Skip to main content
All CollectionsBusiness HubsManaging users via an IdP and business hub
Deprovision users from your apps via an IdP and business hub

Deprovision users from your apps via an IdP and business hub

This article describes how to deprovision users from your external seat-based and paid social apps via an IdP and business hub.

Cerby Team avatar
Written by Cerby Team
Updated over 2 weeks ago

Who can use this feature?

  • IT admins with a tenant in an identity provider

  • Business hub Owners

  • Only supported using the Cerby web app

As an IT admin collaborating with a business hub Owner, you can deprovision users from your external seat-based and paid social apps via your identity provider (IdP), such as Okta or Entra ID, and a business hub.

For this identity lifecycle management functionality to work, Cerby leverages user and group deprovisioning from the IdP to update Cerby teams. These teams must have shared access to a business hub integration with specific roles or permissions both in Cerby and the external app, including assets if supported, as shown in Figure 1.

Diagram of a Cerby business integration leveraging identity provider groups. The diagram shows the multiple systems involved, such as the identity provider, Cerby, and the external app, and the components, such as users, groups, teams, the business hub integration, and the remove user management task

Figure 1. User deprovisioning in external apps from IdP events

With this approach, any user removed from a group or deactivated or deleted while being assigned to a group is automatically deprovisioned from the corresponding Cerby team. Given that the team already has access to the business hub, Cerby detects the IdP event and takes action as follows:

  • Cerby triggers automated tasks to remove these users from the external app.

  • For users removed from an IdP group, Cerby identifies if they have shared access to the business hub integration whether individually or through another team, and determines their role. Based on all their existing access grants, users get the highest role, so if needed, Cerby triggers an automated task to update their role in the external app.


Requirements

The following are the requirements to deprovision users from your external apps via your IdP and business hub:


Deprovision users from your apps via your IdP and business hub

To deprovision users from your external apps via your IdP and business hub, you must complete the following steps:

  1. Log in to the IdP admin console or center of your organization.

  2. Perform any of the following actions. For instructions, read the official documentation of your IdP:

    Given that IdP users and groups are automatically deprovisioned from your Cerby workspace, any the following actions happens depending on whether users have shared access to the business hub integration individually or through another team with the same or lower role:

    • Cerby triggers the automated tasks to remove the users from the external app.

    • Cerby keeps access for the users with the same role.

    • Cerby triggers the automated tasks to update the user roles in the external app, including assets if supported.

    TIP: You can view the progress of the automated tasks in the Automation page.

Now you are done.

Did this answer your question?