account
Audit deliverySigned SIEM webhook

Start with one test user and one test group. Keep a local owner account available until OIDC, SCIM, and deprovisioning have all been tested end to end.

On this page