Available on: the Enterprise planFind it in: Settings in the organization name menu at the top left of the screen > Organization > Enterprise SetupRequired role: Admin or custom
How Directory Sync works
Once you connect a directory, it provisions everyone it lists into your Profound organization:- Assignments grant access. When you connect a directory, everyone currently assigned to it is synced into your organization. After that, anyone your IdP assigns to Profound is provisioned automatically.
- Unassignments remove access. When your IdP unassigns or deactivates someone, their organization membership is removed and any pending invitation is revoked. Their Profound account itself isn’t deleted: if they belong to other Profound organizations, those are unaffected.
- New members start with the Member role. People provisioned through Directory Sync get the Member role, and organization Admins can change roles in Profound afterwards. If someone leaves the directory and is later reassigned, they return with the default Member role.
- Members outside the directory can lose access. When your IdP directory is the only membership source, any members you added manually on the People page who aren’t assigned in your directory lose access to your organization. To keep adding members from both sources, change the membership source setting.
How new members sign in
How a new member signs in for the first time depends on your Single Sign-On (SSO) setup:- With SSO enabled, their account is created and they sign in directly through your IdP. No invitation email is sent.
- Without SSO, they receive an email invitation to create a password. The invitation stays valid for 30 days.
You don’t need SSO to use Directory Sync. They are independent features: enable either one, or both.
Configure Directory Sync
To configure Directory Sync, you need the Admin role in your Profound organization and administrative access to your IdP.1
Locate the Directory Sync in ettings
- In Profound, select your organization name at the top left of the screen, then select Settings.
- Select Enterprise Setup under Organization in the left navigation sidebar. The Directory Sync card shows your current sync status.
2
Configure your membership source
Review Membership source on the Directory Sync card:
- Select the gear icon next to Membership source.
- To keep existing members who aren’t in your directory and continue inviting external users, choose Directory & external users.
- To allow only members from your IdP directory, select Directory only.
3
Open the Directory Sync configuration portal and follow the provider-specific instructions
On the Directory Sync card, select Configure Directory Sync to open the configuration portal.The portal tailors the setup to your directory provider, walking you through creating a SCIM integration in your IdP, connecting it to Profound, and choosing which people and groups to sync.
4
Test and verify
Use the portal’s test step to verify the directory connection. Once syncing is live, the Directory Sync card on the Enterprise Setup page shows Directory Sync Enabled and your current membership source. Select Check status to refresh, or Manage Directory Sync to reopen the configuration portal.
Membership source
The Membership source setting governs your Profound organization membership once the directory is connected:- Directory only (the default): your IdP manages all members. Anyone who isn’t assigned in your directory loses access to your organization, including members you added manually before connecting the directory. Inviting people in Profound is disabled.
- Directory & external users: your IdP still provisions and removes the people it lists, and Admins can also invite people outside your directory in Profound. Use this option when people who aren’t in your internal employee directory, such as agency partners or contractors, need a seat in your organization.
Change the membership source
Admins can change the membership source at any time as instructed in Step 2 of the setup guide. When a directory is connected, switching from Directory & external users to Directory only checks for external users. If any are found, the dialog shows how many may external users will lose access once the setting is changed.Before a directory is connected, the membership source setup dialog doesn’t show how many users are affected by the setting change. This does not mean that all existing members will retain access after you connect the directory. With Directory only any members outside the directory lose access.
Manage members with Directory Sync
Manage the members your directory lists through your IdP:- The People page shows a banner explaining that people are managed by your identity provider.
- With the Directory only membership source, adding members, removing members, and revoking invitations are disabled in Profound. Make these changes in your IdP’s directory instead.
- With the Directory & external users membership source, select Add External User on the People page to invite a user from outside your IdP directory. To invite several people at once, select Add another user or Import from CSV. Manage external users from the People page in Profound.
Admin failsafe
Directory Sync always keeps at least one Admin in your organization. If your directory unassigns the organization’s only Admin, that person keeps their access and role. This prevents a misconfiguration in your IdP, such as an incorrect group assignment, from locking everyone out of administering the organization. To remove your organization’s only Admin, first grant the Admin role to someone else. Once another Admin exists, the directory’s unassignment takes effect normally.Notes
- Directory Sync is configured per Profound organization: each organization needs its own Directory Sync connection and membership source.
- Contact customer support if you need help during setup.