# Setting up SSO and SCIM provisioning for Genesys Cloud

Systems: Genesys Cloud

For A Genesys Cloud administrator working with an identity administrator to set up SAML single sign-on, and optionally SCIM provisioning, for a contact center org.

Canonical: https://warmtransfer.net/guides/genesys-cloud-sso-scim-setup

Last verified: 2026-10-01

Genesys Cloud creates a single sign-on integration under Menu > IT and Integrations > Single Sign-on > Add an Identity Provider, and Genesys lists Microsoft Entra ID and Okta among the identity management systems known to work with its SCIM implementation[^63][^58]. Genesys states that Entra provisioning can create, update and delete Genesys Cloud users, the Okta Genesys Cloud SCIM app supports Create Users, Update User Attributes and Deactivate Users, and an org can disable Genesys Cloud login so that all users sign in by SSO[^44][^39][^70][^69].

## Before you start

- Adding an SSO provider in Genesys Cloud requires Single Sign-on > Provider > Add, Delete, Edit and View permissions, an admin role in the identity provider, and a single email address shared by each person's identity provider account and their Genesys Cloud user[^75].
- Configuring the Genesys Cloud for Azure app in Entra ID requires the Application Administrator, Cloud Application Administrator or Application Owner role[^17].
- The Genesys Cloud for Azure gallery app uses a fixed identifier string, so only 1 instance of it can be configured for SSO in an Entra tenant; check whether your tenant already has one[^15].
- Granting roles through a Genesys group needs Directory Group Add and Edit, Authorization Grant Add and Role View permissions[^23].
- If you will use SCIM, you must hold the SCIM Integration role yourself in order to grant it to the OAuth client[^32].
- Record your org's region: the Entra SAML Identifier and Reply URL use the regional Genesys login host plus /saml, for example https://login.mypurecloud.com/saml, https://login.mypurecloud.ie/saml or https://login.mypurecloud.de/saml[^12].
- With SCIM, also record the regional API domain, for example api.mypurecloud.com (US East), api.mypurecloud.ie (Dublin), api.mypurecloud.de (Frankfurt) or api.euw2.pure.cloud (London)[^59].
- Inventory your existing SSO integrations, because Genesys Cloud allows up to 30 of them, with the same or mixed identity providers, and only 6 appear directly on the login page[^77].
- If you may disable Genesys Cloud login, find out whether you use webhooks for chat notification integrations, because Genesys warns that this feature needs password-based authentication[^73].
- See also [Identity SSO and directory provisioning for UC](https://warmtransfer.net/knowledge/identity-sso-provisioning) and [Genesys Cloud licensing](https://warmtransfer.net/knowledge/genesys-cloud-licensing).

## What changes by situation

- Which identity provider issues the SAML assertions and, if you use SCIM, runs provisioning? Microsoft Entra ID; Okta.
- Do you want single sign-on only, or single sign-on with SCIM provisioning? SSO only, with users created and maintained by hand in Genesys Cloud; SSO with SCIM, so the identity provider creates and updates Genesys Cloud users.
- With SCIM, how do users get their Genesys Cloud roles and divisions? (If you chose SSO only, any answer leads to the same manual path.) Granted in Genesys Cloud; SCIM carries identity and contact attributes only; SCIM sends the role and the division as user attributes; SCIM syncs group membership into Genesys groups that carry roles and divisions.
- Do you disable Genesys Cloud passwords once single sign-on works? Yes, disable Genesys Cloud login so users sign in by SSO only; No, keep Genesys Cloud credentials available alongside SSO.

## Step 1: Confirm access and your region

**Microsoft Entra ID**

### Do
- Confirm that your Genesys Cloud role grants Single Sign-on > Provider > Add, Delete, Edit and View permissions[^75].
- Confirm that your Entra account holds the Application Administrator, Cloud Application Administrator or Application Owner role[^17].
- Confirm that each person uses one email address in both Entra ID and Genesys Cloud[^75].
- Note the regional login host that the SAML URLs will use, for example https://login.mypurecloud.com/saml[^12].
- If you chose SCIM, note the regional API domain that forms the SCIM endpoint https://{domain}/api/v2/scim/v2/[^59].
### Verify
- The Genesys integration page is at Menu > IT and Integrations > Single Sign-on, and the Entra app list is at Entra ID > Enterprise apps[^63][^3].
- Suggested check: open both administration pages with the accounts you will use and confirm that each one loads.

**Okta**

### Do
- Confirm that your Genesys Cloud role grants Single Sign-on > Provider > Add, Delete, Edit and View permissions[^75].
- Confirm that you hold an admin role in Okta, since Genesys requires an admin role in the identity provider[^75].
- Confirm that each person uses one email address in both Okta and Genesys Cloud[^75].
- If you chose SCIM, note the regional domain, for example api.mypurecloud.com (US East) or api.euw2.pure.cloud (London), because Okta asks for the regional SCIM Domain[^59][^37].
### Verify
- The Genesys integration page is at Menu > IT and Integrations > Single Sign-on[^63].
- Suggested check: open both administration consoles with the accounts you will use and confirm that each one loads.

## Step 2: Add the Genesys Cloud application in the identity provider

**Microsoft Entra ID**

### Do
- In Entra ID, go to Enterprise apps > New application, search the gallery for Genesys Cloud for Azure, and add it[^3].
- Only 1 instance of this app can be configured for SSO in the tenant, because it uses a fixed identifier string[^15].
- If you chose SCIM, note that Microsoft says the same app can carry provisioning but recommends a separate app when you first test the provisioning integration[^13].
### Verify
- Suggested check: confirm that the new application appears in the enterprise applications list.
### Rollback
- Suggested rollback: delete the new enterprise application; nothing has changed on the contact center side yet.

**Okta**

### Do
- Add the Genesys Cloud app from the Okta Integration Network, and under Sign On settings set Application username format to Email[^38].
### Verify
- Suggested check: confirm that the application is listed and that its username format shows email.
### Rollback
- Suggested rollback: remove the application from the identity provider; nothing has changed on the contact center side yet.

## Step 3: Configure SAML in the identity provider

**Microsoft Entra ID**

### Do
- In the app's Basic SAML Configuration, set both Identifier and Reply URL to your region's Genesys login host plus /saml, for example https://login.mypurecloud.com/saml[^12].
- For SP-initiated sign-in, set Sign-on URL to the regional login host without a path, for example https://login.mypurecloud.com[^14].
- Keep the pre-populated Email attribute (source user.userprincipalname) and set OrganizationName to your organization name[^2].
- Enter OrganizationName exactly, because Genesys treats it as case-sensitive, reads it as the org short name for IdP-initiated sign-in, and requires it to match the selected org for SP-initiated sign-in[^74].
- From the SAML Signing Certificate section download Certificate (Base64), and from the Set up section copy the Login URL and the Microsoft Entra Identifier[^1].
### Verify
- Suggested check: reopen the SAML configuration and confirm that the identifier, reply and sign-on values all use your region's login host.
- Suggested check: confirm that the attribute list shows both the email and organization name attributes.
### Rollback
- Suggested rollback: clear or correct the SAML settings on the application.

**Okta**

### Do
- Obtain the SAML metadata file for the Genesys Cloud app from Okta, because importing the identity provider's metadata file into Genesys Cloud populates the required fields and signing certificate[^63].
- If you send an OrganizationName attribute, enter it exactly, because Genesys treats it as case-sensitive, reads it as the org short name for IdP-initiated sign-in, and requires it to match the selected org for SP-initiated sign-in[^74].
### Verify
- Suggested check: confirm that you hold a metadata file for this application before moving on.
### Rollback
- Suggested rollback: revert the SAML settings on the application.

## Step 4: Create the SSO integration in Genesys Cloud

**Microsoft Entra ID**

### Do
- Go to Menu > IT and Integrations > Single Sign-on > Add an Identity Provider[^63].
- If you have the identity provider's SAML metadata file, import it, which populates the required fields and the signing certificate[^63].
- Otherwise, fill in the form, which holds Issuer URI, Single Sign-On URI and binding, optional request signing, Single Logout URI and binding, Name Identifier Format, and a ForceAuthn-on-inactivity option[^66].
- For reference, Microsoft's tutorial maps the Entra values into a Genesys ADFS/Azure AD(Premium) tab: the certificate to ADFS Certificate, the Microsoft Entra Identifier to ADFS Issuer URI, the Login URL to Target URI, and the app's Application ID to Relying Party Identifier[^6].
- Set Name Identifier Format, choosing Unspecified if you do not know it[^66].
- Save, then use Download Metadata to get the Genesys service provider metadata, which contains the Issuer URI, Assertion Consumer Service and Single Logout URI for the identity provider[^64].
### Verify
- The Single Sign-on page shows each configuration's signing certificates with their expiration dates[^65].
- Suggested check: confirm that the new integration is listed and that its certificate expiry date is in the future.
### Rollback
- Suggested rollback: delete the new integration from the single sign-on page.
- While Genesys Cloud login is disabled, admins cannot delete every SSO provider[^69].

**Okta**

### Do
- Go to Menu > IT and Integrations > Single Sign-on > Add an Identity Provider[^63].
- Import the Okta SAML metadata file, which populates the required fields and the signing certificate[^63].
- Set Name Identifier Format, choosing Unspecified if you do not know it[^66].
- Save, then use Download Metadata to get the Genesys service provider metadata (Issuer URI, Assertion Consumer Service and Single Logout URI) and load it into Okta[^64].
### Verify
- The Single Sign-on page shows each configuration's signing certificates with their expiration dates[^65].
- Suggested check: confirm that the new integration is listed and that its certificate expiry date is in the future.
### Rollback
- Suggested rollback: delete the new integration from the single sign-on page.
- While Genesys Cloud login is disabled, admins cannot delete every SSO provider[^69].

## Step 5: Create users, or connect SCIM provisioning

**Microsoft Entra ID + SSO only, with users created and maintained by hand in Genesys Cloud**

### Do
- Create each user in Genesys Cloud with Add Person, giving a full name and email, because Entra users must already exist as Genesys Cloud users before they can sign in[^20].
- Use the same email address that the person's Entra account uses[^75].
### Verify
- Suggested check: open the people list and confirm that each pilot user exists with the expected email address.
### Rollback
- Suggested rollback: deactivate the users you added for testing.

**Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Go to Menu > IT and Integrations > OAuth, add a client with grant type Client Credentials, and assign only the SCIM Integration role[^30].
- Include every division that SCIM will manage when you assign the role, because client credentials roles default to the Home division[^31].
- If the SCIM Integration role is missing, restore the default roles with POST /api/v2/authorization/roles/default[^32].
- Set the token duration, which defaults to 86,400 seconds and can be set up to 38,880,000 seconds (450 days) with the SCIM Integration role[^33].
- Copy the client secret now, because it can be viewed only once at setup[^34].
- Generate the bearer token by calling your region's login URL /oauth/token with the client ID and secret, as Genesys documents with its Postman collection[^60].
- On the Entra app's Provisioning tab, set Provisioning Mode to Automatic, set Tenant URL to https://{domain}/api/v2/scim/v2/ and Secret Token to the bearer token, run Test Connection, and save[^50][^59][^8].
- Leave Provisioning Status off for now, because Microsoft advises validating with on-demand provisioning for a few users before you select Start Provisioning[^18].
- In the provisioning Properties, enable notification emails for quarantine and accidental deletions prevention, as Microsoft's steps say[^11].
- Keep the required mappings: userPrincipalName to userName, which generates the Genesys user's main email address, and Not([IsSoftDeleted]) to active[^62][^42].
- Keep userName as the matching attribute, since it is the only one supported for filtering, and keep displayName, because userName, active and displayName are all required by Genesys Cloud[^7].
- Do not rely on name.givenName, name.familyName or the address fields, which Genesys Cloud SCIM does not currently support[^52].
- If users sign in with a non-email identifier, map that identifier to the Genesys externalIds extension keyed on the identity provider's Issuer URI[^68].
### Verify
- Test Connection checks connectivity to the Genesys SCIM endpoint[^8].
- Suggested check: confirm that the connection test reports success and that the mapping list shows the user name as the matching attribute.
### Rollback
- With Entra ID, mapping a previously synced field to an empty value does not clear it in Genesys Cloud[^43].
- If the client secret is exposed, Generate new secret issues a new one[^34].
- Suggested rollback: clear the provisioning credentials on the application and delete the OAuth client you created.

**Okta + SSO only, with users created and maintained by hand in Genesys Cloud**

### Do
- Create each person's Genesys Cloud user with the email address that their Okta account uses, because Genesys requires a single email address shared by the identity provider account and Genesys Cloud[^75].
### Verify
- Suggested check: open the people list and confirm that each pilot user exists with the expected email address.
### Rollback
- Suggested rollback: deactivate the users you added for testing.

**Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Go to Menu > IT and Integrations > OAuth, add a client with grant type Client Credentials, and assign only the SCIM Integration role[^30].
- Include every division that SCIM will manage when you assign the role, because client credentials roles default to the Home division[^31].
- If the SCIM Integration role is missing, restore the default roles with POST /api/v2/authorization/roles/default[^32].
- Set the token duration, which defaults to 86,400 seconds and can be set up to 38,880,000 seconds (450 days) with the SCIM Integration role[^33].
- Copy the client secret now, because it can be viewed only once at setup[^34].
- Generate the bearer token by calling your region's login URL /oauth/token with the client ID and secret, as Genesys documents with its Postman collection[^60].
- In Okta, under Provisioning > Integration, enter the regional SCIM Domain and the bearer token as API Token, select Test API Credentials, then Save[^37].
- Under To App, enable the features you need from Create Users, Update User Attributes, Deactivate Users, Sync Password and Push Groups, each of which is optional[^39].
- Decide on Sync Password with your password decision in mind: Sync Password creates a password for each user and pushes it to Genesys Cloud, while with Genesys Cloud login disabled all users must sign in by SSO[^35][^69].
- Store Okta phone numbers in E.164, because Genesys converts phone numbers from Okta to E.164 and other formats cause continual updates[^36].
- Do not rely on name.givenName, name.familyName or the address fields, which Genesys Cloud SCIM does not currently support; the display name comes from displayName[^52].
### Verify
- Suggested check: confirm that the credentials test reports success and that only the provisioning features you chose are enabled.
### Rollback
- If the client secret is exposed, Generate new secret issues a new one[^34].
- Suggested rollback: turn off the provisioning features, clear the integration credentials, and delete the OAuth client you created.

## Step 6: Prepare how roles and divisions reach users

**SCIM sends the role and the division as user attributes + Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Create the target divisions in Genesys Cloud first, because the division value must match an existing division name or be blank[^46].
- Map the division attribute, which Genesys writes to the user's divisionId[^47].
- Confirm that the OAuth client you created includes every division that SCIM will manage[^31].
- In Entra, create an app role for the Genesys role, assign it to the user, and map SingleAppRoleAssignment([appRoleAssignments]) to roles[primary eq "True"].value[^55].
- Genesys maps the SCIM roles.[].value field to the user roles API, so the role values you send become Genesys role assignments[^56].
### Verify
- Suggested check: after the pilot run, confirm that each pilot user's role and division match the values sent from the identity provider.
### Rollback
- Mapping a previously synced field to an empty value does not clear it in Genesys Cloud[^43].
- Suggested rollback: remove the role and division mappings, then correct the affected users' roles and divisions by hand.

**SCIM syncs group membership into Genesys groups that carry roles and divisions + Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Create one general group per access profile under Menu > User Management > Groups, with Visibility set to Public[^25].
- Name each group identically to its Entra group, because groups must be created in Genesys Cloud first with identical names[^4].
- Genesys SCIM supports only public groups, matches names case-insensitively, and cannot create or delete groups[^54].
- On each group's Roles tab, select Assign Roles, enable the role and choose its divisions[^23].
- Use no membership rules on these groups, because roles cannot be assigned to a group that has them[^24].
### Verify
- A role assigned on a group's Roles tab is granted to every current and future member[^21].
- Suggested check: after the pilot run, confirm that members show the group's roles as inherited.
### Rollback
- A group-granted role is removed from a user when they leave the group[^21].
- Suggested rollback: remove the roles from the group before you delete or rename it.

**SCIM sends the role and the division as user attributes + Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Create the target divisions in Genesys Cloud first, because the division value must match an existing division name or be blank[^46].
- Confirm that the OAuth client you created includes every division that SCIM will manage[^31].
- Make sure Update User Attributes is enabled under To App, since it is one of the optional provisioning features[^39].
- Send the role through the SCIM roles.[].value field, which Genesys maps to the user roles API[^56].
- Send the division through scimEnterpriseUser.division, which Genesys maps to the user's divisionId[^47].
### Verify
- Suggested check: after the pilot run, confirm that each pilot user's role and division match the values sent from the identity provider.
### Rollback
- Suggested rollback: remove the role and division mappings, then correct the affected users' roles and divisions by hand.

**SCIM syncs group membership into Genesys groups that carry roles and divisions + Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Create one general group per access profile under Menu > User Management > Groups, with Visibility set to Public[^25].
- Name each group to match its Okta group, because Okta cannot create or delete Genesys groups and membership will not sync unless names match case-insensitively[^40].
- On each group's Roles tab, select Assign Roles, enable the role and choose its divisions[^23].
- Use no membership rules on these groups, because roles cannot be assigned to a group that has them[^24].
### Verify
- A role assigned on a group's Roles tab is granted to every current and future member[^21].
- Suggested check: after the pilot run, confirm that members show the group's roles as inherited.
### Rollback
- A group-granted role is removed from a user when they leave the group[^21].
- Suggested rollback: remove the roles from the group before you delete or rename it.

**SSO only, with users created and maintained by hand in Genesys Cloud**

### Do
- Create a general group under Menu > User Management > Groups, choosing its Type and Visibility[^25].
- Open the group's Roles tab, select Assign Roles, enable the role and choose its divisions[^23].
- Use groups without membership rules, because roles cannot be assigned to a group that has them and enabling roles discards its rules[^24].
- Add users to the group; a role assigned on the Roles tab, with its divisions, is granted to every current and future member[^21].
### Verify
- Roles a user inherits from a group cannot be edited or removed on the user's own roles section[^22].
- Suggested check: open a member's profile and confirm that the role appears there as inherited from the group.
### Rollback
- To withdraw an inherited role, change the group's roles or the user's membership[^22].

**Granted in Genesys Cloud; SCIM carries identity and contact attributes only + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Leave the roles field and the optional division attribute out of the SCIM mapping, because Genesys maps roles.[].value to the user roles API and scimEnterpriseUser.division to the user's divisionId[^56][^47][^46].
- Grant roles in Genesys Cloud through groups: open the group's Roles tab, select Assign Roles, enable the role and choose its divisions[^23].
- Use groups without membership rules, because roles cannot be assigned to a group that has them[^24].
- Do not hand-edit attributes that SCIM manages, because Genesys Cloud SCIM syncs one way and changes made in Genesys Cloud may be overwritten[^61].
### Verify
- Suggested check: after the pilot run, confirm that each pilot user's roles and division are unchanged.
### Rollback
- To withdraw an inherited role, change the group's roles or the user's membership[^22].

## Step 7: Run a pilot and test sign-in

**Microsoft Entra ID + SSO only, with users created and maintained by hand in Genesys Cloud**

### Do
- Test sign-in with Test this application (SP or IdP initiated), by browsing to the Genesys Sign-on URL directly, or from the Genesys tile in My Apps[^19].
- Test both SP-initiated and IdP-initiated sign-in, since the app supports both[^16].
### Verify
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear[^67].
- Only 6 SSO integrations appear directly on the login page[^77].
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.

**Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Keep the provisioning scope at Sync only assigned users and groups, which is the default[^45].
- Assign a few pilot users, and if you chose group-based access, the matching groups; Entra provisioning only updates existing Genesys groups, matched on displayName[^5].
- Validate with on-demand provisioning for those users, then select Start Provisioning, as Microsoft advises[^18].
- Turn Provisioning Status on and save again[^50].
- Test sign-in with Test this application, the Genesys Sign-on URL, or the Genesys tile in My Apps, covering both SP-initiated and IdP-initiated sign-in[^19][^16].
### Verify
- Entra provisioning is monitored through the provisioning logs and the cycle progress bar, and an unhealthy configuration puts the app into quarantine[^10].
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear[^67].
- Suggested check: confirm that each pilot user appears in the people list with the expected email address.
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.
### Rollback
- Removing a user from the app's scope makes the user inactive in Genesys Cloud[^49].
- A hard delete in Entra, including the automatic hard delete 30 days after removal or soft delete, deletes the user in Genesys Cloud[^48].
- Suggested rollback: turn provisioning off before removing pilot users from scope.

**Okta + SSO only, with users created and maintained by hand in Genesys Cloud**

### Do
- Sign in as a pilot user through the identity provider link on the Genesys login page[^67].
### Verify
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear[^67].
- Only 6 SSO integrations appear directly on the login page[^77].
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.

**Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Assign a small set of pilot users to the app, noting that with Deactivate Users enabled, unassigning them later deactivates their Genesys accounts[^35].
- If you chose group-based access, link the matching groups through Push Groups[^40].
- Avoid Push Now, which can remove many members from a group and strip group-granted Genesys roles; Genesys SCIM blocks any single action removing more than 1,000 members[^41].
- Sign in as a pilot user through the identity provider link on the Genesys login page[^67].
### Verify
- A pilot user's phone number should arrive in E.164, because Genesys converts Okta phone numbers to E.164[^36].
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear[^67].
- Suggested check: confirm that each pilot user appears in the people list with the expected email address.
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.
### Rollback
- With Deactivate Users enabled, unassigning a user deactivates their Genesys account[^35].
- Suggested rollback: unlink a pushed group rather than deleting the matching group on the contact center side.

## Step 8: Decide on Genesys Cloud passwords

**Yes, disable Genesys Cloud login so users sign in by SSO only**

### Do
- Confirm that you do not use webhooks for chat notification integrations, because Genesys warns that this feature needs password-based authentication[^73].
- Confirm that at least one third-party SSO provider is configured in the org, which SSO-only sign-in requires[^71].
- Go to Menu > Account > Organization Settings > Authentication, select Disable Genesys Cloud Login, save, and accept the acknowledgment[^70].
### Verify
- With Genesys Cloud login disabled, the password requirement options are disabled but preserved, all users must sign in by SSO, and admins cannot delete every SSO provider[^69].
- Suggested check: before saving, confirm that at least one administrator can sign in through single sign-on.
### Rollback
- Clear Disable Genesys Cloud Login on the Authentication tab, save, and then reconfigure the password requirements[^72].

**No, keep Genesys Cloud credentials available alongside SSO**

### Do
- Leave Disable Genesys Cloud Login cleared under Menu > Account > Organization Settings > Authentication[^70].
### Verify
- The Genesys login page shows the identity provider link once SSO is configured[^67].
- Suggested check: confirm that the login page still offers password sign-in alongside the single sign-on link.

## Step 9: Operate leavers, tokens and certificates

**Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- Removing a user from the app's scope or soft-deleting them in Entra makes the user inactive in Genesys Cloud[^49].
- A hard delete in Entra, including the automatic hard delete 30 days after removal or soft delete, deletes the user in Genesys Cloud[^48].
- Replace the Secret Token before the token duration you set runs out; that duration defaults to 86,400 seconds and can be at most 38,880,000 seconds (450 days)[^33].
- Watch the provisioning logs, because an unhealthy configuration puts the app into quarantine[^10].
- Add a renewed identity provider signing certificate while the current one is still listed; each configuration holds up to 5 certificates and Genesys picks the correct one at sign-in[^65].
### Verify
- The provisioning logs and the cycle progress bar show provisioning health[^10].
- Suggested check: after each leaver, confirm that the person shows as inactive in the people list.
### Rollback
- Suggested rollback: restore a mistakenly removed user in the identity provider before the automatic hard delete runs, so that the user is not deleted on the contact center side.

**Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users**

### Do
- With Deactivate Users enabled, unassigning or deactivating a user in Okta deactivates their Genesys account[^35].
- Replace the API Token before the token duration you set runs out; that duration defaults to 86,400 seconds and can be at most 38,880,000 seconds (450 days)[^33].
- Add a renewed identity provider signing certificate while the current one is still listed; each configuration holds up to 5 certificates and Genesys picks the correct one at sign-in[^65].
### Verify
- The Single Sign-on page shows each certificate's expiration date[^65].
- Suggested check: after each leaver, confirm that the person shows as inactive in the people list.
### Rollback
- Suggested rollback: reassign a mistakenly removed user to the application and confirm that the account is active again.

**SSO only, with users created and maintained by hand in Genesys Cloud**

### Do
- Add a renewed identity provider signing certificate to the configuration while the current one is still listed; each configuration holds up to 5 X.509 signing certificates and Genesys picks the correct one at sign-in[^65].
- Without automatic provisioning, maintaining Genesys Cloud users is a manual task, so deactivate leavers in Genesys Cloud as well as in the identity provider[^20].
### Verify
- The Single Sign-on page shows each certificate's expiration date[^65].
- Suggested check: after each leaver, confirm that the person shows as inactive in the people list.

## Applicability

Applies to: Microsoft Entra ID and Genesys Cloud CX. Deployments: multi-tenant. Sources checked 2026-10-02. - Since the 22 September 2025 release, SCIM APIs can set and update a user's hireDate in Genesys Cloud, which this guide does not configure[^51].
- Genesys also lists OneLogin as an identity management system known to work with its SCIM implementation, but this guide covers only Entra ID and Okta[^58].
- Genesys SCIM extension fields routingSkills and routingLanguages map to a user's routing skills and languages, and this guide does not configure them[^57].

## What remains uncertain

- The SAML login host for regions beyond the examples given in Microsoft's tutorial is not covered by the sources below.
- What Genesys Cloud does with a SCIM role value that matches no existing role is not covered by the sources below.
- Whether a SCIM sync with no roles mapping leaves manually granted roles untouched is not covered by the sources below.
- The Okta-side SAML configuration screens and values are not covered by the sources below.
- How the current Genesys identity provider form labels relate to the ADFS/Azure AD(Premium) tab named in Microsoft's tutorial is not covered by the sources below.
- SAML assertion encryption and multi-factor authentication are not covered by the sources below.
- Whether any identity provider's default mappings populate the routing skills and languages extension fields is not covered by the sources below.

## Sources

[^1]: From the Entra SAML Signing Certificate section you download Certificate (Base64) and from the Set up section copy the Login URL and Microsoft Entra Identifier for Genesys Cloud. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Configure Microsoft Entra SSO, steps 9-10; Configure Genesys Cloud for Azure SSO step 3b-3c. Checked 2026-10-01.
[^2]: The Genesys Cloud for Azure app expects extra SAML attributes Email (source user.userprincipalname) and OrganizationName (your organization name), which are pre-populated in Entra. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Configure Microsoft Entra SSO, step 8 attribute table. Checked 2026-10-01.
[^3]: In Microsoft Entra ID the Genesys Cloud integration is added from the application gallery under Entra ID > Enterprise apps > New application by searching for Genesys Cloud for Azure. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Add Genesys Cloud for Azure from the gallery, steps 1-4. Checked 2026-10-01.
[^4]: To provision group membership from Entra, groups must first be created in Genesys Cloud with names identical to the Entra groups. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 2, item 3. Checked 2026-10-01.
[^5]: Entra provisioning to Genesys Cloud does not create or delete groups; it only updates existing groups, matched on displayName. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 5, item 13 and group attribute table. Checked 2026-10-01.
[^6]: Microsoft's tutorial maps Entra values into a Genesys ADFS/Azure AD(Premium) tab: certificate to ADFS Certificate, Microsoft Entra Identifier to ADFS Issuer URI, Login URL to Target URI, and the app's Application ID to Relying Party Identifier. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Configure Genesys Cloud for Azure SSO, step 3a-3e. Checked 2026-10-01.
[^7]: In the Entra user mapping for Genesys Cloud, userName is the matching attribute and the only one supported for filtering; userName, active and displayName are required by Genesys Cloud. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 5, item 11 user attribute table. Checked 2026-10-01.
[^8]: In the Entra Provisioning tab the Tenant URL is the Genesys regional API URL followed by /api/v2/scim/v2 and the Secret Token is a Genesys OAuth token; Test Connection checks connectivity. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 5, item 6 (Admin Credentials). Checked 2026-10-01.
[^9]: Entra provisioning to Genesys Cloud can create users, remove users who no longer need access, keep user attributes synchronized, and provision groups and group memberships. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Capabilities supported. Checked 2026-10-01.
[^10]: Entra provisioning to Genesys Cloud is monitored through provisioning logs and the cycle progress bar, and an unhealthy configuration puts the app into quarantine. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 6: Monitor your deployment. Checked 2026-10-01.
[^11]: Microsoft's provisioning steps say to enable notification emails for quarantine and enable accidental deletions prevention in the provisioning Properties. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 5, item 9. Checked 2026-10-01.
[^12]: In Entra Basic SAML Configuration, both Identifier and Reply URL are set to the region's Genesys login host plus /saml, for example https://login.mypurecloud.com/saml, https://login.mypurecloud.ie/saml or https://login.mypurecloud.de/saml. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Configure Microsoft Entra SSO, step 5a and 5b tables. Checked 2026-10-01.
[^13]: Microsoft says the same Genesys Cloud for Azure app used for SSO can be used for provisioning, but recommends a separate app when first testing the provisioning integration. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 3: Add Genesys Cloud for Azure from the Microsoft Entra application gallery. Checked 2026-10-01.
[^14]: For SP-initiated SSO the Entra Sign-on URL is the region's Genesys login host without a path, for example https://login.mypurecloud.com. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Configure Microsoft Entra SSO, step 6. Checked 2026-10-01.
[^15]: The Genesys Cloud for Azure gallery app uses a fixed identifier string, so only one instance of it can be configured for SSO in one Entra tenant. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Scenario description, Note. Checked 2026-10-01.
[^16]: The Genesys Cloud for Azure app supports both service-provider-initiated and identity-provider-initiated SSO. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Scenario description. Checked 2026-10-01.
[^17]: Configuring the Genesys Cloud for Azure app in Entra ID requires the Application Administrator, Cloud Application Administrator or Application Owner role. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Prerequisites. Checked 2026-10-01.
[^18]: Microsoft advises starting small: scope provisioning by assignment or scoping filter, validate with on-demand provisioning for a few users, then select Start Provisioning. Source: [Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-provisioning-tutorial), Step 4 bullets; Step 5 items 15-16. Checked 2026-10-01.
[^19]: Entra SSO to Genesys Cloud can be tested with Test this application (SP or IdP initiated), by browsing to the Genesys Sign-on URL directly, or from the Genesys tile in My Apps. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Test SSO. Checked 2026-10-01.
[^20]: For Entra users to sign in to Genesys Cloud they must already be provisioned as Genesys Cloud users; without automatic provisioning this is a manual Add Person task with full name and email. Source: [Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/purecloud-by-genesys-tutorial), Create Genesys Cloud for Azure test user. Checked 2026-10-01.
[^21]: A role assigned on a Genesys group's Roles tab, with its divisions, is granted to every current and future member and removed from a user when they leave the group. Source: [Assign roles to a group](https://help.genesys.cloud/articles/assign-roles-to-a-group/), Introductory paragraphs. Checked 2026-10-01.
[^22]: Roles a user inherits from a group cannot be edited or removed on the user's own roles section; change the group's roles or the user's membership instead. Source: [Assign roles to a group](https://help.genesys.cloud/articles/assign-roles-to-a-group/), Introductory paragraphs. Checked 2026-10-01.
[^23]: To grant a role per group, open Menu > User Management > Groups, select the group, Roles tab, Assign Roles, enable the role and choose its divisions; this needs Directory Group Add and Edit, Authorization Grant Add and Role View permissions. Source: [Assign roles to a group](https://help.genesys.cloud/articles/assign-roles-to-a-group/), Prerequisites; Assign a role to group steps 1-8. Checked 2026-10-01.
[^24]: Roles cannot be assigned to a Genesys group that has membership rules; enabling roles on such a group discards its rules. Source: [Assign roles to a group](https://help.genesys.cloud/articles/assign-roles-to-a-group/), Example, Step 3 note. Checked 2026-10-01.
[^25]: A Genesys general group is created under Menu > User Management > Groups with a Type (Official or Social) and a Visibility of Public, Members Only or Owners Only. Source: [Create a group](https://help.genesys.cloud/articles/create-group/), Steps to create a general group; Type; Visibility. Checked 2026-10-01.
[^26]: Before disabling Genesys Cloud login, confirm that an administrator can sign in through SSO, because afterwards every user, administrators included, must sign in by SSO (inferred). Source: [Configure Genesys Cloud to authenticate with SSO only](https://help.mypurecloud.com/articles/use-sso-instead-of-genesys-cloud-login-credentials/), When Genesys Cloud login is disabled, third bullet. Checked 2026-10-01.
[^27]: Microsoft's Genesys-side SSO steps (ADFS/Azure AD(Premium) tab) appear to predate Genesys's current Add an Identity Provider page, so the Genesys-side form should follow the Genesys article, with Entra values mapped by meaning (inferred). Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Create an SSO integration, steps 1-8, compared with ms-learn-entra-genesys-cloud-sso-tutorial Configure Genesys Cloud for Azure SSO step 3. Checked 2026-10-01.
[^28]: Any user attribute or role that SCIM manages should be treated as read-only in the Genesys admin UI, because a later sync may overwrite manual edits there (inferred). Source: [About Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/about-genesys-cloud-scim-identity-management/), Overview, Important note. Checked 2026-10-01.
[^29]: Because the documented Entra role mapping uses SingleAppRoleAssignment and a primary role value, it likely carries one Genesys role per user; users needing several roles or per-division grants are better served by group-granted roles (inferred). Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Mappings (Optional), roles row; read with genesys-help-assign-roles-to-a-group introductory paragraphs. Checked 2026-10-01.
[^30]: The Genesys SCIM OAuth client is created under Menu > IT and Integrations > OAuth with grant type Client Credentials and only the SCIM Integration role assigned. Source: [Create an OAuth client](https://help.mypurecloud.com/articles/create-an-oauth-client/), Genesys Cloud SCIM tab, steps 1-7. Checked 2026-10-01.
[^31]: When assigning the SCIM Integration role to the OAuth client, include every division that SCIM will manage; client credentials roles default to the Home division. Source: [Create an OAuth client](https://help.mypurecloud.com/articles/create-an-oauth-client/), Genesys Cloud SCIM tab step 7; Platform API tab, Client Credential Step 1. Checked 2026-10-01.
[^32]: To grant the SCIM Integration role to the OAuth client the admin must hold that role; if it is missing, default roles can be restored with POST /api/v2/authorization/roles/default. Source: [Create an OAuth client](https://help.mypurecloud.com/articles/create-an-oauth-client/), Prerequisites; Genesys Cloud SCIM tab step 7 note. Checked 2026-10-01.
[^33]: A SCIM OAuth client's token duration defaults to 86,400 seconds and can be set up to 38,880,000 seconds (450 days) only when it uses the SCIM Integration role or a custom role with the same permissions. Source: [Create an OAuth client](https://help.mypurecloud.com/articles/create-an-oauth-client/), Genesys Cloud SCIM tab, step 9. Checked 2026-10-01.
[^34]: The Genesys OAuth client secret can be viewed only once at setup, but a new secret can be generated later with Generate new secret. Source: [Create an OAuth client](https://help.mypurecloud.com/articles/create-an-oauth-client/), Genesys Cloud SCIM tab, steps 10-12. Checked 2026-10-01.
[^35]: In Okta, Deactivate Users deactivates the Genesys account when the user is unassigned or deactivated, and Sync Password creates a password for each user and pushes it to Genesys Cloud. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), To App, steps 3-4. Checked 2026-10-01.
[^36]: Genesys converts phone numbers from Okta to E.164, so Okta phone numbers should already be E.164 to avoid continual updates. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), To App, Important note. Checked 2026-10-01.
[^37]: In Okta's Provisioning > Integration, enter the regional SCIM Domain and the bearer token as API Token, then select Test API Credentials and Save. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), Integration, steps 1-4. Checked 2026-10-01.
[^38]: For Okta, the Genesys Cloud app is added from the Okta Integration Network, and its Application username format is set to Email under Sign On settings. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), Application setup; Sign On. Checked 2026-10-01.
[^39]: The Genesys Cloud SCIM app in Okta supports Create Users, Update User Attributes, Deactivate Users, Sync Password and Push Groups, each optional. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), Provisioning; To App steps 1-5. Checked 2026-10-01.
[^40]: Okta links groups to Genesys Cloud through Push Groups; Okta cannot create or delete Genesys groups, and names must match case-insensitively or membership will not sync. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), Groups, notes and steps 1-3. Checked 2026-10-01.
[^41]: Okta's Push Now action can remove many members from a group, stripping group-granted Genesys roles; Genesys SCIM blocks any single action removing more than 1000 members. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), Groups, Notes; Link large groups. Checked 2026-10-01.
[^42]: In the Genesys Entra mapping, the required SCIM active attribute is mapped from Not([IsSoftDeleted]). Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Mappings (Optional), field mapping table, active row. Checked 2026-10-01.
[^43]: With Entra ID, mapping a previously synced field to an empty value does not clear it in Genesys Cloud. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Mappings (Optional), introductory note. Checked 2026-10-01.
[^44]: Genesys states that Entra provisioning can create, update and delete users in Genesys Cloud. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Users and Groups, Notes. Checked 2026-10-01.
[^45]: By default Entra scopes Genesys provisioning to Sync only assigned users and groups; it can be changed to Sync all users and groups. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Scope (Optional). Checked 2026-10-01.
[^46]: The SCIM enterprise division attribute is optional and its value must match an existing Genesys Cloud division name or be blank. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Mappings (Optional), field mapping table, scimEnterpriseUser.division row. Checked 2026-10-01.
[^47]: Genesys maps the SCIM scimEnterpriseUser.division field to the user's divisionId in Genesys Cloud. Source: [SCIM and Genesys Cloud field mappings](https://help.genesys.cloud/articles/scim-and-genesys-cloud-field-mappings/), Field mapping table, scimEnterpriseUser.division row. Checked 2026-10-01.
[^48]: A hard delete in Entra, including the automatic hard delete 30 days after removal or soft delete, deletes the user in Genesys Cloud. Source: [What causes Genesys Cloud to change the status of a Microsoft Entra ID user to inactive or to delete a user?](https://help.genesys.cloud/faqs/what-causes-genesys-cloud-to-change-the-status-of-a-microsoft-entra-id-user-to-inactive-or-to-delete-a-user/), FAQ answer, first paragraph. Checked 2026-10-01.
[^49]: Removing a user from the Entra app's scope or soft-deleting them in Entra makes the user inactive in Genesys Cloud. Source: [What causes Genesys Cloud to change the status of a Microsoft Entra ID user to inactive or to delete a user?](https://help.genesys.cloud/faqs/what-causes-genesys-cloud-to-change-the-status-of-a-microsoft-entra-id-user-to-inactive-or-to-delete-a-user/), FAQ answer, first paragraph. Checked 2026-10-01.
[^50]: Genesys's Entra procedure sets Provisioning Mode to Automatic, enters Tenant URL and Secret Token, runs Test Connection, saves, then turns Provisioning Status on and saves again. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Provisioning section. Checked 2026-10-01.
[^51]: Since the 22 September 2025 release, SCIM APIs can set and update a user's hireDate in Genesys Cloud. Source: [Release notes for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/release-notes-for-genesys-cloud-scim-identity-management/), September 22, 2025 entry. Checked 2026-10-01.
[^52]: Genesys Cloud SCIM does not currently support name.givenName, name.familyName or the address fields; the display name comes from displayName. Source: [SCIM and Genesys Cloud field mappings](https://help.genesys.cloud/articles/scim-and-genesys-cloud-field-mappings/), Unsupported fields rows; displayName row. Checked 2026-10-01.
[^53]: The SCIM password field updates the Genesys Cloud user's password via PUT or PATCH but is never returned. Source: [SCIM and Genesys Cloud field mappings](https://help.genesys.cloud/articles/scim-and-genesys-cloud-field-mappings/), Field mapping table, password row. Checked 2026-10-01.
[^54]: Genesys SCIM can add users to or remove users from a public group but cannot create or delete groups; only public groups are supported and names must match case-insensitively. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Users and Groups, Notes. Checked 2026-10-01.
[^55]: To send a Genesys role from Entra, the documented mapping is SingleAppRoleAssignment([appRoleAssignments]) to roles[primary eq "True"].value, after creating an app role in Entra and assigning it to the user. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Mappings (Optional), field mapping table, roles row. Checked 2026-10-01.
[^56]: Genesys maps the SCIM roles.[].value field to the user roles API, so role values sent by SCIM become Genesys role assignments. Source: [SCIM and Genesys Cloud field mappings](https://help.genesys.cloud/articles/scim-and-genesys-cloud-field-mappings/), Field mapping table, roles.[].value row and roles example. Checked 2026-10-01.
[^57]: Genesys SCIM extension fields scimUserExtensions.routingSkills and routingLanguages (name and proficiency) map to the user's routing skills and languages. Source: [SCIM and Genesys Cloud field mappings](https://help.genesys.cloud/articles/scim-and-genesys-cloud-field-mappings/), Field mapping table, scimUserExtensions rows. Checked 2026-10-01.
[^58]: Genesys lists Microsoft Entra ID, Okta and OneLogin as identity management systems known to work with its SCIM implementation. Source: [About Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/about-genesys-cloud-scim-identity-management/), Identity Management Systems. Checked 2026-10-01.
[^59]: The Genesys SCIM endpoint is https://{domain}/api/v2/scim/v2/ where domain is the org's regional API domain, for example api.mypurecloud.com (US East), api.mypurecloud.ie (Dublin), api.mypurecloud.de (Frankfurt), api.euw2.pure.cloud (London). Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Provisioning section, regional domain table. Checked 2026-10-01.
[^60]: Genesys documents generating the SCIM bearer token by calling the regional login URL /oauth/token with the OAuth client ID and secret (client credentials), using its Postman collection. Source: [Configure Okta for Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/configure-okta-for-genesys-cloud-scim-identity-management/), Token generation, steps 1-5. Checked 2026-10-01.
[^61]: Genesys Cloud SCIM only syncs one way, from the identity management system to Genesys Cloud; changes made in Genesys Cloud are not synced back and may be overwritten. Source: [About Genesys Cloud SCIM (Identity Management)](https://help.genesys.cloud/articles/about-genesys-cloud-scim-identity-management/), Overview, Important note. Checked 2026-10-01.
[^62]: In the Genesys Entra mapping, userPrincipalName maps to the required SCIM userName, which generates the Genesys user's main email address. Source: [Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)](https://help.mypurecloud.com/articles/configure-azure-active-directory-for-genesys-cloud-scim-identity-management/), Mappings (Optional), field mapping table, userName row. Checked 2026-10-01.
[^63]: An SSO integration is created under Menu > IT and Integrations > Single Sign-on > Add an Identity Provider, and importing the IdP's SAML metadata file populates the required fields and signing certificate. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Create an SSO integration, steps 1-8. Checked 2026-10-01.
[^64]: After saving the integration, Genesys generates SP metadata (Issuer URI, Assertion Consumer Service, Single Logout URI) that can be downloaded with Download Metadata for the IdP. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Genesys Cloud Service provider data. Checked 2026-10-01.
[^65]: Each Genesys SSO configuration holds up to five X.509 signing certificates, shown with their expiration dates, and Genesys picks the correct one at sign-in. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Identity provider field details table, Certificate row; Single sign-on page. Checked 2026-10-01.
[^66]: The Genesys identity provider form holds Issuer URI, Single Sign-On URI and binding, optional request signing, Single Logout URI and binding, Name Identifier Format (Unspecified if unknown), and a ForceAuthn-on-inactivity option. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Identity provider field details table. Checked 2026-10-01.
[^67]: After SSO is configured, the Genesys login page shows the identity provider link; if it does not appear, Genesys says something in the configuration is incorrect. Source: [What users can expect after SSO setup](https://help.mypurecloud.com/articles/what-users-can-expect-after-sso-setup/), Item 2 and its note. Checked 2026-10-01.
[^68]: Users can sign in with a non-email identifier by choosing an alternative Name Identifier Format, and with Entra SCIM the identifier can be mapped to the Genesys externalIds extension keyed on the IdP Issuer URI. Source: [Configure SSO identity provider without email address](https://help.genesys.cloud/articles/configure-sso-identity-provider-without-email-address/), Body paragraphs 2-4 and mapping table. Checked 2026-10-01.
[^69]: With Genesys Cloud login disabled, password requirement options are disabled but preserved, all users must sign in by SSO, and admins cannot delete every SSO provider. Source: [Configure Genesys Cloud to authenticate with SSO only](https://help.mypurecloud.com/articles/use-sso-instead-of-genesys-cloud-login-credentials/), When Genesys Cloud login is disabled. Checked 2026-10-01.
[^70]: SSO-only sign-in is enabled under Menu > Account > Organization Settings > Authentication by selecting Disable Genesys Cloud Login, saving, and accepting the acknowledgment. Source: [Configure Genesys Cloud to authenticate with SSO only](https://help.mypurecloud.com/articles/use-sso-instead-of-genesys-cloud-login-credentials/), Enable SSO only authentication, steps 1-5. Checked 2026-10-01.
[^71]: Enabling SSO-only sign-in in Genesys Cloud requires at least one third-party SSO provider already configured in the org. Source: [Configure Genesys Cloud to authenticate with SSO only](https://help.mypurecloud.com/articles/use-sso-instead-of-genesys-cloud-login-credentials/), Prerequisites. Checked 2026-10-01.
[^72]: SSO-only is reversed by clearing Disable Genesys Cloud Login on the Authentication tab and saving, after which Genesys password requirements must be reconfigured. Source: [Configure Genesys Cloud to authenticate with SSO only](https://help.mypurecloud.com/articles/use-sso-instead-of-genesys-cloud-login-credentials/), Disable SSO only authentication. Checked 2026-10-01.
[^73]: Genesys warns not to enable SSO-only authentication if webhooks are used for chat notification integrations, because that feature needs password-based authentication. Source: [Configure Genesys Cloud to authenticate with SSO only](https://help.mypurecloud.com/articles/use-sso-instead-of-genesys-cloud-login-credentials/), Note under When Genesys Cloud login is disabled. Checked 2026-10-01.
[^74]: Genesys acts on a case-sensitive OrganizationName SAML attribute: for IdP-initiated SSO it carries the org short name, and for SP-initiated SSO it must match the selected org. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), SAML attributes table, OrganizationName row. Checked 2026-10-01.
[^75]: Adding an SSO provider in Genesys Cloud requires Single Sign-on > Provider > Add, Delete, Edit and View permissions, an admin role in the IdP, and a single email address shared by the IdP account and Genesys Cloud. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Prerequisites. Checked 2026-10-01.
[^76]: An optional ServiceName SAML attribute redirects the browser after authentication to a URL or to the keywords directory or directory-admin. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), SAML attributes table, ServiceName row. Checked 2026-10-01.
[^77]: Genesys Cloud allows up to 30 SSO integrations, with the same or mixed identity providers, and only six appear directly on the login page. Source: [Add multiple single sign-on providers to Genesys Cloud](https://help.mypurecloud.com/articles/add-multiple-single-sign-on-providers-to-genesys-cloud/), Introduction; Customize the login screen for each SSO integration. Checked 2026-10-01.
