Synchronizing users into Webex from Entra ID or Active Directory
Verified 2026-09-30 · 73 sources · tier 2
For Webex Control Hub full administrators configuring automated directory synchronization and licensing.
Directory synchronization populates Webex Control Hub user identities directly from external directories and applies automated service entitlements 37. When configured with automated licence templates, users receive designated services upon account creation 37.
Before you start
- Ensure you hold a full administrator account in Webex Control Hub 1068.
- If synchronizing from Okta, configure Okta SSO beforehand, as Cisco requires SSO and licence assignment templates prior to syncing 54.
- If synchronizing from on-premises Active Directory, prepare a Windows Server 2025, 2022, 2019, or 2016 host with .NET Framework 3.5 and .NET Framework 4.5, at least 8 GB RAM, 50 GB storage, and outbound HTTPS access on port 443 2671314.
- Note that when users are synchronized from an external directory, administrators cannot add users manually in Control Hub 61.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Three questions. One permanent page you can send to your manager.
Step 1 Verify and claim your email domains
Do
In Control Hub Organization Settings, add each email domain, add the generated verification token as a DNS TXT record in your DNS provider, and select Verify 29. Add and verify the domain used by your administrator account first, because Control Hub enforces this sequence to avoid administrator lockout 27. After verification, claim the domain so that new user registrations using that domain automatically join your organization instead of a free consumer organization 28.
Verify
Suggested check: Ensure each required domain displays as verified and claimed in Control Hub. If your organization enforces that all users must belong to a verified domain, Entra sync will not create users residing in unverified domains 60.
Rollback
Suggested rollback: Remove the DNS TXT records from your DNS provider and delete the domains from Control Hub Organization Settings.
Step 2 Check for conflicting synchronization methods
On-premises Active Directory with Cisco Directory Connector
Do
Confirm that no cloud synchronization method, such as the Entra ID Wizard App, is configured to block on-premises synchronization 62.
Verify
Suggested check: Navigate to the Directory Synchronization area in Control Hub to verify that on-premises connector setup is available.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
If Cisco Directory Connector is currently enabled, disable scheduled synchronization under Actions > Synchronization Mode > Disable Synchronization in Directory Connector 6. In Control Hub, proceed with the Entra ID Wizard App setup prompt to choose Entra ID and block Directory Connector 62.
Verify
Confirm that Directory Connector synchronization schedule is disabled and that the Wizard App setup continues past the connector block prompt 662.
Rollback
Suggested rollback: Close the Wizard App setup dialog and re-evaluate directory synchronization settings.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
In Microsoft Entra ID, create a custom enterprise application for SCIM 2.0 provisioning rather than configuring conflicting synchronization 59.
Verify
Suggested check: Confirm in Control Hub that only one provisioning application manages the scoped user group.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Confirm that Directory Connector is not enabled in the organization, as an organization using Directory Connector cannot synchronize users from Okta 53.
Verify
Ensure Directory Connector is completely absent or disabled in Control Hub before proceeding 53.
Step 3 Configure automatic licence templates
Organization-level automatic licence template + On-premises Active Directory with Cisco Directory Connector
Do
Create an organization-level automatic licence template in Control Hub so that newly synchronized users receive services upon creation 3723. If desired, enable the option to apply to existing users; note that the 'Preserve licenses for existing users' setting is checked by default 38.
Verify
Confirm that the template appears as active in Control Hub before initiating synchronization 23.
Rollback
Suggested rollback: Deactivate or modify the organization-level licence template in Control Hub.
Group-level licence templates mapped to directory groups + On-premises Active Directory with Cisco Directory Connector
Do
Configure group-level licence templates in Control Hub and map them specifically to Active Directory security groups 40. Do not map templates to distribution groups, as Webex does not support automatic licence assignment for distribution groups 40. Users belonging to multiple groups will receive the union of all matching group templates and any organization-level template 41.
Verify
Verify that all mapped groups are designated as security groups and have active template assignments 40.
Rollback
Suggested rollback: Remove the group mappings from the licence template.
Organization-level automatic licence template + Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Create an organization-level automatic licence template in Control Hub 37. If applying to existing users, note that 'Preserve licenses for existing users' is enabled by default 38.
Verify
Confirm the template is saved and active in Control Hub before starting synchronization 37.
Rollback
Suggested rollback: Edit or remove the organization-level template in Control Hub.
Group-level licence templates mapped to directory groups + Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Configure group-level licence templates in Control Hub and create an organization-level template as an operational fallback 41. Note that distribution groups cannot be synchronized with the Entra ID Wizard App 66.
Verify
Suggested check: Verify that the group templates are configured against synchronized security groups in Control Hub.
Rollback
Suggested rollback: Remove group template mappings in Control Hub.
Organization-level automatic licence template + Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Configure an organization-level automatic licence assignment template in Control Hub prior to provisioning 37.
Verify
Confirm that the template is active in Control Hub 37.
Rollback
Suggested rollback: Remove or update the template in Control Hub.
Group-level licence templates mapped to directory groups + Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Configure an organization-level licence template in Control Hub as the primary method, noting that Cisco positions the Wizard App rather than custom SCIM 2.0 when group synchronization is required 59.
Verify
Ensure the organization-level licence assignment template is active 37.
Rollback
Suggested rollback: Modify or delete the licence assignment template.
Organization-level automatic licence template + Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Set up an organization-level automatic licence template in Control Hub before enabling synchronization, as Cisco requires licence templates to avoid users arriving without licences 54.
Verify
Verify the licence template exists and is active in Control Hub 54.
Rollback
Suggested rollback: Deactivate or alter the template in Control Hub.
Group-level licence templates mapped to directory groups + Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Configure an organization-level licence template in Control Hub, as Cisco requires automatic licence assignment templates prior to Okta synchronization 54.
Verify
Confirm that the licence assignment template is active in Control Hub 54.
Rollback
Suggested rollback: Deactivate or delete the template in Control Hub.
Step 4 Configure Webex Calling number pre-provisioning
Yes, include Webex Calling in the licence template
Do
For directory synchronization, Webex Calling automatic assignment uses the user's work phone number from the directory to look up a pre-provisioned number 1. Pre-provision the phone numbers at the target Webex Calling location in E.164 format and ensure the numbers are unassigned 2. Populate each user's work phone attribute in the identity directory with the exact matching E.164 number 2. Include Webex Calling in your licence template 1. See also Setting up a Webex Calling location.
Verify
Check that the work numbers in the directory match unassigned, pre-provisioned E.164 numbers in Webex Calling; if validation fails, the user is not provisioned with Webex Calling 2.
Rollback
Suggested rollback: Remove Webex Calling from the licence template in Control Hub.
No, exclude Webex Calling from the template
Do
Ensure Webex Calling is not selected in the organization or group licence templates 37.
Verify
Suggested check: Review the active licence templates to confirm Webex Calling is excluded.
Step 5 Connect or install the synchronization engine
On-premises Active Directory with Cisco Directory Connector
Do
In Control Hub, go to Users > Manage Users > Enable Directory Synchronization and download the connector installer 9. Install the connector on a Windows Server host using a service account (Local System or domain) that can reach the domain controller and read Active Directory user objects 2126. Sign in to Directory Connector using a Control Hub full administrator account 10. If managing multiple domains, install one connector per Active Directory domain 19. Deploy a second connector if high availability backup is required 12. Under Configuration > General, check 'Automatically upgrade to the new Cisco Directory Connector version' 3.
Verify
Confirm that the Directory Connector signs in and the dashboard displays active connector status 4.
Rollback
Suggested rollback: Uninstall the connector software from the host. Synchronized users remain in Webex but stop receiving updates 6.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Sign in to Control Hub as a full administrator and navigate to Organization Settings > Microsoft Entra ID Wizard App > Set up 6870. Authenticate with an Entra ID account authorized to grant tenant-wide admin consent and accept the requested permissions 6870.
Verify
Confirm that consent succeeds and the Wizard App displays its configuration tabs 70.
Rollback
Suggested rollback: In Control Hub, use the Delete instance action on the Wizard App to remove the configuration 67.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
In Microsoft Entra ID, create a custom enterprise application for SCIM 2.0 provisioning 59. In Control Hub, navigate to Apps > Service apps > Get a token as a full administrator to generate a SCIM bearer token 56. In Entra ID, set the Tenant URL to https://webexapis.com/identity/scim/{OrgId}/v2 using your Control Hub organization ID, and supply the bearer token 5856. In provisioning settings, enable notification emails for quarantine and configure accidental deletions prevention 43.
Verify
In Entra ID, select Test Connection and verify that the SCIM connection test succeeds 43.
Rollback
Suggested rollback: In Entra ID, delete the custom enterprise application.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
In the Okta admin portal, add the 'Cisco Webex Identity SCIM 2.0' application from the Okta Integration Network 50. Set the base URL to https://webexapis.com/identity/scim/{OrgId}/v2 using your organization ID 58. In Control Hub, navigate to Apps > Service apps > Get a token as a full administrator and paste the resulting token into Okta's API integration credentials 56.
Verify
In Okta, test API credentials and verify that the integration test succeeds 50.
Rollback
Suggested rollback: Disable provisioning or remove the Webex application in Okta.
Step 6 Define user and group synchronization scope
On-premises Active Directory with Cisco Directory Connector
Do
By default, Directory Connector synchronizes all users that are not computers and all groups that are not critical system objects 5. Define LDAP filters for users and groups and specify on-premises Base DNs under object selection to narrow the synchronization scope 17. If group licence templates are used, ensure that Groups are included in object selection and that only security groups are mapped 40.
Verify
Suggested check: Review LDAP filter syntax and Base DN scopes to confirm they point to intended organizational units.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
In the Wizard App configuration tabs, scope synchronization by adding individual users or by adding groups using 'Sync group members' or 'Sync children groups' 69. Avoid using 'Select all users' if configuring a large tenant 69. Do not attempt to add distribution groups, as they are not supported 66.
Verify
Verify that the Users and Groups tabs list only the intended individual accounts and security groups 69.
Rollback
Suggested rollback: Remove individual users or groups from the Wizard App scope tabs.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Assign users or security groups to the custom SCIM enterprise application in Entra ID 42. Ensure each assignment uses a role other than Default Access, as users assigned with Default Access are excluded from provisioning 42. Assign users directly or via immediate parent groups; do not rely on nested groups, as the Entra provisioning service cannot read or provision nested group members 46.
Verify
Verify the application assignments list in Entra ID to ensure target groups have specific assigned roles rather than Default Access 42.
Rollback
Suggested rollback: Unassign users or groups from the enterprise application in Entra ID 49.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
In Okta, assign the target users and security groups to the Cisco Webex Identity SCIM 2.0 application, and configure Push Groups for groups that should sync to Control Hub 52.
Verify
Verify in Okta that assignments and pushed groups show an active status without synchronization errors 52.
Rollback
Suggested rollback: Remove user assignments or push group configurations in Okta.
Step 7 Map attributes and username identity
On-premises Active Directory with Cisco Directory Connector
Do
Under attribute mapping in Directory Connector, map the required uid field from mail or userPrincipalName 25. Retain the default mapping of userAccountControl to ds-pwp-account-disabled to reflect disabled accounts in Webex 24.
Verify
Suggested check: Confirm that uid is mapped to an attribute containing valid email addresses to avoid duplicate accounts.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Retain the default attribute mapping in the Wizard App, which maps userPrincipalName to the Control Hub email address (username) 72. Do not change this default, because mapping the username away from the email address causes Entra ID to create duplicate accounts instead of matching existing users 33.
Verify
Check the attribute mapping tab in the Wizard App to confirm userPrincipalName maps to email 72.
Rollback
Suggested rollback: Revert attribute mappings to defaults in the Wizard App.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Map userPrincipalName in Entra ID to the Webex userName attribute 72. Note that Entra ID does not synchronize null values to Webex, meaning clearing an attribute in Entra ID will not clear that attribute in Webex 57.
Verify
Review the attribute mapping table in Entra ID to confirm userPrincipalName maps to userName and email 72.
Rollback
Suggested rollback: Restore previous attribute mapping definitions in Entra ID.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Ensure the username in Okta is mapped to the user's primary email address 33. Note that Okta attribute updates overwrite existing attribute values in Webex 52.
Verify
Suggested check: Verify the attribute mapping in the Okta application integration settings.
Step 8 Perform a dry run or pilot synchronization
On-premises Active Directory with Cisco Directory Connector
Do
Perform a dry run synchronization from Directory Connector 8. Review the dry run report showing objects that will be added, modified, or deleted 8. Select the option to retain mismatched cloud users unless deletion of users added outside AD is explicitly desired, because Directory Connector flags any Webex user lacking a matching AD object as a mismatch 818.
Verify
Verify that the counts of added, modified, and deleted objects align with your planned scope 8.
Rollback
Suggested rollback: Adjust LDAP filters or Base DNs if dry run counts reflect incorrect objects.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Run a dry run in the Wizard App and download the dry-run report, using on-demand provisioning to test individual users outside the schedule before enabling automated synchronization 63.
Verify
Inspect the dry-run report for errors and verify that the on-demand test users appear in Control Hub with expected licences 6337.
Rollback
Suggested rollback: Unassign or remove pilot test users from the Wizard App.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Perform on-demand provisioning in Entra ID for a few users before starting provisioning 43.
Verify
Review the Microsoft Entra provisioning logs to verify successful user creation in Webex 47.
Rollback
Suggested rollback: Unassign the test users in Entra ID to disable them in Webex 49.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Assign a single pilot test user to the Okta Webex application 52.
Verify
Check Control Hub to confirm the pilot user appears and has received the automatic template licences 54.
Rollback
Suggested rollback: Unassign the pilot user in Okta, which deactivates the account in Webex 51.
Step 9 Run full synchronization and schedule recurring jobs
On-premises Active Directory with Cisco Directory Connector
Do
Execute a full synchronization in Directory Connector, which sends all filtered AD objects and is required before incremental synchronizations can begin 11. Under Configuration > Connector Policy, configure the full and incremental synchronization schedules by day, hour, and minute 20. On version 3.5 and later, the default incremental interval is every 4 hours 15.
Verify
Review the Directory Connector dashboard to confirm current sync status, the two most recent sync results, connector status, and cloud statistics 4.
Rollback
Suggested rollback: Under Actions > Synchronization Mode, select Disable Synchronization to halt scheduled sync cycles 6.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Enable Auto Sync in the Wizard App 73. The Wizard App synchronizes users approximately every 40 minutes and synchronizes groups automatically every 12 hours 7364.
Verify
Confirm that the synchronization status displays as Active and check the counts of synced, skipped, and failed objects 71.
Rollback
Suggested rollback: Turn off Auto Sync to stop synchronization without deleting the configuration 67.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Start provisioning in the Entra ID custom enterprise application 43.
Verify
Check the Microsoft Entra provisioning logs to ensure incremental cycles process without entering quarantine 4748.
Rollback
Suggested rollback: Stop provisioning from the enterprise application overview in Entra ID.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Assign the remaining user population and ensure Push Groups are active in Okta 52.
Verify
Suggested check: Review Okta provisioning task logs and verify that user creation events succeed.
Rollback
Suggested rollback: Unassign user groups in Okta 52.
Step 10 Verify provisioned users and licence allocation
Do
Open Users and Groups in Control Hub to inspect provisioned accounts 34. Note that a synchronized group's name, description, and membership cannot be modified in Control Hub because they are managed directly in the source directory 34.
Verify
Confirm that provisioned users have their expected licences assigned 37. If group templates were used, verify that users belonging to multiple groups show the combined union of licences 41.
Rollback
Suggested rollback: Adjust group memberships in the identity source or modify template rules in Control Hub.
Step 11 Test deprovisioning workflows
On-premises Active Directory with Cisco Directory Connector
Do
Disable a test user in Active Directory or move them outside the configured Base DN scope, then execute a synchronization run 2422. Disabling the user in AD updates ds-pwp-account-disabled in Webex via userAccountControl mapping 24. If deleted, Directory Connector keeps deleted users in the Webex cloud identity service for 7 days before permanent deletion 22.
Verify
Confirm that the test user is marked disabled or moved to deleted status in Control Hub 2422.
Rollback
Suggested rollback: Re-enable the user in AD or restore them within the cloud identity recovery window.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Unassign a test user from the Webex app in Entra ID, block their sign-in, or delete them in Entra ID 3230. When a user is deleted in Entra ID, Webex renames the user and marks them Inactive 30. If a user is permanently deleted in Entra ID, Webex deletes the user from the organization 31.
Verify
Verify that unassigned, blocked, or deleted test users transition to Inactive in Control Hub 3230.
Rollback
Suggested rollback: Reassign the user in Entra ID or restore them from the Entra recycle bin to reactivate them and restore their original username 30.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Unassign a test user from the enterprise application in Entra ID 49. The Entra provisioning service disables the user by setting the SCIM active attribute to false, which Webex marks as Inactive 4932. Note that Entra ID hard-deletes users 30 days after soft deletion, at which point the provisioning service issues a delete operation to Webex 45.
Verify
Review the Entra provisioning logs to confirm the update setting active to false, and verify in Control Hub that the user is Inactive 4932.
Rollback
Suggested rollback: Reassign the user to the enterprise application in Entra ID 49.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Unassign or deactivate a test user in Okta 51. Okta deprovisioning deactivates rather than deletes Webex accounts 51.
Verify
Confirm in Control Hub that the user account displays as deactivated 51.
Rollback
Suggested rollback: Reassign the user in Okta to reactivate the Webex account 51.
Step 12 Establish recurring operational maintenance
On-premises Active Directory with Cisco Directory Connector
Do
Keep automatic upgrades enabled under Configuration > General in Directory Connector 3. Note that release 3.8.7000 added a field to exclude organizational units from sync 16. Use the Windows event viewer to review and troubleshoot any synchronization failures 4.
Verify
Check the Directory Connector dashboard regularly to verify recurring scheduled sync results 4.
Microsoft Entra ID with the Control Hub Entra ID Wizard App
Do
Schedule routine checks of the Wizard App synchronization status tab in Control Hub 71.
Verify
Verify that sync status remains Active and investigate any entries in Quarantine or elevated failed object counts 71.
Microsoft Entra ID with a custom SCIM 2.0 enterprise application
Do
Track bearer token expiration on your administrative calendar, noting that the bearer token used for Webex SCIM 2.0 provisioning is valid for 365 days and then expires 55. Monitor administrator email notifications for provisioning quarantine alerts 43. A provisioning job with consistent errors enters quarantine, runs at most daily, and is disabled if it remains in quarantine for more than 4 weeks 48.
Verify
Suggested check: Confirm that a reminder is scheduled prior to bearer token expiration.
Okta with the Cisco Webex Identity SCIM 2.0 application
Do
Schedule a recurring calendar reminder to renew the SCIM bearer token in Okta before its 365-day validity window expires 55.
Verify
Suggested check: Verify that the bearer token expiration date is documented in operational runbooks.
Applicability
Applies to: Cisco Webex Calling, Cisco Directory Connector, Cisco Webex Control Hub, Cisco Webex Control Hub with Entra ID synchronization, Microsoft Entra ID provisioning - Cisco Webex gallery app, Microsoft Entra ID application provisioning service, Cisco Webex Control Hub with Okta SCIM 2.0, Cisco Webex Identity SCIM 2.0 API, Cisco Webex Control Hub SCIM 2.0 with custom Entra ID enterprise app, and Cisco Webex Control Hub Entra ID Wizard App. Deployments: multi-tenant and on-premises-connector. Sources checked 2026-09-30. The latest Directory Connector release listed on Cisco's release notes page is 3.8.7000, dated April 4 2024 16. Directory Connector requires .NET Framework 3.5 and .NET Framework 4.5 on supported Windows Server operating systems 267.
What remains uncertain
Whether the custom SCIM 2.0 Entra ID enterprise application can coexist with Directory Connector or the Entra ID Wizard App within the same organization is not covered by the sources below. The deletion threshold setting and its default value in Directory Connector are not covered by the sources below. The exact administrative procedure to unblock Directory Connector once blocked by the Wizard App setup is not covered by the sources below. The effect of unclaiming a verified domain on users who have already joined the organization is not covered by the sources below.
See also
Depends on
- Setting up SSO for a Webex organization — Okta sync requires Okta SSO first; SSO is out of scope here.
Related to
- Onboarding agents in Webex Contact Center — Contact Center agents are usually created by the directory sync this guide sets up.
- Setting up a Webex Calling location — Calling auto-assignment needs numbers pre-provisioned at a Calling location.
Sources
- 1When users arrive by directory synchronization (AD, Entra/Azure, Okta), Webex Calling auto-assignment uses the user's work phone number from the directory to find a pre-provisioned Webex Calling number.Set up automatic license assignment templates for Webex Calling users · How auto-assignment works - directory synchronization · Checked 2026-09-30
- 2For Calling auto-assignment the work number must be in E.164 format, pre-provisioned at a valid Webex Calling location, and not assigned to another user or service; otherwise the user is not provisioned with Webex Calling.Set up automatic license assignment templates for Webex Calling users · Prerequisites / validation · Checked 2026-09-30
- 3Directory Connector can upgrade itself automatically when 'Automatically upgrade to the new Cisco Directory Connector version' is checked under Configuration > General, and Cisco recommends enabling it.Deployment Guide for Directory Connector · Auto-upgrade setting · Checked 2026-09-30
- 4The Directory Connector dashboard shows current sync status, the two most recent sync results, cloud statistics and connector status, and the Windows event viewer is used to find sync issues.Deployment Guide for Directory Connector · Directory Connector dashboard / Troubleshooting · Checked 2026-09-30
- 5By default Directory Connector synchronizes all users that are not computers and all groups that are not critical system objects.Deployment Guide for Directory Connector · Configure object selection · Checked 2026-09-30
- 6Scheduled Directory Connector synchronization is turned off under Actions > Synchronization Mode > Disable Synchronization, and synchronized users remain in Webex but stop receiving AD updates.Deployment Guide for Directory Connector · Turn off directory synchronization / Deactivate · Checked 2026-09-30
- 7Directory Connector requires .NET Framework 3.5 and .NET Framework 4.5, the latter being required for TLS 1.2.Deployment Guide for Directory Connector · Requirements for Directory Connector · Checked 2026-09-30
- 8A Directory Connector dry run compares on-premises objects with Webex cloud objects and shows what will be added, modified or deleted, and the administrator chooses whether to retain or delete mismatched cloud users.Deployment Guide for Directory Connector · Perform a dry run synchronization · Checked 2026-09-30
- 9Directory synchronization is enabled and the connector installer downloaded from Control Hub under Users > Manage Users > Enable Directory Synchronization.Deployment Guide for Directory Connector · Install Directory Connector · Checked 2026-09-30
- 10The account used to sign in to Directory Connector must be a full administrator account in Control Hub.Deployment Guide for Directory Connector · Requirements for Directory Connector · Checked 2026-09-30
- 11A Directory Connector full synchronization sends all filtered AD objects and must run before incremental synchronizations begin.Deployment Guide for Directory Connector · Do a Full Synchronization of Active Directory Users Into the Cloud · Checked 2026-09-30
- 12Multiple Directory Connectors can be configured so a backup takes over if the main connector or its host goes down.Deployment Guide for Directory Connector · High availability · Checked 2026-09-30
- 13The Directory Connector host needs at least 8 GB RAM and 50 GB storage; no minimum CPU is specified.Deployment Guide for Directory Connector · Requirements for Directory Connector · Checked 2026-09-30
- 14The Directory Connector host needs outbound HTTPS (port 443) access to the internet.Deployment Guide for Directory Connector · Requirements for Directory Connector · Checked 2026-09-30
- 15Directory Connector's default incremental sync interval is every 4 hours on version 3.5 and later, and every 30 minutes on earlier versions.Deployment Guide for Directory Connector · Schedule synchronization / incremental synchronization · Checked 2026-09-30
- 16The latest Directory Connector release listed on Cisco's release notes page is 3.8.7000, dated April 4 2024, which added a field to exclude organizational units from sync.Directory Connector release notes · Release 3.8.7000 · Checked 2026-09-30
- 17Directory Connector object selection can be narrowed with LDAP filters for users and groups and by choosing the on-premises base DNs to synchronize.Deployment Guide for Directory Connector · Configure object selection - LDAP filters / On Premises Base DNs to Synchronize · Checked 2026-09-30
- 18Directory Connector treats a Webex user with no matching AD object as a mismatch no matter how that user was added to Webex, and can delete such users after the first full sync if the administrator chose delete.Deployment Guide for Directory Connector · Perform a dry run synchronization · Checked 2026-09-30
- 19A multi-domain Active Directory deployment needs one Directory Connector per Active Directory domain.Deployment Guide for Directory Connector · Install Directory Connector - multiple domains · Checked 2026-09-30
- 20Full and incremental sync schedules are set by day, hour and minute under Configuration > Connector Policy in Directory Connector.Deployment Guide for Directory Connector · Schedule synchronization · Checked 2026-09-30
- 21The Directory Connector service account (Local System or a domain account) must be able to connect to the domain controller and read Active Directory user objects.Deployment Guide for Directory Connector · Install Directory Connector - service account type · Checked 2026-09-30
- 22Users deleted by Directory Connector are kept in the Webex cloud identity service for 7 days before permanent deletion, and the guide documents recovering accidentally deleted users.Deployment Guide for Directory Connector · Recover Accidentally Deleted Users · Checked 2026-09-30
- 23An auto-assign licence template must be set up before it can apply to new users synchronized from Active Directory.Deployment Guide for Directory Connector · Do a Full Synchronization of Active Directory Users Into the Cloud · Checked 2026-09-30
- 24Directory Connector maps the Active Directory userAccountControl attribute to ds-pwp-account-disabled so disabled AD accounts are reflected in Webex.Deployment Guide for Directory Connector · Map User Attributes · Checked 2026-09-30
- 25In Directory Connector attribute mapping the only required Webex field is uid, and Cisco recommends mapping it from mail or userPrincipalName.Deployment Guide for Directory Connector · Map User Attributes · Checked 2026-09-30
- 26Cisco Directory Connector is supported on Windows Server 2025, 2022, 2019 and 2016.Deployment Guide for Directory Connector · Requirements for Directory Connector · Checked 2026-09-30
- 27Control Hub forces the administrator's own domain to be added and verified first, to prevent administrator lockout.Manage your domains · Claim a domain - ordering · Checked 2026-09-30
- 28A domain must be verified before it is claimed, and once claimed new users signing up with that domain join the organization rather than another or the free consumer organization.Manage your domains · Claim a domain · Checked 2026-09-30
- 29A domain is verified in Control Hub Organization Settings by publishing the Control Hub verification token as a DNS TXT record and then selecting Verify.Manage your domains · Add and verify a domain · Checked 2026-09-30
- 30When a synchronized user is deleted in Entra ID, Webex renames the user and marks them Inactive; restoring the user from the Entra recycle bin reactivates them and restores the original username.Manage synchronized Entra ID users · Entra ID actions and Webex results table - Delete user / Restore · Checked 2026-09-30
- 31When a synchronized user is permanently deleted in Entra ID, Webex deletes the user from the organization.Manage synchronized Entra ID users · Entra ID actions and Webex results table - Permanently delete · Checked 2026-09-30
- 32Unassigning a synchronized user from the Webex app in Entra ID, or blocking their sign-in, causes Webex to mark the user Inactive.Manage synchronized Entra ID users · Entra ID actions and Webex results table - Unassign / Block sign-in · Checked 2026-09-30
- 33If the username is not mapped to the users' email address, Entra ID provisions them into Control Hub as new users instead of matching existing users, so Cisco advises against changing default mappings.Manage synchronized Entra ID users · Attribute mappings warning · Checked 2026-09-30
- 34A synchronized group's name, description and membership cannot be changed in Control Hub because they are managed in the source directory.Group management in Control Hub · Synchronized groups · Checked 2026-09-30
- 35Control Hub group management lists Directory Connector (AD security groups) and Entra ID as synchronized group sources and says synchronized groups support automatic licence assignment.disputedGroup management in Control Hub · Group sources / Licence templates for groups · Checked 2026-09-30
- 36The legacy Cisco Webex Entra gallery app uses SCIM 1.1, and department and manager attributes require SCIM 2.0 instead.Legacy SCIM provisioning with the Cisco Webex Entra ID gallery app · Attribute mapping - custom mappings · Checked 2026-09-30
- 37Automatic licence templates grant licences to users at the point of user creation, and do not apply to users created with a specific licence already assigned.Set up automatic license assignments in Control Hub · Overview / Things to know · Checked 2026-09-30
- 38An organization-level licence template can also be applied to existing users, with a 'Preserve licenses for existing users' option that is checked by default.Set up automatic license assignments in Control Hub · Set up an organization-level template · Checked 2026-09-30
- 39Group-level licence templates require users and groups to be synchronized from Active Directory with Directory Connector.disputedSet up automatic license assignments in Control Hub · Group-level templates - prerequisites · Checked 2026-09-30
- 40Webex does not support licence auto-assignment to Active Directory distribution groups; only security groups are used for licences, settings and policies.Set up automatic license assignments in Control Hub · Group-level templates · Checked 2026-09-30
- 41Users receive the union of licences from the organization-level template and every group-level template that applies to them.Set up automatic license assignments in Control Hub · Group-level templates · Checked 2026-09-30
- 42In the Microsoft Entra Cisco Webex gallery app, users assigned with the Default Access role are excluded from provisioning.Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID · Important tips for assigning users to Cisco Webex · Checked 2026-09-30
- 43Microsoft's Cisco Webex provisioning tutorial instructs enabling notification emails for quarantine and accidental deletions prevention, and validating with on-demand provisioning for a few users before starting provisioning.Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID · Configuring automatic user provisioning to Cisco Webex - steps 10 and 16 · Checked 2026-09-30
- 44Microsoft labels the Cisco Webex gallery provisioning connector as Preview and states Cisco Webex is in Cisco's Early Field Testing phase.Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID · Introductory note / Connector limitations · Checked 2026-09-30
- 45Entra ID hard-deletes users 30 days after soft deletion, at which point the provisioning service sends a delete to the target app.Understand how Application Provisioning in Microsoft Entra ID · Incremental cycles step 9; Deprovisioning - configure your application to delete a user · Checked 2026-09-30
- 46The Entra provisioning service cannot read or provision users in nested groups; only immediate members of an assigned group are provisioned.Understand how Application Provisioning in Microsoft Entra ID · Scoping - Nested groups · Checked 2026-09-30
- 47Every operation run by the Entra provisioning service is recorded in the Microsoft Entra provisioning logs, which are the place to diagnose failed users.Understand how Application Provisioning in Microsoft Entra ID · How to tell if users are being provisioned properly; Errors and retries · Checked 2026-09-30
- 48An Entra provisioning job with consistent target errors enters quarantine, runs at most daily, and is disabled if it stays in quarantine more than four weeks.Understand how Application Provisioning in Microsoft Entra ID · Quarantine · Checked 2026-09-30
- 49The Entra provisioning service disables a user in the target app via an update when the user is unassigned, goes out of scope, or is disabled or soft-deleted in Entra ID; for SCIM apps a disable sets active to false.Understand how Application Provisioning in Microsoft Entra ID · Incremental cycles steps 7-8; Deprovisioning · Checked 2026-09-30
- 50Okta synchronization into Control Hub uses the Okta Integration Network app 'Cisco Webex Identity SCIM 2.0' and needs no on-premises infrastructure.Synchronize Okta users into Control Hub · Overview / Configure Okta · Checked 2026-09-30
- 51Okta deprovisioning deactivates rather than deletes Webex accounts, and the accounts can be reactivated if the user is reassigned.Synchronize Okta users into Control Hub · Supported features - Deactivate Users · Checked 2026-09-30
- 52The Okta integration creates users when assigned, overwrites Webex attributes on update, deactivates users when unassigned or deactivated in Okta, and creates, updates and deletes pushed groups.Synchronize Okta users into Control Hub · Supported features · Checked 2026-09-30
- 53An organization that already uses Directory Connector to synchronize users cannot synchronize users from Okta.Synchronize Okta users into Control Hub · Limitations · Checked 2026-09-30
- 54Before syncing from Okta, Cisco requires Okta SSO to be set up and automatic licence assignment templates to be configured, otherwise newly synced users get no Webex licences.Synchronize Okta users into Control Hub · Before you begin · Checked 2026-09-30
- 55The bearer token used for Webex SCIM 2.0 provisioning is valid for 365 days and then expires.SCIM 2.0 provisioning with a custom Webex app in Entra ID · Bearer token generation · Checked 2026-09-30
- 56A SCIM bearer token can be generated in Control Hub via Apps > Service apps > Get a token, or manually through an OAuth URL, and creating it requires a full administrator.Synchronize Okta users into Control Hub · Prerequisites / Get a bearer token · Checked 2026-09-30
- 57Entra ID does not synchronize null values to Webex, so clearing an attribute in Entra ID does not clear it in Webex.SCIM 2.0 provisioning with a custom Webex app in Entra ID · Limitations · Checked 2026-09-30
- 58The SCIM 2.0 tenant URL for commercial Webex is https://webexapis.com/identity/scim/{OrgId}/v2, with the organization ID copied from Control Hub.SCIM 2.0 provisioning with a custom Webex app in Entra ID · Tenant URL · Checked 2026-09-30
- 59Cisco positions the custom SCIM 2.0 Entra app for new setups needing wider SCIM 2.0 scope and more user attributes, while the Wizard App uses Microsoft Graph and supports groups, rooms and avatars that SCIM 2.0 does not.SCIM 2.0 provisioning with a custom Webex app in Entra ID · Introduction / comparison with Wizard App · Checked 2026-09-30
- 60If an organization enforces that all users must have a verified domain, Entra sync will not create users in unverified domains.Legacy SCIM provisioning with the Cisco Webex Entra ID gallery app · Before you begin - verified domains · Checked 2026-09-30
- 61When users are synchronized from a directory such as Active Directory, administrators cannot add users manually in Control Hub.Ways to add users to your Control Hub organization · Ways to add users - directory synchronization note · Checked 2026-09-30
- 62If Directory Connector is enabled, the Entra ID Wizard App setup asks the administrator to choose Entra ID and block Directory Connector before proceeding.Set up the Entra ID Wizard App in Control Hub · Set up the Wizard App · Checked 2026-09-30
- 63Before Auto Sync is enabled, the Wizard App can run a dry run with a downloadable dry-run report, and on-demand provisioning tests individual users outside the schedule.Set up the Entra ID Wizard App in Control Hub · Dry run / On-demand provisioning · Checked 2026-09-30
- 64The Wizard App synchronizes groups automatically every 12 hours.Set up the Entra ID Wizard App in Control Hub · Synchronization / Auto Sync · Checked 2026-09-30
- 65With the Wizard App, users removed from scope or inactive in Entra ID are skipped in synchronizations and continue to appear in the Control Hub organization until an administrator removes them.Set up the Entra ID Wizard App in Control Hub · User removal behaviour · Checked 2026-09-30
- 66Distribution groups from Entra ID cannot be synchronized into Control Hub by the Entra ID Wizard App.Set up the Entra ID Wizard App in Control Hub · Groups tab · Checked 2026-09-30
- 67Turning Wizard App Auto Sync off stops syncing but preserves the configuration, whereas Delete instance removes the configuration and requires full reconfiguration.Set up the Entra ID Wizard App in Control Hub · Auto Sync / Delete instance · Checked 2026-09-30
- 68Setting up the Entra ID Wizard App requires a Control Hub full administrator and an Entra ID account with authority to grant tenant-wide admin consent.Set up the Entra ID Wizard App in Control Hub · Before you begin / Prerequisites · Checked 2026-09-30
- 69The Entra ID Wizard App scopes sync by adding individual users (with a 'Select all users' option Cisco does not recommend for large enterprises) and by adding groups with 'Sync group members' or 'Sync children groups'.Set up the Entra ID Wizard App in Control Hub · Users tab / Groups tab · Checked 2026-09-30
- 70The Entra ID Wizard App is started from Control Hub Organization Settings > Microsoft Entra ID Wizard App > Set up, followed by an Entra admin sign-in that accepts the requested permissions.Set up the Entra ID Wizard App in Control Hub · Set up the Wizard App · Checked 2026-09-30
- 71The Wizard App shows a sync status of Active, Quarantine or NotRun along with counts of synced, skipped and failed objects.Set up the Entra ID Wizard App in Control Hub · Synchronization status · Checked 2026-09-30
- 72The Wizard App's default mapping sends Entra ID userPrincipalName to the Control Hub email address (username).Set up the Entra ID Wizard App in Control Hub · Attributes mapping · Checked 2026-09-30
- 73The Wizard App syncs users about every 40 minutes, per Microsoft policy.Set up the Entra ID Wizard App in Control Hub · Synchronization / Auto Sync · Checked 2026-09-30
Documents
Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID
Deployment Guide for Directory Connector
Directory Connector release notes
Group management in Control Hub
Legacy SCIM provisioning with the Cisco Webex Entra ID gallery app
Manage synchronized Entra ID users
Manage your domains
SCIM 2.0 provisioning with a custom Webex app in Entra ID
Set up automatic license assignment templates for Webex Calling users
Set up automatic license assignments in Control Hub
Set up the Entra ID Wizard App in Control Hub
Synchronize Okta users into Control Hub
Understand how Application Provisioning in Microsoft Entra ID
Ways to add users to your Control Hub organization
Cite this page
APA
WarmTransfer. (2026, September 30). Synchronizing users into Webex from Entra ID or Active Directory. WarmTransfer. https://warmtransfer.net/guides/webex-directory-sync-setup
BibTeX
@misc{warmtransfer-webex-directory-sync-setup,
title = {Synchronizing users into Webex from Entra ID or Active Directory},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/webex-directory-sync-setup},
note = {Verified 2026-09-30}
}