UniAsset
Home/Knowledge Base/Users & People/How to Auto-Deprovision Leavers via Entra ID
Back to Users & People

How to Auto-Deprovision Leavers via Entra ID

4 minIntermediateLast updated: January 2, 2026

How to auto-deprovision leavers via Entra ID

Auto-deprovisioning deactivates UniAsset accounts automatically when people leave your Microsoft Entra ID directory, so offboarding does not depend on someone remembering.

Requirements

  • Available on: Cosmos
  • Roles: Owner — the Integrations area is Owner-only
  • Prerequisite: Microsoft Entra ID must be connected. See Connecting Microsoft Entra ID.

Steps

  1. Sign in as the Owner.
  2. Go to Settings → Integrations → Microsoft Entra ID.
  3. Under Directory Sync Settings, switch Auto-deprovision sync to Enabled.

The sync runs at the next scheduled window.

How the sync works

A daily job runs for organizations with Entra configured. It:

  1. Reads your directory, refreshing the stored token if needed.
  2. Provisions new users from the configured groups, mapping groups to UniAsset roles. Each gets a Person created and linked.
  3. Deactivates users no longer present in the directory, if deprovisioning is enabled.
  4. Records the sync time.

Users who are not linked to a Microsoft account — those who signed up with an email and password, or with Google — are unaffected.

When deactivation takes effect

On the deactivated user's next request, not at their next sign-in.

Authorization is re-read from the database on every request, so someone who is deactivated mid-session loses access immediately rather than continuing until their session expires.

What deactivated means

A deactivated user:

  • Cannot use UniAsset — access ends immediately
  • Keeps their history — everything they did stays attributed to them
  • Keeps their Person record, so assignments and custody history survive
  • Frees a seat on your plan
  • Can be reactivated — see Reactivating users

Deactivation is not deletion. Nothing is lost.

Warning If you reactivate someone in UniAsset while they are still absent from your Entra directory, the next sync will deactivate them again. Restore them in Entra first.

Disabling auto-deprovisioning

Go to Settings → Integrations → Microsoft Entra ID and switch Auto-deprovision sync to Disabled.

Users already deactivated are not restored. It only stops future automatic deactivations.

Before you rely on it

Handle custody separately. Deactivating a user does not check in their outstanding checkouts or reassign their assets. Build that into your offboarding process — see Deactivating users.

The sync is daily, not instant. For an immediate revocation — a dismissal, a security incident — deactivate the user directly at Dashboard → Users.

Common mistakes

Treating the nightly sync as immediate revocation. For urgent cases, deactivate manually.

Assuming it reassigns their assets. It does not.

Enabling it before group mappings are configured. Get provisioning and role mapping right first.

Troubleshooting

The toggle isn't there. Directory sync needs Cosmos, and the Integrations area is Owner-only.

A leaver still has access. The sync runs daily. Deactivate them manually at Dashboard → Users if it is urgent.

Someone was deactivated who should not have been. They are not in the configured directory groups. Restore them in Entra, then reactivate in UniAsset.

Nobody is being deprovisioned. Confirm the toggle is enabled, the connection is healthy, and the affected users are actually linked to Microsoft accounts.

The connection shows as stale. Reconnect from the Entra page — the stored token may need refreshing.

Related articles

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support