How to auto-provision users from Entra ID
Auto-provisioning lets anyone with an email address on your verified Entra ID domain sign in to UniAsset without being individually invited. The first time they sign in with Microsoft, their account is created automatically.
Requirements
- Available on: Cosmos
- Roles: Owner — the Integrations area is Owner-only
- Prerequisite: Microsoft Entra ID must be connected first. See Connecting Microsoft Entra ID.
How Auto-Provisioning Works
When auto-provisioning is enabled:
- A user from your organization visits the UniAsset login page
- They click Continue with Microsoft and sign in with their work account
- UniAsset checks that their email domain matches your verified Entra domain
- If it matches and they don't already have a UniAsset account, one is created automatically
- They are signed in and assigned a role
Without auto-provisioning, users must receive an individual invitation before they can access UniAsset.
Enabling Auto-Provisioning
- Sign in as the Owner.
- Go to Settings → Integrations.
- Open Microsoft Entra ID.
- Under Directory Sync Settings, switch Auto-provision users to Enabled.
Auto-provisioning takes effect immediately.
Default Role for Auto-Provisioned Users
Auto-provisioned users are assigned the Employee role by default.
💡 TIP: If you have Group → Role Mapping configured, group membership takes precedence over the default role. A user whose Entra groups match a mapping will receive the mapped role at sign-in instead of the Employee default.
When Not to Enable Auto-Provisioning
Auto-provisioning is the right choice when you want frictionless onboarding for a large or frequently changing team.
Consider keeping it off if:
- You want to control exactly which individuals can access UniAsset, regardless of their domain
- You are running a multi-tenant or shared-domain environment where not all users on the domain should have access
- You prefer to use manual invitations to assign specific roles to each person before they sign in
When auto-provisioning is off, only users you have explicitly invited can join your organization.
Disabling Auto-Provisioning
- Go to Settings → Integrations → Microsoft Entra ID.
- Switch Auto-provision users to Disabled.
Disabling does not remove users who were already provisioned. It only stops new accounts being created automatically.
Watch your user limit
Auto-provisioned users are real users and count toward your plan's user limit. Cosmos has unlimited users, so this is normally not a concern — but if your organization is on a plan with a seat limit, provisioning is still bounded by it.
Common mistakes
Enabling it on a shared domain. If not everyone on the domain should have access, keep it off and invite individually.
Relying on the default role for everyone. Set up group-to-role mapping so people arrive with the right permissions rather than needing to be adjusted afterwards.
Troubleshooting
The toggle isn't there. Directory sync needs Cosmos, and the Integrations area is Owner-only.
A user on our domain still can't sign in. Confirm Entra is connected, the domain is the verified one, and auto-provisioning is enabled.
They signed in but with the wrong role. Check your group-to-role mappings. Group membership takes precedence over the default role.
Someone outside our domain got in. Auto-provisioning only matches the verified Entra domain. Anyone else must have been invited.
Related articles
Need Help?
If you have questions not covered in this article, our support team is here to help.
Contact Support