# Synchronizing users into Webex from Entra ID or Active Directory

For Webex Control Hub full administrators configuring automated directory synchronization and licensing.

Canonical: https://warmtransfer.net/guides/webex-directory-sync-setup

Last verified: 2026-09-30

Directory synchronization populates Webex Control Hub user identities directly from external directories and applies automated service entitlements[^37]. When configured with automated licence templates, users receive designated services upon account creation[^37].

## Before you start

- Ensure you hold a full administrator account in Webex Control Hub[^10][^68].
- If synchronizing from Okta, configure Okta SSO beforehand, as Cisco requires SSO and licence assignment templates prior to syncing[^54].
- If synchronizing from on-premises Active Directory, prepare a Windows Server 2025, 2022, 2019, or 2016 host with.NET Framework 3.5 and.NET Framework 4.5, at least 8 GB RAM, 50 GB storage, and outbound HTTPS access on port 443[^26][^7][^13][^14].
- Note that when users are synchronized from an external directory, administrators cannot add users manually in Control Hub[^61].

## What changes by situation

- Where do your user identities originate and which synchronization method will you use? On-premises Active Directory with Cisco Directory Connector; Microsoft Entra ID with the Control Hub Entra ID Wizard App; Microsoft Entra ID with a custom SCIM 2.0 enterprise application; Okta with the Cisco Webex Identity SCIM 2.0 application.
- How will automated licence templates be assigned? Organization-level automatic licence template; Group-level licence templates mapped to directory groups.
- Should synchronized users be provisioned with Webex Calling? Yes, include Webex Calling in the licence template; No, exclude Webex Calling from the template.

## Step 1: Verify and claim your email domains

### Do
In Control Hub Organization Settings, add each email domain, add the generated verification token as a DNS TXT record in your DNS provider, and select Verify[^29]. Add and verify the domain used by your administrator account first, because Control Hub enforces this sequence to avoid administrator lockout[^27]. After verification, claim the domain so that new user registrations using that domain automatically join your organization instead of a free consumer organization[^28].

### Verify
Suggested check: Ensure each required domain displays as verified and claimed in Control Hub. If your organization enforces that all users must belong to a verified domain, Entra sync will not create users residing in unverified domains[^60].

### Rollback
Suggested rollback: Remove the DNS TXT records from your DNS provider and delete the domains from Control Hub Organization Settings.

## Step 2: Check for conflicting synchronization methods

**On-premises Active Directory with Cisco Directory Connector**

### Do
Confirm that no cloud synchronization method, such as the Entra ID Wizard App, is configured to block on-premises synchronization[^62].

### Verify
Suggested check: Navigate to the Directory Synchronization area in Control Hub to verify that on-premises connector setup is available.

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
If Cisco Directory Connector is currently enabled, disable scheduled synchronization under Actions > Synchronization Mode > Disable Synchronization in Directory Connector[^6]. In Control Hub, proceed with the Entra ID Wizard App setup prompt to choose Entra ID and block Directory Connector[^62].

### Verify
Confirm that Directory Connector synchronization schedule is disabled and that the Wizard App setup continues past the connector block prompt[^6][^62].

### Rollback
Suggested rollback: Close the Wizard App setup dialog and re-evaluate directory synchronization settings.

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
In Microsoft Entra ID, create a custom enterprise application for SCIM 2.0 provisioning rather than configuring conflicting synchronization[^59].

### Verify
Suggested check: Confirm in Control Hub that only one provisioning application manages the scoped user group.

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Confirm that Directory Connector is not enabled in the organization, as an organization using Directory Connector cannot synchronize users from Okta[^53].

### Verify
Ensure Directory Connector is completely absent or disabled in Control Hub before proceeding[^53].

## Step 3: Configure automatic licence templates

**Organization-level automatic licence template + On-premises Active Directory with Cisco Directory Connector**

### Do
Create an organization-level automatic licence template in Control Hub so that newly synchronized users receive services upon creation[^37][^23]. If desired, enable the option to apply to existing users; note that the 'Preserve licenses for existing users' setting is checked by default[^38].

### Verify
Confirm that the template appears as active in Control Hub before initiating synchronization[^23].

### Rollback
Suggested rollback: Deactivate or modify the organization-level licence template in Control Hub.

**Group-level licence templates mapped to directory groups + On-premises Active Directory with Cisco Directory Connector**

### Do
Configure group-level licence templates in Control Hub and map them specifically to Active Directory security groups[^40]. Do not map templates to distribution groups, as Webex does not support automatic licence assignment for distribution groups[^40]. Users belonging to multiple groups will receive the union of all matching group templates and any organization-level template[^41].

### Verify
Verify that all mapped groups are designated as security groups and have active template assignments[^40].

### Rollback
Suggested rollback: Remove the group mappings from the licence template.

**Organization-level automatic licence template + Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Create an organization-level automatic licence template in Control Hub[^37]. If applying to existing users, note that 'Preserve licenses for existing users' is enabled by default[^38].

### Verify
Confirm the template is saved and active in Control Hub before starting synchronization[^37].

### Rollback
Suggested rollback: Edit or remove the organization-level template in Control Hub.

**Group-level licence templates mapped to directory groups + Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Configure group-level licence templates in Control Hub and create an organization-level template as an operational fallback[^41]. Note that distribution groups cannot be synchronized with the Entra ID Wizard App[^66].

### Verify
Suggested check: Verify that the group templates are configured against synchronized security groups in Control Hub.

### Rollback
Suggested rollback: Remove group template mappings in Control Hub.

**Organization-level automatic licence template + Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Configure an organization-level automatic licence assignment template in Control Hub prior to provisioning[^37].

### Verify
Confirm that the template is active in Control Hub[^37].

### Rollback
Suggested rollback: Remove or update the template in Control Hub.

**Group-level licence templates mapped to directory groups + Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Configure an organization-level licence template in Control Hub as the primary method, noting that Cisco positions the Wizard App rather than custom SCIM 2.0 when group synchronization is required[^59].

### Verify
Ensure the organization-level licence assignment template is active[^37].

### Rollback
Suggested rollback: Modify or delete the licence assignment template.

**Organization-level automatic licence template + Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Set up an organization-level automatic licence template in Control Hub before enabling synchronization, as Cisco requires licence templates to avoid users arriving without licences[^54].

### Verify
Verify the licence template exists and is active in Control Hub[^54].

### Rollback
Suggested rollback: Deactivate or alter the template in Control Hub.

**Group-level licence templates mapped to directory groups + Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Configure an organization-level licence template in Control Hub, as Cisco requires automatic licence assignment templates prior to Okta synchronization[^54].

### Verify
Confirm that the licence assignment template is active in Control Hub[^54].

### Rollback
Suggested rollback: Deactivate or delete the template in Control Hub.

## Step 4: Configure Webex Calling number pre-provisioning

**Yes, include Webex Calling in the licence template**

### Do
For directory synchronization, Webex Calling automatic assignment uses the user's work phone number from the directory to look up a pre-provisioned number[^1]. Pre-provision the phone numbers at the target Webex Calling location in E.164 format and ensure the numbers are unassigned[^2]. Populate each user's work phone attribute in the identity directory with the exact matching E.164 number[^2]. Include Webex Calling in your licence template[^1]. See also [Setting up a Webex Calling location](https://warmtransfer.net/knowledge/webex-calling-location-setup).

### Verify
Check that the work numbers in the directory match unassigned, pre-provisioned E.164 numbers in Webex Calling; if validation fails, the user is not provisioned with Webex Calling[^2].

### Rollback
Suggested rollback: Remove Webex Calling from the licence template in Control Hub.

**No, exclude Webex Calling from the template**

### Do
Ensure Webex Calling is not selected in the organization or group licence templates[^37].

### Verify
Suggested check: Review the active licence templates to confirm Webex Calling is excluded.

## Step 5: Connect or install the synchronization engine

**On-premises Active Directory with Cisco Directory Connector**

### Do
In Control Hub, go to Users > Manage Users > Enable Directory Synchronization and download the connector installer[^9]. Install the connector on a Windows Server host using a service account (Local System or domain) that can reach the domain controller and read Active Directory user objects[^21][^26]. Sign in to Directory Connector using a Control Hub full administrator account[^10]. If managing multiple domains, install one connector per Active Directory domain[^19]. Deploy a second connector if high availability backup is required[^12]. Under Configuration > General, check 'Automatically upgrade to the new Cisco Directory Connector version'[^3].

### Verify
Confirm that the Directory Connector signs in and the dashboard displays active connector status[^4].

### Rollback
Suggested rollback: Uninstall the connector software from the host. Synchronized users remain in Webex but stop receiving updates[^6].

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Sign in to Control Hub as a full administrator and navigate to Organization Settings > Microsoft Entra ID Wizard App > Set up[^68][^70]. Authenticate with an Entra ID account authorized to grant tenant-wide admin consent and accept the requested permissions[^68][^70].

### Verify
Confirm that consent succeeds and the Wizard App displays its configuration tabs[^70].

### Rollback
Suggested rollback: In Control Hub, use the Delete instance action on the Wizard App to remove the configuration[^67].

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
In Microsoft Entra ID, create a custom enterprise application for SCIM 2.0 provisioning[^59]. In Control Hub, navigate to Apps > Service apps > Get a token as a full administrator to generate a SCIM bearer token[^56]. In Entra ID, set the Tenant URL to `https://webexapis.com/identity/scim/{OrgId}/v2` using your Control Hub organization ID, and supply the bearer token[^58][^56]. In provisioning settings, enable notification emails for quarantine and configure accidental deletions prevention[^43].

### Verify
In Entra ID, select Test Connection and verify that the SCIM connection test succeeds[^43].

### Rollback
Suggested rollback: In Entra ID, delete the custom enterprise application.

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
In the Okta admin portal, add the 'Cisco Webex Identity SCIM 2.0' application from the Okta Integration Network[^50]. Set the base URL to `https://webexapis.com/identity/scim/{OrgId}/v2` using your organization ID[^58]. In Control Hub, navigate to Apps > Service apps > Get a token as a full administrator and paste the resulting token into Okta's API integration credentials[^56].

### Verify
In Okta, test API credentials and verify that the integration test succeeds[^50].

### Rollback
Suggested rollback: Disable provisioning or remove the Webex application in Okta.

## Step 6: Define user and group synchronization scope

**On-premises Active Directory with Cisco Directory Connector**

### Do
By default, Directory Connector synchronizes all users that are not computers and all groups that are not critical system objects[^5]. Define LDAP filters for users and groups and specify on-premises Base DNs under object selection to narrow the synchronization scope[^17]. If group licence templates are used, ensure that Groups are included in object selection and that only security groups are mapped[^40].

### Verify
Suggested check: Review LDAP filter syntax and Base DN scopes to confirm they point to intended organizational units.

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
In the Wizard App configuration tabs, scope synchronization by adding individual users or by adding groups using 'Sync group members' or 'Sync children groups'[^69]. Avoid using 'Select all users' if configuring a large tenant[^69]. Do not attempt to add distribution groups, as they are not supported[^66].

### Verify
Verify that the Users and Groups tabs list only the intended individual accounts and security groups[^69].

### Rollback
Suggested rollback: Remove individual users or groups from the Wizard App scope tabs.

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Assign users or security groups to the custom SCIM enterprise application in Entra ID[^42]. Ensure each assignment uses a role other than Default Access, as users assigned with Default Access are excluded from provisioning[^42]. Assign users directly or via immediate parent groups; do not rely on nested groups, as the Entra provisioning service cannot read or provision nested group members[^46].

### Verify
Verify the application assignments list in Entra ID to ensure target groups have specific assigned roles rather than Default Access[^42].

### Rollback
Suggested rollback: Unassign users or groups from the enterprise application in Entra ID[^49].

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
In Okta, assign the target users and security groups to the Cisco Webex Identity SCIM 2.0 application, and configure Push Groups for groups that should sync to Control Hub[^52].

### Verify
Verify in Okta that assignments and pushed groups show an active status without synchronization errors[^52].

### Rollback
Suggested rollback: Remove user assignments or push group configurations in Okta.

## Step 7: Map attributes and username identity

**On-premises Active Directory with Cisco Directory Connector**

### Do
Under attribute mapping in Directory Connector, map the required uid field from mail or userPrincipalName[^25]. Retain the default mapping of userAccountControl to ds-pwp-account-disabled to reflect disabled accounts in Webex[^24].

### Verify
Suggested check: Confirm that uid is mapped to an attribute containing valid email addresses to avoid duplicate accounts.

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Retain the default attribute mapping in the Wizard App, which maps userPrincipalName to the Control Hub email address (username)[^72]. Do not change this default, because mapping the username away from the email address causes Entra ID to create duplicate accounts instead of matching existing users[^33].

### Verify
Check the attribute mapping tab in the Wizard App to confirm userPrincipalName maps to email[^72].

### Rollback
Suggested rollback: Revert attribute mappings to defaults in the Wizard App.

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Map userPrincipalName in Entra ID to the Webex userName attribute[^72]. Note that Entra ID does not synchronize null values to Webex, meaning clearing an attribute in Entra ID will not clear that attribute in Webex[^57].

### Verify
Review the attribute mapping table in Entra ID to confirm userPrincipalName maps to userName and email[^72].

### Rollback
Suggested rollback: Restore previous attribute mapping definitions in Entra ID.

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Ensure the username in Okta is mapped to the user's primary email address[^33]. Note that Okta attribute updates overwrite existing attribute values in Webex[^52].

### Verify
Suggested check: Verify the attribute mapping in the Okta application integration settings.

## Step 8: Perform a dry run or pilot synchronization

**On-premises Active Directory with Cisco Directory Connector**

### Do
Perform a dry run synchronization from Directory Connector[^8]. Review the dry run report showing objects that will be added, modified, or deleted[^8]. Select the option to retain mismatched cloud users unless deletion of users added outside AD is explicitly desired, because Directory Connector flags any Webex user lacking a matching AD object as a mismatch[^8][^18].

### Verify
Verify that the counts of added, modified, and deleted objects align with your planned scope[^8].

### Rollback
Suggested rollback: Adjust LDAP filters or Base DNs if dry run counts reflect incorrect objects.

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Run a dry run in the Wizard App and download the dry-run report, using on-demand provisioning to test individual users outside the schedule before enabling automated synchronization[^63].

### Verify
Inspect the dry-run report for errors and verify that the on-demand test users appear in Control Hub with expected licences[^63][^37].

### Rollback
Suggested rollback: Unassign or remove pilot test users from the Wizard App.

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Perform on-demand provisioning in Entra ID for a few users before starting provisioning[^43].

### Verify
Review the Microsoft Entra provisioning logs to verify successful user creation in Webex[^47].

### Rollback
Suggested rollback: Unassign the test users in Entra ID to disable them in Webex[^49].

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Assign a single pilot test user to the Okta Webex application[^52].

### Verify
Check Control Hub to confirm the pilot user appears and has received the automatic template licences[^54].

### Rollback
Suggested rollback: Unassign the pilot user in Okta, which deactivates the account in Webex[^51].

## Step 9: Run full synchronization and schedule recurring jobs

**On-premises Active Directory with Cisco Directory Connector**

### Do
Execute a full synchronization in Directory Connector, which sends all filtered AD objects and is required before incremental synchronizations can begin[^11]. Under Configuration > Connector Policy, configure the full and incremental synchronization schedules by day, hour, and minute[^20]. On version 3.5 and later, the default incremental interval is every 4 hours[^15].

### Verify
Review the Directory Connector dashboard to confirm current sync status, the two most recent sync results, connector status, and cloud statistics[^4].

### Rollback
Suggested rollback: Under Actions > Synchronization Mode, select Disable Synchronization to halt scheduled sync cycles[^6].

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Enable Auto Sync in the Wizard App[^73]. The Wizard App synchronizes users approximately every 40 minutes and synchronizes groups automatically every 12 hours[^73][^64].

### Verify
Confirm that the synchronization status displays as Active and check the counts of synced, skipped, and failed objects[^71].

### Rollback
Suggested rollback: Turn off Auto Sync to stop synchronization without deleting the configuration[^67].

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Start provisioning in the Entra ID custom enterprise application[^43].

### Verify
Check the Microsoft Entra provisioning logs to ensure incremental cycles process without entering quarantine[^47][^48].

### Rollback
Suggested rollback: Stop provisioning from the enterprise application overview in Entra ID.

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Assign the remaining user population and ensure Push Groups are active in Okta[^52].

### Verify
Suggested check: Review Okta provisioning task logs and verify that user creation events succeed.

### Rollback
Suggested rollback: Unassign user groups in Okta[^52].

## Step 10: Verify provisioned users and licence allocation

### Do
Open Users and Groups in Control Hub to inspect provisioned accounts[^34]. Note that a synchronized group's name, description, and membership cannot be modified in Control Hub because they are managed directly in the source directory[^34].

### Verify
Confirm that provisioned users have their expected licences assigned[^37]. If group templates were used, verify that users belonging to multiple groups show the combined union of licences[^41].

### Rollback
Suggested rollback: Adjust group memberships in the identity source or modify template rules in Control Hub.

## Step 11: Test deprovisioning workflows

**On-premises Active Directory with Cisco Directory Connector**

### Do
Disable a test user in Active Directory or move them outside the configured Base DN scope, then execute a synchronization run[^24][^22]. Disabling the user in AD updates ds-pwp-account-disabled in Webex via userAccountControl mapping[^24]. If deleted, Directory Connector keeps deleted users in the Webex cloud identity service for 7 days before permanent deletion[^22].

### Verify
Confirm that the test user is marked disabled or moved to deleted status in Control Hub[^24][^22].

### Rollback
Suggested rollback: Re-enable the user in AD or restore them within the cloud identity recovery window.

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Unassign a test user from the Webex app in Entra ID, block their sign-in, or delete them in Entra ID[^32][^30]. When a user is deleted in Entra ID, Webex renames the user and marks them Inactive[^30]. If a user is permanently deleted in Entra ID, Webex deletes the user from the organization[^31].

### Verify
Verify that unassigned, blocked, or deleted test users transition to Inactive in Control Hub[^32][^30].

### Rollback
Suggested rollback: Reassign the user in Entra ID or restore them from the Entra recycle bin to reactivate them and restore their original username[^30].

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Unassign a test user from the enterprise application in Entra ID[^49]. The Entra provisioning service disables the user by setting the SCIM active attribute to false, which Webex marks as Inactive[^49][^32]. Note that Entra ID hard-deletes users 30 days after soft deletion, at which point the provisioning service issues a delete operation to Webex[^45].

### Verify
Review the Entra provisioning logs to confirm the update setting active to false, and verify in Control Hub that the user is Inactive[^49][^32].

### Rollback
Suggested rollback: Reassign the user to the enterprise application in Entra ID[^49].

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Unassign or deactivate a test user in Okta[^51]. Okta deprovisioning deactivates rather than deletes Webex accounts[^51].

### Verify
Confirm in Control Hub that the user account displays as deactivated[^51].

### Rollback
Suggested rollback: Reassign the user in Okta to reactivate the Webex account[^51].

## Step 12: Establish recurring operational maintenance

**On-premises Active Directory with Cisco Directory Connector**

### Do
Keep automatic upgrades enabled under Configuration > General in Directory Connector[^3]. Note that release 3.8.7000 added a field to exclude organizational units from sync[^16]. Use the Windows event viewer to review and troubleshoot any synchronization failures[^4].

### Verify
Check the Directory Connector dashboard regularly to verify recurring scheduled sync results[^4].

**Microsoft Entra ID with the Control Hub Entra ID Wizard App**

### Do
Schedule routine checks of the Wizard App synchronization status tab in Control Hub[^71].

### Verify
Verify that sync status remains Active and investigate any entries in Quarantine or elevated failed object counts[^71].

**Microsoft Entra ID with a custom SCIM 2.0 enterprise application**

### Do
Track bearer token expiration on your administrative calendar, noting that the bearer token used for Webex SCIM 2.0 provisioning is valid for 365 days and then expires[^55]. Monitor administrator email notifications for provisioning quarantine alerts[^43]. A provisioning job with consistent errors enters quarantine, runs at most daily, and is disabled if it remains in quarantine for more than 4 weeks[^48].

### Verify
Suggested check: Confirm that a reminder is scheduled prior to bearer token expiration.

**Okta with the Cisco Webex Identity SCIM 2.0 application**

### Do
Schedule a recurring calendar reminder to renew the SCIM bearer token in Okta before its 365-day validity window expires[^55].

### Verify
Suggested check: Verify that the bearer token expiration date is documented in operational runbooks.

## Applicability

Applies to: Cisco Webex Calling, Cisco Directory Connector, Cisco Webex Control Hub, Cisco Webex Control Hub with Entra ID synchronization, Microsoft Entra ID provisioning - Cisco Webex gallery app, Microsoft Entra ID application provisioning service, Cisco Webex Control Hub with Okta SCIM 2.0, Cisco Webex Identity SCIM 2.0 API, Cisco Webex Control Hub SCIM 2.0 with custom Entra ID enterprise app, and Cisco Webex Control Hub Entra ID Wizard App. Deployments: multi-tenant and on-premises-connector. Sources checked 2026-09-30. The latest Directory Connector release listed on Cisco's release notes page is 3.8.7000, dated April 4 2024[^16]. Directory Connector requires.NET Framework 3.5 and.NET Framework 4.5 on supported Windows Server operating systems[^26][^7].

## What remains uncertain

Whether the custom SCIM 2.0 Entra ID enterprise application can coexist with Directory Connector or the Entra ID Wizard App within the same organization is not covered by the sources below. The deletion threshold setting and its default value in Directory Connector are not covered by the sources below. The exact administrative procedure to unblock Directory Connector once blocked by the Wizard App setup is not covered by the sources below. The effect of unclaiming a verified domain on users who have already joined the organization is not covered by the sources below.

## Sources

[^1]: When users arrive by directory synchronization (AD, Entra/Azure, Okta), Webex Calling auto-assignment uses the user's work phone number from the directory to find a pre-provisioned Webex Calling number. Source: [Set up automatic license assignment templates for Webex Calling users](https://help.webex.com/en-us/article/n8iptxg/Set-up-automatic-license-assignment-templates-for-Webex-Calling-users), How auto-assignment works - directory synchronization. Checked 2026-09-30.
[^2]: For Calling auto-assignment the work number must be in E.164 format, pre-provisioned at a valid Webex Calling location, and not assigned to another user or service; otherwise the user is not provisioned with Webex Calling. Source: [Set up automatic license assignment templates for Webex Calling users](https://help.webex.com/en-us/article/n8iptxg/Set-up-automatic-license-assignment-templates-for-Webex-Calling-users), Prerequisites / validation. Checked 2026-09-30.
[^3]: Directory Connector can upgrade itself automatically when 'Automatically upgrade to the new Cisco Directory Connector version' is checked under Configuration > General, and Cisco recommends enabling it. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Auto-upgrade setting. Checked 2026-09-30.
[^4]: The Directory Connector dashboard shows current sync status, the two most recent sync results, cloud statistics and connector status, and the Windows event viewer is used to find sync issues. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Directory Connector dashboard / Troubleshooting. Checked 2026-09-30.
[^5]: By default Directory Connector synchronizes all users that are not computers and all groups that are not critical system objects. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Configure object selection. Checked 2026-09-30.
[^6]: Scheduled Directory Connector synchronization is turned off under Actions > Synchronization Mode > Disable Synchronization, and synchronized users remain in Webex but stop receiving AD updates. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Turn off directory synchronization / Deactivate. Checked 2026-09-30.
[^7]: Directory Connector requires .NET Framework 3.5 and .NET Framework 4.5, the latter being required for TLS 1.2. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Requirements for Directory Connector. Checked 2026-09-30.
[^8]: A Directory Connector dry run compares on-premises objects with Webex cloud objects and shows what will be added, modified or deleted, and the administrator chooses whether to retain or delete mismatched cloud users. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Perform a dry run synchronization. Checked 2026-09-30.
[^9]: Directory synchronization is enabled and the connector installer downloaded from Control Hub under Users > Manage Users > Enable Directory Synchronization. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Install Directory Connector. Checked 2026-09-30.
[^10]: The account used to sign in to Directory Connector must be a full administrator account in Control Hub. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Requirements for Directory Connector. Checked 2026-09-30.
[^11]: A Directory Connector full synchronization sends all filtered AD objects and must run before incremental synchronizations begin. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Do a Full Synchronization of Active Directory Users Into the Cloud. Checked 2026-09-30.
[^12]: Multiple Directory Connectors can be configured so a backup takes over if the main connector or its host goes down. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), High availability. Checked 2026-09-30.
[^13]: The Directory Connector host needs at least 8 GB RAM and 50 GB storage; no minimum CPU is specified. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Requirements for Directory Connector. Checked 2026-09-30.
[^14]: The Directory Connector host needs outbound HTTPS (port 443) access to the internet. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Requirements for Directory Connector. Checked 2026-09-30.
[^15]: Directory Connector's default incremental sync interval is every 4 hours on version 3.5 and later, and every 30 minutes on earlier versions. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Schedule synchronization / incremental synchronization. Checked 2026-09-30.
[^16]: The latest Directory Connector release listed on Cisco's release notes page is 3.8.7000, dated April 4 2024, which added a field to exclude organizational units from sync. Source: [Directory Connector release notes](https://help.webex.com/article/nqvsbmq), Release 3.8.7000. Checked 2026-09-30.
[^17]: Directory Connector object selection can be narrowed with LDAP filters for users and groups and by choosing the on-premises base DNs to synchronize. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Configure object selection - LDAP filters / On Premises Base DNs to Synchronize. Checked 2026-09-30.
[^18]: Directory Connector treats a Webex user with no matching AD object as a mismatch no matter how that user was added to Webex, and can delete such users after the first full sync if the administrator chose delete. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Perform a dry run synchronization. Checked 2026-09-30.
[^19]: A multi-domain Active Directory deployment needs one Directory Connector per Active Directory domain. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Install Directory Connector - multiple domains. Checked 2026-09-30.
[^20]: Full and incremental sync schedules are set by day, hour and minute under Configuration > Connector Policy in Directory Connector. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Schedule synchronization. Checked 2026-09-30.
[^21]: The Directory Connector service account (Local System or a domain account) must be able to connect to the domain controller and read Active Directory user objects. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Install Directory Connector - service account type. Checked 2026-09-30.
[^22]: Users deleted by Directory Connector are kept in the Webex cloud identity service for 7 days before permanent deletion, and the guide documents recovering accidentally deleted users. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Recover Accidentally Deleted Users. Checked 2026-09-30.
[^23]: An auto-assign licence template must be set up before it can apply to new users synchronized from Active Directory. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Do a Full Synchronization of Active Directory Users Into the Cloud. Checked 2026-09-30.
[^24]: Directory Connector maps the Active Directory userAccountControl attribute to ds-pwp-account-disabled so disabled AD accounts are reflected in Webex. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Map User Attributes. Checked 2026-09-30.
[^25]: In Directory Connector attribute mapping the only required Webex field is uid, and Cisco recommends mapping it from mail or userPrincipalName. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Map User Attributes. Checked 2026-09-30.
[^26]: Cisco Directory Connector is supported on Windows Server 2025, 2022, 2019 and 2016. Source: [Deployment Guide for Directory Connector](https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector), Requirements for Directory Connector. Checked 2026-09-30.
[^27]: Control Hub forces the administrator's own domain to be added and verified first, to prevent administrator lockout. Source: [Manage your domains](https://help.webex.com/en-us/article/cd6d84/manage-your-domains), Claim a domain - ordering. Checked 2026-09-30.
[^28]: A domain must be verified before it is claimed, and once claimed new users signing up with that domain join the organization rather than another or the free consumer organization. Source: [Manage your domains](https://help.webex.com/en-us/article/cd6d84/manage-your-domains), Claim a domain. Checked 2026-09-30.
[^29]: A domain is verified in Control Hub Organization Settings by publishing the Control Hub verification token as a DNS TXT record and then selecting Verify. Source: [Manage your domains](https://help.webex.com/en-us/article/cd6d84/manage-your-domains), Add and verify a domain. Checked 2026-09-30.
[^30]: When a synchronized user is deleted in Entra ID, Webex renames the user and marks them Inactive; restoring the user from the Entra recycle bin reactivates them and restores the original username. Source: [Manage synchronized Entra ID users](https://help.webex.com/en-us/article/d3p9vfb/Manage-synchronized-Entra-ID-users), Entra ID actions and Webex results table - Delete user / Restore. Checked 2026-09-30.
[^31]: When a synchronized user is permanently deleted in Entra ID, Webex deletes the user from the organization. Source: [Manage synchronized Entra ID users](https://help.webex.com/en-us/article/d3p9vfb/Manage-synchronized-Entra-ID-users), Entra ID actions and Webex results table - Permanently delete. Checked 2026-09-30.
[^32]: Unassigning a synchronized user from the Webex app in Entra ID, or blocking their sign-in, causes Webex to mark the user Inactive. Source: [Manage synchronized Entra ID users](https://help.webex.com/en-us/article/d3p9vfb/Manage-synchronized-Entra-ID-users), Entra ID actions and Webex results table - Unassign / Block sign-in. Checked 2026-09-30.
[^33]: If the username is not mapped to the users' email address, Entra ID provisions them into Control Hub as new users instead of matching existing users, so Cisco advises against changing default mappings. Source: [Manage synchronized Entra ID users](https://help.webex.com/en-us/article/d3p9vfb/Manage-synchronized-Entra-ID-users), Attribute mappings warning. Checked 2026-09-30.
[^34]: A synchronized group's name, description and membership cannot be changed in Control Hub because they are managed in the source directory. Source: [Group management in Control Hub](https://help.webex.com/en-us/article/7eedy0/Group-management-in-Control-Hub), Synchronized groups. Checked 2026-09-30.
[^35]: Control Hub group management lists Directory Connector (AD security groups) and Entra ID as synchronized group sources and says synchronized groups support automatic licence assignment (disputed). Source: [Group management in Control Hub](https://help.webex.com/en-us/article/7eedy0/Group-management-in-Control-Hub), Group sources / Licence templates for groups. Checked 2026-09-30.
[^36]: The legacy Cisco Webex Entra gallery app uses SCIM 1.1, and department and manager attributes require SCIM 2.0 instead. Source: [Legacy SCIM provisioning with the Cisco Webex Entra ID gallery app](https://help.webex.com/en-us/article/6ta3gz/Synchronize-Entra-ID-users-into-Control-Hub), Attribute mapping - custom mappings. Checked 2026-09-30.
[^37]: Automatic licence templates grant licences to users at the point of user creation, and do not apply to users created with a specific licence already assigned. Source: [Set up automatic license assignments in Control Hub](https://help.webex.com/en-us/article/n3ijtao/Set-up-automatic-license-assignments-in-Control-Hub), Overview / Things to know. Checked 2026-09-30.
[^38]: An organization-level licence template can also be applied to existing users, with a 'Preserve licenses for existing users' option that is checked by default. Source: [Set up automatic license assignments in Control Hub](https://help.webex.com/en-us/article/n3ijtao/Set-up-automatic-license-assignments-in-Control-Hub), Set up an organization-level template. Checked 2026-09-30.
[^39]: Group-level licence templates require users and groups to be synchronized from Active Directory with Directory Connector (disputed). Source: [Set up automatic license assignments in Control Hub](https://help.webex.com/en-us/article/n3ijtao/Set-up-automatic-license-assignments-in-Control-Hub), Group-level templates - prerequisites. Checked 2026-09-30.
[^40]: Webex does not support licence auto-assignment to Active Directory distribution groups; only security groups are used for licences, settings and policies. Source: [Set up automatic license assignments in Control Hub](https://help.webex.com/en-us/article/n3ijtao/Set-up-automatic-license-assignments-in-Control-Hub), Group-level templates. Checked 2026-09-30.
[^41]: Users receive the union of licences from the organization-level template and every group-level template that applies to them. Source: [Set up automatic license assignments in Control Hub](https://help.webex.com/en-us/article/n3ijtao/Set-up-automatic-license-assignments-in-Control-Hub), Group-level templates. Checked 2026-09-30.
[^42]: In the Microsoft Entra Cisco Webex gallery app, users assigned with the Default Access role are excluded from provisioning. Source: [Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/cisco-webex-provisioning-tutorial), Important tips for assigning users to Cisco Webex. Checked 2026-09-30.
[^43]: Microsoft's Cisco Webex provisioning tutorial instructs enabling notification emails for quarantine and accidental deletions prevention, and validating with on-demand provisioning for a few users before starting provisioning. Source: [Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/cisco-webex-provisioning-tutorial), Configuring automatic user provisioning to Cisco Webex - steps 10 and 16. Checked 2026-09-30.
[^44]: Microsoft labels the Cisco Webex gallery provisioning connector as Preview and states Cisco Webex is in Cisco's Early Field Testing phase. Source: [Configure Cisco Webex for automatic user provisioning with Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/saas-apps/cisco-webex-provisioning-tutorial), Introductory note / Connector limitations. Checked 2026-09-30.
[^45]: Entra ID hard-deletes users 30 days after soft deletion, at which point the provisioning service sends a delete to the target app. Source: [Understand how Application Provisioning in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/how-provisioning-works), Incremental cycles step 9; Deprovisioning - configure your application to delete a user. Checked 2026-09-30.
[^46]: The Entra provisioning service cannot read or provision users in nested groups; only immediate members of an assigned group are provisioned. Source: [Understand how Application Provisioning in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/how-provisioning-works), Scoping - Nested groups. Checked 2026-09-30.
[^47]: Every operation run by the Entra provisioning service is recorded in the Microsoft Entra provisioning logs, which are the place to diagnose failed users. Source: [Understand how Application Provisioning in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/how-provisioning-works), How to tell if users are being provisioned properly; Errors and retries. Checked 2026-09-30.
[^48]: An Entra provisioning job with consistent target errors enters quarantine, runs at most daily, and is disabled if it stays in quarantine more than four weeks. Source: [Understand how Application Provisioning in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/how-provisioning-works), Quarantine. Checked 2026-09-30.
[^49]: The Entra provisioning service disables a user in the target app via an update when the user is unassigned, goes out of scope, or is disabled or soft-deleted in Entra ID; for SCIM apps a disable sets active to false. Source: [Understand how Application Provisioning in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/how-provisioning-works), Incremental cycles steps 7-8; Deprovisioning. Checked 2026-09-30.
[^50]: Okta synchronization into Control Hub uses the Okta Integration Network app 'Cisco Webex Identity SCIM 2.0' and needs no on-premises infrastructure. Source: [Synchronize Okta users into Control Hub](https://help.webex.com/en-US/article/nmm9pzdb/Synchronize-Okta-Users-into-Cisco-Webex-Control-Hub), Overview / Configure Okta. Checked 2026-09-30.
[^51]: Okta deprovisioning deactivates rather than deletes Webex accounts, and the accounts can be reactivated if the user is reassigned. Source: [Synchronize Okta users into Control Hub](https://help.webex.com/en-US/article/nmm9pzdb/Synchronize-Okta-Users-into-Cisco-Webex-Control-Hub), Supported features - Deactivate Users. Checked 2026-09-30.
[^52]: The Okta integration creates users when assigned, overwrites Webex attributes on update, deactivates users when unassigned or deactivated in Okta, and creates, updates and deletes pushed groups. Source: [Synchronize Okta users into Control Hub](https://help.webex.com/en-US/article/nmm9pzdb/Synchronize-Okta-Users-into-Cisco-Webex-Control-Hub), Supported features. Checked 2026-09-30.
[^53]: An organization that already uses Directory Connector to synchronize users cannot synchronize users from Okta. Source: [Synchronize Okta users into Control Hub](https://help.webex.com/en-US/article/nmm9pzdb/Synchronize-Okta-Users-into-Cisco-Webex-Control-Hub), Limitations. Checked 2026-09-30.
[^54]: Before syncing from Okta, Cisco requires Okta SSO to be set up and automatic licence assignment templates to be configured, otherwise newly synced users get no Webex licences. Source: [Synchronize Okta users into Control Hub](https://help.webex.com/en-US/article/nmm9pzdb/Synchronize-Okta-Users-into-Cisco-Webex-Control-Hub), Before you begin. Checked 2026-09-30.
[^55]: The bearer token used for Webex SCIM 2.0 provisioning is valid for 365 days and then expires. Source: [SCIM 2.0 provisioning with a custom Webex app in Entra ID](https://help.webex.com/en-us/article/3211gv), Bearer token generation. Checked 2026-09-30.
[^56]: A SCIM bearer token can be generated in Control Hub via Apps > Service apps > Get a token, or manually through an OAuth URL, and creating it requires a full administrator. Source: [Synchronize Okta users into Control Hub](https://help.webex.com/en-US/article/nmm9pzdb/Synchronize-Okta-Users-into-Cisco-Webex-Control-Hub), Prerequisites / Get a bearer token. Checked 2026-09-30.
[^57]: Entra ID does not synchronize null values to Webex, so clearing an attribute in Entra ID does not clear it in Webex. Source: [SCIM 2.0 provisioning with a custom Webex app in Entra ID](https://help.webex.com/en-us/article/3211gv), Limitations. Checked 2026-09-30.
[^58]: The SCIM 2.0 tenant URL for commercial Webex is https://webexapis.com/identity/scim/{OrgId}/v2, with the organization ID copied from Control Hub. Source: [SCIM 2.0 provisioning with a custom Webex app in Entra ID](https://help.webex.com/en-us/article/3211gv), Tenant URL. Checked 2026-09-30.
[^59]: Cisco positions the custom SCIM 2.0 Entra app for new setups needing wider SCIM 2.0 scope and more user attributes, while the Wizard App uses Microsoft Graph and supports groups, rooms and avatars that SCIM 2.0 does not. Source: [SCIM 2.0 provisioning with a custom Webex app in Entra ID](https://help.webex.com/en-us/article/3211gv), Introduction / comparison with Wizard App. Checked 2026-09-30.
[^60]: If an organization enforces that all users must have a verified domain, Entra sync will not create users in unverified domains. Source: [Legacy SCIM provisioning with the Cisco Webex Entra ID gallery app](https://help.webex.com/en-us/article/6ta3gz/Synchronize-Entra-ID-users-into-Control-Hub), Before you begin - verified domains. Checked 2026-09-30.
[^61]: When users are synchronized from a directory such as Active Directory, administrators cannot add users manually in Control Hub. Source: [Ways to add users to your Control Hub organization](https://help.webex.com/article/nj34yk2/Ways-to-Add-and-Manage-Users-in-Cisco-Webex-Control-Hub), Ways to add users - directory synchronization note. Checked 2026-09-30.
[^62]: If Directory Connector is enabled, the Entra ID Wizard App setup asks the administrator to choose Entra ID and block Directory Connector before proceeding. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Set up the Wizard App. Checked 2026-09-30.
[^63]: Before Auto Sync is enabled, the Wizard App can run a dry run with a downloadable dry-run report, and on-demand provisioning tests individual users outside the schedule. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Dry run / On-demand provisioning. Checked 2026-09-30.
[^64]: The Wizard App synchronizes groups automatically every 12 hours. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Synchronization / Auto Sync. Checked 2026-09-30.
[^65]: With the Wizard App, users removed from scope or inactive in Entra ID are skipped in synchronizations and continue to appear in the Control Hub organization until an administrator removes them. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), User removal behaviour. Checked 2026-09-30.
[^66]: Distribution groups from Entra ID cannot be synchronized into Control Hub by the Entra ID Wizard App. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Groups tab. Checked 2026-09-30.
[^67]: Turning Wizard App Auto Sync off stops syncing but preserves the configuration, whereas Delete instance removes the configuration and requires full reconfiguration. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Auto Sync / Delete instance. Checked 2026-09-30.
[^68]: Setting up the Entra ID Wizard App requires a Control Hub full administrator and an Entra ID account with authority to grant tenant-wide admin consent. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Before you begin / Prerequisites. Checked 2026-09-30.
[^69]: The Entra ID Wizard App scopes sync by adding individual users (with a 'Select all users' option Cisco does not recommend for large enterprises) and by adding groups with 'Sync group members' or 'Sync children groups'. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Users tab / Groups tab. Checked 2026-09-30.
[^70]: The Entra ID Wizard App is started from Control Hub Organization Settings > Microsoft Entra ID Wizard App > Set up, followed by an Entra admin sign-in that accepts the requested permissions. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Set up the Wizard App. Checked 2026-09-30.
[^71]: The Wizard App shows a sync status of Active, Quarantine or NotRun along with counts of synced, skipped and failed objects. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Synchronization status. Checked 2026-09-30.
[^72]: The Wizard App's default mapping sends Entra ID userPrincipalName to the Control Hub email address (username). Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Attributes mapping. Checked 2026-09-30.
[^73]: The Wizard App syncs users about every 40 minutes, per Microsoft policy. Source: [Set up the Entra ID Wizard App in Control Hub](https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub), Synchronization / Auto Sync. Checked 2026-09-30.
