Home/Knowledge Base/Users & Permissions/Auto-Provisioning Users from Entra ID
Back to Users & Permissions

Auto-Provisioning Users from Entra ID

4 min readintermediateLast updated: January 2, 2026

Overview

Auto-provisioning allows any user with an email address on your verified Entra ID domain to sign in to UniAsset without being individually invited. When they sign in with Microsoft for the first time, UniAsset creates their account automatically.

Plan required: Enterprise

Prerequisite: Microsoft Entra ID must be connected first. See Connecting Microsoft Entra ID.

Who Can Access This

Required role: Owner or Admin

How Auto-Provisioning Works

When auto-provisioning is enabled:

  1. A user from your organization visits the UniAsset login page
  2. They click Continue with Microsoft and sign in with their work account
  3. UniAsset checks that their email domain matches your verified Entra domain
  4. If it matches and they don't already have a UniAsset account, one is created automatically
  5. They are signed in and assigned a role

Without auto-provisioning, users must receive an individual invitation before they can access UniAsset.

Enabling Auto-Provisioning

  1. Log in to UniAsset as an Owner or Admin
  2. Click Settings in the left sidebar
  3. Select the Integrations tab
  4. Click Microsoft Entra ID
  5. Toggle Auto-provision users to on
  6. Click Save

Auto-provisioning takes effect immediately.

Default Role for Auto-Provisioned Users

Auto-provisioned users are assigned the Employee role by default.

💡 TIP: If you have Group → Role Mapping configured, group membership takes precedence over the default role. A user whose Entra groups match a mapping will receive the mapped role at sign-in instead of the Employee default.

When Not to Enable Auto-Provisioning

Auto-provisioning is the right choice when you want frictionless onboarding for a large or frequently changing team.

Consider keeping it off if:

  • You want to control exactly which individuals can access UniAsset, regardless of their domain
  • You are running a multi-tenant or shared-domain environment where not all users on the domain should have access
  • You prefer to use manual invitations to assign specific roles to each person before they sign in

When auto-provisioning is off, only users you have explicitly invited can join your organization.

Disabling Auto-Provisioning

  1. Go to Settings → Integrations → Microsoft Entra ID
  2. Toggle Auto-provision users to off
  3. Click Save

Disabling auto-provisioning does not remove existing auto-provisioned users. It only prevents new users from being created automatically going forward.

Related Articles

Need Help?

Contact support at support@uniasset.app with questions about auto-provisioning.

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support