Identity integration overview
Choose an authentication and provisioning model without weakening Tenvyr's identity guarantees.
Tenvyr separates three jobs that are often bundled together:
- Authentication proves who is signing in. Use a local invitation or an OIDC provider such as Microsoft Entra ID.
- Provisioning supplies lifecycle state and group membership. Use SCIM 2.0 when your identity provider supports it.
- Authorization stays in Tenvyr. Tenant roles, access policies, host groups, approvals, and access reviews decide what a person may do.
An external identity provider does not replace Tenvyr MFA or recovery controls.
Recommended enterprise pattern
Use Entra OIDC and SCIM together:
Entra sign-in ──OIDC──▶ Tenvyr authentication
Entra lifecycle ─SCIM─▶ Tenvyr users and groups
Tenvyr policies ──────▶ SSH authorizationEnable first-sign-in provisioning only after SCIM users have stable external IDs and their Tenvyr roles are mapped. This gives new users a predictable path without permitting email-based account linking.
Identity linking is explicit
Tenvyr links an external identity by its provider and immutable subject—not by email address. Matching email addresses are not sufficient. This prevents an email reassignment or alias change from silently taking over an existing account.
If an invited account already exists, an administrator must use the explicit identity-linking workflow. Do not delete and recreate identities to work around a collision.
Choose the right setup
| Need | Configure |
|---|---|
| Workforce single sign-on | OIDC provider |
| Joiner, mover, and leaver automation | SCIM connector |
| Group-driven role assignment | SCIM groups plus Tenvyr role mappings |
| Local break-glass administration | A tightly controlled local owner account |
| Audit delivery | Signed SIEM webhook |
Start with one test user and one test group. Keep a local owner account available until OIDC, SCIM, and deprovisioning have all been tested end to end.