Setting up SSO and SCIM provisioning for Genesys Cloud
Genesys Cloud
Verified 2026-10-01 · 77 sources · tier 2
For A Genesys Cloud administrator working with an identity administrator to set up SAML single sign-on, and optionally SCIM provisioning, for a contact center org..
Genesys Cloud creates a single sign-on integration under Menu > IT and Integrations > Single Sign-on > Add an Identity Provider, and Genesys lists Microsoft Entra ID and Okta among the identity management systems known to work with its SCIM implementation 63 58. Genesys states that Entra provisioning can create, update and delete Genesys Cloud users, the Okta Genesys Cloud SCIM app supports Create Users, Update User Attributes and Deactivate Users, and an org can disable Genesys Cloud login so that all users sign in by SSO 44 39 70 69.
Before you start
- Adding an SSO provider in Genesys Cloud requires Single Sign-on > Provider > Add, Delete, Edit and View permissions, an admin role in the identity provider, and a single email address shared by each person's identity provider account and their Genesys Cloud user 75.
- Configuring the Genesys Cloud for Azure app in Entra ID requires the Application Administrator, Cloud Application Administrator or Application Owner role 17.
- The Genesys Cloud for Azure gallery app uses a fixed identifier string, so only 1 instance of it can be configured for SSO in an Entra tenant; check whether your tenant already has one 15.
- Granting roles through a Genesys group needs Directory Group Add and Edit, Authorization Grant Add and Role View permissions 23.
- If you will use SCIM, you must hold the SCIM Integration role yourself in order to grant it to the OAuth client 32.
- Record your org's region: the Entra SAML Identifier and Reply URL use the regional Genesys login host plus /saml, for example https://login.mypurecloud.com/saml, https://login.mypurecloud.ie/saml or https://login.mypurecloud.de/saml 12.
- With SCIM, also record the regional API domain, for example api.mypurecloud.com (US East), api.mypurecloud.ie (Dublin), api.mypurecloud.de (Frankfurt) or api.euw2.pure.cloud (London) 59.
- Inventory your existing SSO integrations, because Genesys Cloud allows up to 30 of them, with the same or mixed identity providers, and only 6 appear directly on the login page 77.
- If you may disable Genesys Cloud login, find out whether you use webhooks for chat notification integrations, because Genesys warns that this feature needs password-based authentication 73.
- See also Identity SSO and directory provisioning for UC and Genesys Cloud licensing.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Four questions. One permanent page you can send to your manager.
Step 1 Confirm access and your region
Microsoft Entra ID
Do
- Confirm that your Genesys Cloud role grants Single Sign-on > Provider > Add, Delete, Edit and View permissions 75.
- Confirm that your Entra account holds the Application Administrator, Cloud Application Administrator or Application Owner role 17.
- Confirm that each person uses one email address in both Entra ID and Genesys Cloud 75.
- Note the regional login host that the SAML URLs will use, for example https://login.mypurecloud.com/saml 12.
- If you chose SCIM, note the regional API domain that forms the SCIM endpoint https://{domain}/api/v2/scim/v2/ 59.
Verify
Okta
Do
- Confirm that your Genesys Cloud role grants Single Sign-on > Provider > Add, Delete, Edit and View permissions 75.
- Confirm that you hold an admin role in Okta, since Genesys requires an admin role in the identity provider 75.
- Confirm that each person uses one email address in both Okta and Genesys Cloud 75.
- If you chose SCIM, note the regional domain, for example api.mypurecloud.com (US East) or api.euw2.pure.cloud (London), because Okta asks for the regional SCIM Domain 59 37.
Verify
- The Genesys integration page is at Menu > IT and Integrations > Single Sign-on 63.
- Suggested check: open both administration consoles with the accounts you will use and confirm that each one loads.
Step 2 Add the Genesys Cloud application in the identity provider
Microsoft Entra ID
Do
- In Entra ID, go to Enterprise apps > New application, search the gallery for Genesys Cloud for Azure, and add it 3.
- Only 1 instance of this app can be configured for SSO in the tenant, because it uses a fixed identifier string 15.
- If you chose SCIM, note that Microsoft says the same app can carry provisioning but recommends a separate app when you first test the provisioning integration 13.
Verify
- Suggested check: confirm that the new application appears in the enterprise applications list.
Rollback
- Suggested rollback: delete the new enterprise application; nothing has changed on the contact center side yet.
Okta
Do
- Add the Genesys Cloud app from the Okta Integration Network, and under Sign On settings set Application username format to Email 38.
Verify
- Suggested check: confirm that the application is listed and that its username format shows email.
Rollback
- Suggested rollback: remove the application from the identity provider; nothing has changed on the contact center side yet.
Step 3 Configure SAML in the identity provider
Microsoft Entra ID
Do
- In the app's Basic SAML Configuration, set both Identifier and Reply URL to your region's Genesys login host plus /saml, for example https://login.mypurecloud.com/saml 12.
- For SP-initiated sign-in, set Sign-on URL to the regional login host without a path, for example https://login.mypurecloud.com 14.
- Keep the pre-populated Email attribute (source user.userprincipalname) and set OrganizationName to your organization name 2.
- Enter OrganizationName exactly, because Genesys treats it as case-sensitive, reads it as the org short name for IdP-initiated sign-in, and requires it to match the selected org for SP-initiated sign-in 74.
- From the SAML Signing Certificate section download Certificate (Base64), and from the Set up section copy the Login URL and the Microsoft Entra Identifier 1.
Verify
- Suggested check: reopen the SAML configuration and confirm that the identifier, reply and sign-on values all use your region's login host.
- Suggested check: confirm that the attribute list shows both the email and organization name attributes.
Rollback
- Suggested rollback: clear or correct the SAML settings on the application.
Okta
Do
- Obtain the SAML metadata file for the Genesys Cloud app from Okta, because importing the identity provider's metadata file into Genesys Cloud populates the required fields and signing certificate 63.
- If you send an OrganizationName attribute, enter it exactly, because Genesys treats it as case-sensitive, reads it as the org short name for IdP-initiated sign-in, and requires it to match the selected org for SP-initiated sign-in 74.
Verify
- Suggested check: confirm that you hold a metadata file for this application before moving on.
Rollback
- Suggested rollback: revert the SAML settings on the application.
Step 4 Create the SSO integration in Genesys Cloud
Microsoft Entra ID
Do
- Go to Menu > IT and Integrations > Single Sign-on > Add an Identity Provider 63.
- If you have the identity provider's SAML metadata file, import it, which populates the required fields and the signing certificate 63.
- Otherwise, fill in the form, which holds Issuer URI, Single Sign-On URI and binding, optional request signing, Single Logout URI and binding, Name Identifier Format, and a ForceAuthn-on-inactivity option 66.
- For reference, Microsoft's tutorial maps the Entra values into a Genesys ADFS/Azure AD(Premium) tab: the certificate to ADFS Certificate, the Microsoft Entra Identifier to ADFS Issuer URI, the Login URL to Target URI, and the app's Application ID to Relying Party Identifier 6.
- Set Name Identifier Format, choosing Unspecified if you do not know it 66.
- Save, then use Download Metadata to get the Genesys service provider metadata, which contains the Issuer URI, Assertion Consumer Service and Single Logout URI for the identity provider 64.
Verify
- The Single Sign-on page shows each configuration's signing certificates with their expiration dates 65.
- Suggested check: confirm that the new integration is listed and that its certificate expiry date is in the future.
Rollback
- Suggested rollback: delete the new integration from the single sign-on page.
- While Genesys Cloud login is disabled, admins cannot delete every SSO provider 69.
Okta
Do
- Go to Menu > IT and Integrations > Single Sign-on > Add an Identity Provider 63.
- Import the Okta SAML metadata file, which populates the required fields and the signing certificate 63.
- Set Name Identifier Format, choosing Unspecified if you do not know it 66.
- Save, then use Download Metadata to get the Genesys service provider metadata (Issuer URI, Assertion Consumer Service and Single Logout URI) and load it into Okta 64.
Verify
- The Single Sign-on page shows each configuration's signing certificates with their expiration dates 65.
- Suggested check: confirm that the new integration is listed and that its certificate expiry date is in the future.
Rollback
- Suggested rollback: delete the new integration from the single sign-on page.
- While Genesys Cloud login is disabled, admins cannot delete every SSO provider 69.
Step 5 Create users, or connect SCIM provisioning
Microsoft Entra ID + SSO only, with users created and maintained by hand in Genesys Cloud
Do
- Create each user in Genesys Cloud with Add Person, giving a full name and email, because Entra users must already exist as Genesys Cloud users before they can sign in 20.
- Use the same email address that the person's Entra account uses 75.
Verify
- Suggested check: open the people list and confirm that each pilot user exists with the expected email address.
Rollback
- Suggested rollback: deactivate the users you added for testing.
Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Go to Menu > IT and Integrations > OAuth, add a client with grant type Client Credentials, and assign only the SCIM Integration role 30.
- Include every division that SCIM will manage when you assign the role, because client credentials roles default to the Home division 31.
- If the SCIM Integration role is missing, restore the default roles with POST /api/v2/authorization/roles/default 32.
- Set the token duration, which defaults to 86,400 seconds and can be set up to 38,880,000 seconds (450 days) with the SCIM Integration role 33.
- Copy the client secret now, because it can be viewed only once at setup 34.
- Generate the bearer token by calling your region's login URL /oauth/token with the client ID and secret, as Genesys documents with its Postman collection 60.
- On the Entra app's Provisioning tab, set Provisioning Mode to Automatic, set Tenant URL to https://{domain}/api/v2/scim/v2/ and Secret Token to the bearer token, run Test Connection, and save 50 59 8.
- Leave Provisioning Status off for now, because Microsoft advises validating with on-demand provisioning for a few users before you select Start Provisioning 18.
- In the provisioning Properties, enable notification emails for quarantine and accidental deletions prevention, as Microsoft's steps say 11.
- Keep the required mappings: userPrincipalName to userName, which generates the Genesys user's main email address, and Not([IsSoftDeleted]) to active 62 42.
- Keep userName as the matching attribute, since it is the only one supported for filtering, and keep displayName, because userName, active and displayName are all required by Genesys Cloud 7.
- Do not rely on name.givenName, name.familyName or the address fields, which Genesys Cloud SCIM does not currently support 52.
- If users sign in with a non-email identifier, map that identifier to the Genesys externalIds extension keyed on the identity provider's Issuer URI 68.
Verify
- Test Connection checks connectivity to the Genesys SCIM endpoint 8.
- Suggested check: confirm that the connection test reports success and that the mapping list shows the user name as the matching attribute.
Rollback
Okta + SSO only, with users created and maintained by hand in Genesys Cloud
Do
- Create each person's Genesys Cloud user with the email address that their Okta account uses, because Genesys requires a single email address shared by the identity provider account and Genesys Cloud 75.
Verify
- Suggested check: open the people list and confirm that each pilot user exists with the expected email address.
Rollback
- Suggested rollback: deactivate the users you added for testing.
Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Go to Menu > IT and Integrations > OAuth, add a client with grant type Client Credentials, and assign only the SCIM Integration role 30.
- Include every division that SCIM will manage when you assign the role, because client credentials roles default to the Home division 31.
- If the SCIM Integration role is missing, restore the default roles with POST /api/v2/authorization/roles/default 32.
- Set the token duration, which defaults to 86,400 seconds and can be set up to 38,880,000 seconds (450 days) with the SCIM Integration role 33.
- Copy the client secret now, because it can be viewed only once at setup 34.
- Generate the bearer token by calling your region's login URL /oauth/token with the client ID and secret, as Genesys documents with its Postman collection 60.
- In Okta, under Provisioning > Integration, enter the regional SCIM Domain and the bearer token as API Token, select Test API Credentials, then Save 37.
- Under To App, enable the features you need from Create Users, Update User Attributes, Deactivate Users, Sync Password and Push Groups, each of which is optional 39.
- Decide on Sync Password with your password decision in mind: Sync Password creates a password for each user and pushes it to Genesys Cloud, while with Genesys Cloud login disabled all users must sign in by SSO 35 69.
- Store Okta phone numbers in E.164, because Genesys converts phone numbers from Okta to E.164 and other formats cause continual updates 36.
- Do not rely on name.givenName, name.familyName or the address fields, which Genesys Cloud SCIM does not currently support; the display name comes from displayName 52.
Verify
- Suggested check: confirm that the credentials test reports success and that only the provisioning features you chose are enabled.
Rollback
- If the client secret is exposed, Generate new secret issues a new one 34.
- Suggested rollback: turn off the provisioning features, clear the integration credentials, and delete the OAuth client you created.
Step 6 Prepare how roles and divisions reach users
SCIM sends the role and the division as user attributes + Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Create the target divisions in Genesys Cloud first, because the division value must match an existing division name or be blank 46.
- Map the division attribute, which Genesys writes to the user's divisionId 47.
- Confirm that the OAuth client you created includes every division that SCIM will manage 31.
- In Entra, create an app role for the Genesys role, assign it to the user, and map SingleAppRoleAssignment([appRoleAssignments]) to roles[primary eq "True"].value 55.
- Genesys maps the SCIM roles.[].value field to the user roles API, so the role values you send become Genesys role assignments 56.
Verify
- Suggested check: after the pilot run, confirm that each pilot user's role and division match the values sent from the identity provider.
Rollback
- Mapping a previously synced field to an empty value does not clear it in Genesys Cloud 43.
- Suggested rollback: remove the role and division mappings, then correct the affected users' roles and divisions by hand.
SCIM syncs group membership into Genesys groups that carry roles and divisions + Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Create one general group per access profile under Menu > User Management > Groups, with Visibility set to Public 25.
- Name each group identically to its Entra group, because groups must be created in Genesys Cloud first with identical names 4.
- Genesys SCIM supports only public groups, matches names case-insensitively, and cannot create or delete groups 54.
- On each group's Roles tab, select Assign Roles, enable the role and choose its divisions 23.
- Use no membership rules on these groups, because roles cannot be assigned to a group that has them 24.
Verify
- A role assigned on a group's Roles tab is granted to every current and future member 21.
- Suggested check: after the pilot run, confirm that members show the group's roles as inherited.
Rollback
- A group-granted role is removed from a user when they leave the group 21.
- Suggested rollback: remove the roles from the group before you delete or rename it.
SCIM sends the role and the division as user attributes + Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Create the target divisions in Genesys Cloud first, because the division value must match an existing division name or be blank 46.
- Confirm that the OAuth client you created includes every division that SCIM will manage 31.
- Make sure Update User Attributes is enabled under To App, since it is one of the optional provisioning features 39.
- Send the role through the SCIM roles.[].value field, which Genesys maps to the user roles API 56.
- Send the division through scimEnterpriseUser.division, which Genesys maps to the user's divisionId 47.
Verify
- Suggested check: after the pilot run, confirm that each pilot user's role and division match the values sent from the identity provider.
Rollback
- Suggested rollback: remove the role and division mappings, then correct the affected users' roles and divisions by hand.
SCIM syncs group membership into Genesys groups that carry roles and divisions + Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Create one general group per access profile under Menu > User Management > Groups, with Visibility set to Public 25.
- Name each group to match its Okta group, because Okta cannot create or delete Genesys groups and membership will not sync unless names match case-insensitively 40.
- On each group's Roles tab, select Assign Roles, enable the role and choose its divisions 23.
- Use no membership rules on these groups, because roles cannot be assigned to a group that has them 24.
Verify
- A role assigned on a group's Roles tab is granted to every current and future member 21.
- Suggested check: after the pilot run, confirm that members show the group's roles as inherited.
Rollback
- A group-granted role is removed from a user when they leave the group 21.
- Suggested rollback: remove the roles from the group before you delete or rename it.
SSO only, with users created and maintained by hand in Genesys Cloud
Do
- Create a general group under Menu > User Management > Groups, choosing its Type and Visibility 25.
- Open the group's Roles tab, select Assign Roles, enable the role and choose its divisions 23.
- Use groups without membership rules, because roles cannot be assigned to a group that has them and enabling roles discards its rules 24.
- Add users to the group; a role assigned on the Roles tab, with its divisions, is granted to every current and future member 21.
Verify
- Roles a user inherits from a group cannot be edited or removed on the user's own roles section 22.
- Suggested check: open a member's profile and confirm that the role appears there as inherited from the group.
Rollback
- To withdraw an inherited role, change the group's roles or the user's membership 22.
Granted in Genesys Cloud; SCIM carries identity and contact attributes only + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Leave the roles field and the optional division attribute out of the SCIM mapping, because Genesys maps roles.[].value to the user roles API and scimEnterpriseUser.division to the user's divisionId 56 47 46.
- Grant roles in Genesys Cloud through groups: open the group's Roles tab, select Assign Roles, enable the role and choose its divisions 23.
- Use groups without membership rules, because roles cannot be assigned to a group that has them 24.
- Do not hand-edit attributes that SCIM manages, because Genesys Cloud SCIM syncs one way and changes made in Genesys Cloud may be overwritten 61.
Verify
- Suggested check: after the pilot run, confirm that each pilot user's roles and division are unchanged.
Rollback
- To withdraw an inherited role, change the group's roles or the user's membership 22.
Step 7 Run a pilot and test sign-in
Microsoft Entra ID + SSO only, with users created and maintained by hand in Genesys Cloud
Do
- Test sign-in with Test this application (SP or IdP initiated), by browsing to the Genesys Sign-on URL directly, or from the Genesys tile in My Apps 19.
- Test both SP-initiated and IdP-initiated sign-in, since the app supports both 16.
Verify
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear 67.
- Only 6 SSO integrations appear directly on the login page 77.
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.
Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Keep the provisioning scope at Sync only assigned users and groups, which is the default 45.
- Assign a few pilot users, and if you chose group-based access, the matching groups; Entra provisioning only updates existing Genesys groups, matched on displayName 5.
- Validate with on-demand provisioning for those users, then select Start Provisioning, as Microsoft advises 18.
- Turn Provisioning Status on and save again 50.
- Test sign-in with Test this application, the Genesys Sign-on URL, or the Genesys tile in My Apps, covering both SP-initiated and IdP-initiated sign-in 19 16.
Verify
- Entra provisioning is monitored through the provisioning logs and the cycle progress bar, and an unhealthy configuration puts the app into quarantine 10.
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear 67.
- Suggested check: confirm that each pilot user appears in the people list with the expected email address.
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.
Rollback
Okta + SSO only, with users created and maintained by hand in Genesys Cloud
Do
- Sign in as a pilot user through the identity provider link on the Genesys login page 67.
Verify
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear 67.
- Only 6 SSO integrations appear directly on the login page 77.
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.
Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Assign a small set of pilot users to the app, noting that with Deactivate Users enabled, unassigning them later deactivates their Genesys accounts 35.
- If you chose group-based access, link the matching groups through Push Groups 40.
- Avoid Push Now, which can remove many members from a group and strip group-granted Genesys roles; Genesys SCIM blocks any single action removing more than 1,000 members 41.
- Sign in as a pilot user through the identity provider link on the Genesys login page 67.
Verify
- A pilot user's phone number should arrive in E.164, because Genesys converts Okta phone numbers to E.164 36.
- The Genesys login page shows the identity provider link, and Genesys says something in the configuration is incorrect if it does not appear 67.
- Suggested check: confirm that each pilot user appears in the people list with the expected email address.
- Suggested check: sign in as an administrator through single sign-on and confirm that you land in the correct org.
Rollback
- With Deactivate Users enabled, unassigning a user deactivates their Genesys account 35.
- Suggested rollback: unlink a pushed group rather than deleting the matching group on the contact center side.
Step 8 Decide on Genesys Cloud passwords
Yes, disable Genesys Cloud login so users sign in by SSO only
Do
- Confirm that you do not use webhooks for chat notification integrations, because Genesys warns that this feature needs password-based authentication 73.
- Confirm that at least one third-party SSO provider is configured in the org, which SSO-only sign-in requires 71.
- Go to Menu > Account > Organization Settings > Authentication, select Disable Genesys Cloud Login, save, and accept the acknowledgment 70.
Verify
- With Genesys Cloud login disabled, the password requirement options are disabled but preserved, all users must sign in by SSO, and admins cannot delete every SSO provider 69.
- Suggested check: before saving, confirm that at least one administrator can sign in through single sign-on.
Rollback
- Clear Disable Genesys Cloud Login on the Authentication tab, save, and then reconfigure the password requirements 72.
No, keep Genesys Cloud credentials available alongside SSO
Do
- Leave Disable Genesys Cloud Login cleared under Menu > Account > Organization Settings > Authentication 70.
Verify
- The Genesys login page shows the identity provider link once SSO is configured 67.
- Suggested check: confirm that the login page still offers password sign-in alongside the single sign-on link.
Step 9 Operate leavers, tokens and certificates
Microsoft Entra ID + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- Removing a user from the app's scope or soft-deleting them in Entra makes the user inactive in Genesys Cloud 49.
- A hard delete in Entra, including the automatic hard delete 30 days after removal or soft delete, deletes the user in Genesys Cloud 48.
- Replace the Secret Token before the token duration you set runs out; that duration defaults to 86,400 seconds and can be at most 38,880,000 seconds (450 days) 33.
- Watch the provisioning logs, because an unhealthy configuration puts the app into quarantine 10.
- Add a renewed identity provider signing certificate while the current one is still listed; each configuration holds up to 5 certificates and Genesys picks the correct one at sign-in 65.
Verify
- The provisioning logs and the cycle progress bar show provisioning health 10.
- Suggested check: after each leaver, confirm that the person shows as inactive in the people list.
Rollback
- Suggested rollback: restore a mistakenly removed user in the identity provider before the automatic hard delete runs, so that the user is not deleted on the contact center side.
Okta + SSO with SCIM, so the identity provider creates and updates Genesys Cloud users
Do
- With Deactivate Users enabled, unassigning or deactivating a user in Okta deactivates their Genesys account 35.
- Replace the API Token before the token duration you set runs out; that duration defaults to 86,400 seconds and can be at most 38,880,000 seconds (450 days) 33.
- Add a renewed identity provider signing certificate while the current one is still listed; each configuration holds up to 5 certificates and Genesys picks the correct one at sign-in 65.
Verify
- The Single Sign-on page shows each certificate's expiration date 65.
- Suggested check: after each leaver, confirm that the person shows as inactive in the people list.
Rollback
- Suggested rollback: reassign a mistakenly removed user to the application and confirm that the account is active again.
SSO only, with users created and maintained by hand in Genesys Cloud
Do
- Add a renewed identity provider signing certificate to the configuration while the current one is still listed; each configuration holds up to 5 X.509 signing certificates and Genesys picks the correct one at sign-in 65.
- Without automatic provisioning, maintaining Genesys Cloud users is a manual task, so deactivate leavers in Genesys Cloud as well as in the identity provider 20.
Verify
- The Single Sign-on page shows each certificate's expiration date 65.
- Suggested check: after each leaver, confirm that the person shows as inactive in the people list.
Applicability
Applies to: Microsoft Entra ID and Genesys Cloud CX. Deployments: multi-tenant. Sources checked 2026-10-02. - Since the 22 September 2025 release, SCIM APIs can set and update a user's hireDate in Genesys Cloud, which this guide does not configure 51.
- Genesys also lists OneLogin as an identity management system known to work with its SCIM implementation, but this guide covers only Entra ID and Okta 58.
- Genesys SCIM extension fields routingSkills and routingLanguages map to a user's routing skills and languages, and this guide does not configure them 57.
What remains uncertain
- The SAML login host for regions beyond the examples given in Microsoft's tutorial is not covered by the sources below.
- What Genesys Cloud does with a SCIM role value that matches no existing role is not covered by the sources below.
- Whether a SCIM sync with no roles mapping leaves manually granted roles untouched is not covered by the sources below.
- The Okta-side SAML configuration screens and values are not covered by the sources below.
- How the current Genesys identity provider form labels relate to the ADFS/Azure AD(Premium) tab named in Microsoft's tutorial is not covered by the sources below.
- SAML assertion encryption and multi-factor authentication are not covered by the sources below.
- Whether any identity provider's default mappings populate the routing skills and languages extension fields is not covered by the sources below.
See also
Related to
- Genesys Cloud licensing — Users created by SCIM still need Genesys Cloud licences and roles; licensing is out of scope here
- Identity SSO and directory provisioning for UC — Vendor-neutral SSO and provisioning concepts; this guide is the Genesys Cloud specific procedure with Microsoft Entra ID or Okta
Sources
- 1From the Entra SAML Signing Certificate section you download Certificate (Base64) and from the Set up section copy the Login URL and Microsoft Entra Identifier for Genesys Cloud.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Configure Microsoft Entra SSO, steps 9-10; Configure Genesys Cloud for Azure SSO step 3b-3c · Checked 2026-10-01
- 2The Genesys Cloud for Azure app expects extra SAML attributes Email (source user.userprincipalname) and OrganizationName (your organization name), which are pre-populated in Entra.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Configure Microsoft Entra SSO, step 8 attribute table · Checked 2026-10-01
- 3In Microsoft Entra ID the Genesys Cloud integration is added from the application gallery under Entra ID > Enterprise apps > New application by searching for Genesys Cloud for Azure.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Add Genesys Cloud for Azure from the gallery, steps 1-4 · Checked 2026-10-01
- 4To provision group membership from Entra, groups must first be created in Genesys Cloud with names identical to the Entra groups.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 2, item 3 · Checked 2026-10-01
- 5Entra provisioning to Genesys Cloud does not create or delete groups; it only updates existing groups, matched on displayName.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 5, item 13 and group attribute table · Checked 2026-10-01
- 6Microsoft's tutorial maps Entra values into a Genesys ADFS/Azure AD(Premium) tab: certificate to ADFS Certificate, Microsoft Entra Identifier to ADFS Issuer URI, Login URL to Target URI, and the app's Application ID to Relying Party Identifier.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Configure Genesys Cloud for Azure SSO, step 3a-3e · Checked 2026-10-01
- 7In the Entra user mapping for Genesys Cloud, userName is the matching attribute and the only one supported for filtering; userName, active and displayName are required by Genesys Cloud.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 5, item 11 user attribute table · Checked 2026-10-01
- 8In the Entra Provisioning tab the Tenant URL is the Genesys regional API URL followed by /api/v2/scim/v2 and the Secret Token is a Genesys OAuth token; Test Connection checks connectivity.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 5, item 6 (Admin Credentials) · Checked 2026-10-01
- 9Entra provisioning to Genesys Cloud can create users, remove users who no longer need access, keep user attributes synchronized, and provision groups and group memberships.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Capabilities supported · Checked 2026-10-01
- 10Entra provisioning to Genesys Cloud is monitored through provisioning logs and the cycle progress bar, and an unhealthy configuration puts the app into quarantine.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 6: Monitor your deployment · Checked 2026-10-01
- 11Microsoft's provisioning steps say to enable notification emails for quarantine and enable accidental deletions prevention in the provisioning Properties.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 5, item 9 · Checked 2026-10-01
- 12In Entra Basic SAML Configuration, both Identifier and Reply URL are set to the region's Genesys login host plus /saml, for example https://login.mypurecloud.com/saml, https://login.mypurecloud.ie/saml or https://login.mypurecloud.de/saml.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Configure Microsoft Entra SSO, step 5a and 5b tables · Checked 2026-10-01
- 13Microsoft says the same Genesys Cloud for Azure app used for SSO can be used for provisioning, but recommends a separate app when first testing the provisioning integration.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 3: Add Genesys Cloud for Azure from the Microsoft Entra application gallery · Checked 2026-10-01
- 14For SP-initiated SSO the Entra Sign-on URL is the region's Genesys login host without a path, for example https://login.mypurecloud.com.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Configure Microsoft Entra SSO, step 6 · Checked 2026-10-01
- 15The Genesys Cloud for Azure gallery app uses a fixed identifier string, so only one instance of it can be configured for SSO in one Entra tenant.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Scenario description, Note · Checked 2026-10-01
- 16The Genesys Cloud for Azure app supports both service-provider-initiated and identity-provider-initiated SSO.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Scenario description · Checked 2026-10-01
- 17Configuring the Genesys Cloud for Azure app in Entra ID requires the Application Administrator, Cloud Application Administrator or Application Owner role.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Prerequisites · Checked 2026-10-01
- 18Microsoft advises starting small: scope provisioning by assignment or scoping filter, validate with on-demand provisioning for a few users, then select Start Provisioning.Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID · Step 4 bullets; Step 5 items 15-16 · Checked 2026-10-01
- 19Entra SSO to Genesys Cloud can be tested with Test this application (SP or IdP initiated), by browsing to the Genesys Sign-on URL directly, or from the Genesys tile in My Apps.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Test SSO · Checked 2026-10-01
- 20For Entra users to sign in to Genesys Cloud they must already be provisioned as Genesys Cloud users; without automatic provisioning this is a manual Add Person task with full name and email.Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID · Create Genesys Cloud for Azure test user · Checked 2026-10-01
- 21A role assigned on a Genesys group's Roles tab, with its divisions, is granted to every current and future member and removed from a user when they leave the group.Assign roles to a group · Introductory paragraphs · Checked 2026-10-01
- 22Roles a user inherits from a group cannot be edited or removed on the user's own roles section; change the group's roles or the user's membership instead.Assign roles to a group · Introductory paragraphs · Checked 2026-10-01
- 23To grant a role per group, open Menu > User Management > Groups, select the group, Roles tab, Assign Roles, enable the role and choose its divisions; this needs Directory Group Add and Edit, Authorization Grant Add and Role View permissions.Assign roles to a group · Prerequisites; Assign a role to group steps 1-8 · Checked 2026-10-01
- 24Roles cannot be assigned to a Genesys group that has membership rules; enabling roles on such a group discards its rules.Assign roles to a group · Example, Step 3 note · Checked 2026-10-01
- 25A Genesys general group is created under Menu > User Management > Groups with a Type (Official or Social) and a Visibility of Public, Members Only or Owners Only.Create a group · Steps to create a general group; Type; Visibility · Checked 2026-10-01
- 26Before disabling Genesys Cloud login, confirm that an administrator can sign in through SSO, because afterwards every user, administrators included, must sign in by SSO.inferredConfigure Genesys Cloud to authenticate with SSO only · When Genesys Cloud login is disabled, third bullet · Checked 2026-10-01
- 27Microsoft's Genesys-side SSO steps (ADFS/Azure AD(Premium) tab) appear to predate Genesys's current Add an Identity Provider page, so the Genesys-side form should follow the Genesys article, with Entra values mapped by meaning.inferredAdd multiple single sign-on providers to Genesys Cloud · Create an SSO integration, steps 1-8, compared with ms-learn-entra-genesys-cloud-sso-tutorial Configure Genesys Cloud for Azure SSO step 3 · Checked 2026-10-01
- 28Any user attribute or role that SCIM manages should be treated as read-only in the Genesys admin UI, because a later sync may overwrite manual edits there.inferredAbout Genesys Cloud SCIM (Identity Management) · Overview, Important note · Checked 2026-10-01
- 29Because the documented Entra role mapping uses SingleAppRoleAssignment and a primary role value, it likely carries one Genesys role per user; users needing several roles or per-division grants are better served by group-granted roles.inferredConfigure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Mappings (Optional), roles row; read with genesys-help-assign-roles-to-a-group introductory paragraphs · Checked 2026-10-01
- 30The Genesys SCIM OAuth client is created under Menu > IT and Integrations > OAuth with grant type Client Credentials and only the SCIM Integration role assigned.Create an OAuth client · Genesys Cloud SCIM tab, steps 1-7 · Checked 2026-10-01
- 31When assigning the SCIM Integration role to the OAuth client, include every division that SCIM will manage; client credentials roles default to the Home division.Create an OAuth client · Genesys Cloud SCIM tab step 7; Platform API tab, Client Credential Step 1 · Checked 2026-10-01
- 32To grant the SCIM Integration role to the OAuth client the admin must hold that role; if it is missing, default roles can be restored with POST /api/v2/authorization/roles/default.Create an OAuth client · Prerequisites; Genesys Cloud SCIM tab step 7 note · Checked 2026-10-01
- 33A SCIM OAuth client's token duration defaults to 86,400 seconds and can be set up to 38,880,000 seconds (450 days) only when it uses the SCIM Integration role or a custom role with the same permissions.Create an OAuth client · Genesys Cloud SCIM tab, step 9 · Checked 2026-10-01
- 34The Genesys OAuth client secret can be viewed only once at setup, but a new secret can be generated later with Generate new secret.Create an OAuth client · Genesys Cloud SCIM tab, steps 10-12 · Checked 2026-10-01
- 35In Okta, Deactivate Users deactivates the Genesys account when the user is unassigned or deactivated, and Sync Password creates a password for each user and pushes it to Genesys Cloud.Configure Okta for Genesys Cloud SCIM (Identity Management) · To App, steps 3-4 · Checked 2026-10-01
- 36Genesys converts phone numbers from Okta to E.164, so Okta phone numbers should already be E.164 to avoid continual updates.Configure Okta for Genesys Cloud SCIM (Identity Management) · To App, Important note · Checked 2026-10-01
- 37In Okta's Provisioning > Integration, enter the regional SCIM Domain and the bearer token as API Token, then select Test API Credentials and Save.Configure Okta for Genesys Cloud SCIM (Identity Management) · Integration, steps 1-4 · Checked 2026-10-01
- 38For Okta, the Genesys Cloud app is added from the Okta Integration Network, and its Application username format is set to Email under Sign On settings.Configure Okta for Genesys Cloud SCIM (Identity Management) · Application setup; Sign On · Checked 2026-10-01
- 39The Genesys Cloud SCIM app in Okta supports Create Users, Update User Attributes, Deactivate Users, Sync Password and Push Groups, each optional.Configure Okta for Genesys Cloud SCIM (Identity Management) · Provisioning; To App steps 1-5 · Checked 2026-10-01
- 40Okta links groups to Genesys Cloud through Push Groups; Okta cannot create or delete Genesys groups, and names must match case-insensitively or membership will not sync.Configure Okta for Genesys Cloud SCIM (Identity Management) · Groups, notes and steps 1-3 · Checked 2026-10-01
- 41Okta's Push Now action can remove many members from a group, stripping group-granted Genesys roles; Genesys SCIM blocks any single action removing more than 1000 members.Configure Okta for Genesys Cloud SCIM (Identity Management) · Groups, Notes; Link large groups · Checked 2026-10-01
- 42In the Genesys Entra mapping, the required SCIM active attribute is mapped from Not([IsSoftDeleted]).Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Mappings (Optional), field mapping table, active row · Checked 2026-10-01
- 43With Entra ID, mapping a previously synced field to an empty value does not clear it in Genesys Cloud.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Mappings (Optional), introductory note · Checked 2026-10-01
- 44Genesys states that Entra provisioning can create, update and delete users in Genesys Cloud.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Users and Groups, Notes · Checked 2026-10-01
- 45By default Entra scopes Genesys provisioning to Sync only assigned users and groups; it can be changed to Sync all users and groups.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Scope (Optional) · Checked 2026-10-01
- 46The SCIM enterprise division attribute is optional and its value must match an existing Genesys Cloud division name or be blank.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Mappings (Optional), field mapping table, scimEnterpriseUser.division row · Checked 2026-10-01
- 47Genesys maps the SCIM scimEnterpriseUser.division field to the user's divisionId in Genesys Cloud.SCIM and Genesys Cloud field mappings · Field mapping table, scimEnterpriseUser.division row · Checked 2026-10-01
- 48A hard delete in Entra, including the automatic hard delete 30 days after removal or soft delete, deletes the user in Genesys Cloud.What causes Genesys Cloud to change the status of a Microsoft Entra ID user to inactive or to delete a user? · FAQ answer, first paragraph · Checked 2026-10-01
- 49Removing a user from the Entra app's scope or soft-deleting them in Entra makes the user inactive in Genesys Cloud.What causes Genesys Cloud to change the status of a Microsoft Entra ID user to inactive or to delete a user? · FAQ answer, first paragraph · Checked 2026-10-01
- 50Genesys's Entra procedure sets Provisioning Mode to Automatic, enters Tenant URL and Secret Token, runs Test Connection, saves, then turns Provisioning Status on and saves again.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Provisioning section · Checked 2026-10-01
- 51Since the 22 September 2025 release, SCIM APIs can set and update a user's hireDate in Genesys Cloud.Release notes for Genesys Cloud SCIM (Identity Management) · September 22, 2025 entry · Checked 2026-10-01
- 52Genesys Cloud SCIM does not currently support name.givenName, name.familyName or the address fields; the display name comes from displayName.SCIM and Genesys Cloud field mappings · Unsupported fields rows; displayName row · Checked 2026-10-01
- 53The SCIM password field updates the Genesys Cloud user's password via PUT or PATCH but is never returned.SCIM and Genesys Cloud field mappings · Field mapping table, password row · Checked 2026-10-01
- 54Genesys SCIM can add users to or remove users from a public group but cannot create or delete groups; only public groups are supported and names must match case-insensitively.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Users and Groups, Notes · Checked 2026-10-01
- 55To send a Genesys role from Entra, the documented mapping is SingleAppRoleAssignment([appRoleAssignments]) to roles[primary eq "True"].value, after creating an app role in Entra and assigning it to the user.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Mappings (Optional), field mapping table, roles row · Checked 2026-10-01
- 56Genesys maps the SCIM roles.[].value field to the user roles API, so role values sent by SCIM become Genesys role assignments.SCIM and Genesys Cloud field mappings · Field mapping table, roles.[].value row and roles example · Checked 2026-10-01
- 57Genesys SCIM extension fields scimUserExtensions.routingSkills and routingLanguages (name and proficiency) map to the user's routing skills and languages.SCIM and Genesys Cloud field mappings · Field mapping table, scimUserExtensions rows · Checked 2026-10-01
- 58Genesys lists Microsoft Entra ID, Okta and OneLogin as identity management systems known to work with its SCIM implementation.About Genesys Cloud SCIM (Identity Management) · Identity Management Systems · Checked 2026-10-01
- 59The Genesys SCIM endpoint is https://{domain}/api/v2/scim/v2/ where domain is the org's regional API domain, for example api.mypurecloud.com (US East), api.mypurecloud.ie (Dublin), api.mypurecloud.de (Frankfurt), api.euw2.pure.cloud (London).Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Provisioning section, regional domain table · Checked 2026-10-01
- 60Genesys documents generating the SCIM bearer token by calling the regional login URL /oauth/token with the OAuth client ID and secret (client credentials), using its Postman collection.Configure Okta for Genesys Cloud SCIM (Identity Management) · Token generation, steps 1-5 · Checked 2026-10-01
- 61Genesys Cloud SCIM only syncs one way, from the identity management system to Genesys Cloud; changes made in Genesys Cloud are not synced back and may be overwritten.About Genesys Cloud SCIM (Identity Management) · Overview, Important note · Checked 2026-10-01
- 62In the Genesys Entra mapping, userPrincipalName maps to the required SCIM userName, which generates the Genesys user's main email address.Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management) · Mappings (Optional), field mapping table, userName row · Checked 2026-10-01
- 63An SSO integration is created under Menu > IT and Integrations > Single Sign-on > Add an Identity Provider, and importing the IdP's SAML metadata file populates the required fields and signing certificate.Add multiple single sign-on providers to Genesys Cloud · Create an SSO integration, steps 1-8 · Checked 2026-10-01
- 64After saving the integration, Genesys generates SP metadata (Issuer URI, Assertion Consumer Service, Single Logout URI) that can be downloaded with Download Metadata for the IdP.Add multiple single sign-on providers to Genesys Cloud · Genesys Cloud Service provider data · Checked 2026-10-01
- 65Each Genesys SSO configuration holds up to five X.509 signing certificates, shown with their expiration dates, and Genesys picks the correct one at sign-in.Add multiple single sign-on providers to Genesys Cloud · Identity provider field details table, Certificate row; Single sign-on page · Checked 2026-10-01
- 66The Genesys identity provider form holds Issuer URI, Single Sign-On URI and binding, optional request signing, Single Logout URI and binding, Name Identifier Format (Unspecified if unknown), and a ForceAuthn-on-inactivity option.Add multiple single sign-on providers to Genesys Cloud · Identity provider field details table · Checked 2026-10-01
- 67After SSO is configured, the Genesys login page shows the identity provider link; if it does not appear, Genesys says something in the configuration is incorrect.What users can expect after SSO setup · Item 2 and its note · Checked 2026-10-01
- 68Users can sign in with a non-email identifier by choosing an alternative Name Identifier Format, and with Entra SCIM the identifier can be mapped to the Genesys externalIds extension keyed on the IdP Issuer URI.Configure SSO identity provider without email address · Body paragraphs 2-4 and mapping table · Checked 2026-10-01
- 69With Genesys Cloud login disabled, password requirement options are disabled but preserved, all users must sign in by SSO, and admins cannot delete every SSO provider.Configure Genesys Cloud to authenticate with SSO only · When Genesys Cloud login is disabled · Checked 2026-10-01
- 70SSO-only sign-in is enabled under Menu > Account > Organization Settings > Authentication by selecting Disable Genesys Cloud Login, saving, and accepting the acknowledgment.Configure Genesys Cloud to authenticate with SSO only · Enable SSO only authentication, steps 1-5 · Checked 2026-10-01
- 71Enabling SSO-only sign-in in Genesys Cloud requires at least one third-party SSO provider already configured in the org.Configure Genesys Cloud to authenticate with SSO only · Prerequisites · Checked 2026-10-01
- 72SSO-only is reversed by clearing Disable Genesys Cloud Login on the Authentication tab and saving, after which Genesys password requirements must be reconfigured.Configure Genesys Cloud to authenticate with SSO only · Disable SSO only authentication · Checked 2026-10-01
- 73Genesys warns not to enable SSO-only authentication if webhooks are used for chat notification integrations, because that feature needs password-based authentication.Configure Genesys Cloud to authenticate with SSO only · Note under When Genesys Cloud login is disabled · Checked 2026-10-01
- 74Genesys acts on a case-sensitive OrganizationName SAML attribute: for IdP-initiated SSO it carries the org short name, and for SP-initiated SSO it must match the selected org.Add multiple single sign-on providers to Genesys Cloud · SAML attributes table, OrganizationName row · Checked 2026-10-01
- 75Adding an SSO provider in Genesys Cloud requires Single Sign-on > Provider > Add, Delete, Edit and View permissions, an admin role in the IdP, and a single email address shared by the IdP account and Genesys Cloud.Add multiple single sign-on providers to Genesys Cloud · Prerequisites · Checked 2026-10-01
- 76An optional ServiceName SAML attribute redirects the browser after authentication to a URL or to the keywords directory or directory-admin.Add multiple single sign-on providers to Genesys Cloud · SAML attributes table, ServiceName row · Checked 2026-10-01
- 77Genesys Cloud allows up to 30 SSO integrations, with the same or mixed identity providers, and only six appear directly on the login page.Add multiple single sign-on providers to Genesys Cloud · Introduction; Customize the login screen for each SSO integration · Checked 2026-10-01
Documents
About Genesys Cloud SCIM (Identity Management)
Add multiple single sign-on providers to Genesys Cloud
Assign roles to a group
Configure Genesys Cloud for Azure for automatic user provisioning with Microsoft Entra ID
Configure Genesys Cloud for Azure for Single sign-on with Microsoft Entra ID
Configure Genesys Cloud to authenticate with SSO only
Configure Microsoft Entra ID for Genesys Cloud SCIM (Identity Management)
Configure Okta for Genesys Cloud SCIM (Identity Management)
Configure SSO identity provider without email address
Create a group
Create an OAuth client
Release notes for Genesys Cloud SCIM (Identity Management)
SCIM and Genesys Cloud field mappings
What causes Genesys Cloud to change the status of a Microsoft Entra ID user to inactive or to delete a user?
What users can expect after SSO setup
Cite this page
APA
WarmTransfer. (2026, October 1). Setting up SSO and SCIM provisioning for Genesys Cloud. WarmTransfer. https://warmtransfer.net/guides/genesys-cloud-sso-scim-setup
BibTeX
@misc{warmtransfer-genesys-cloud-sso-scim-setup,
title = {Setting up SSO and SCIM provisioning for Genesys Cloud},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/genesys-cloud-sso-scim-setup},
note = {Verified 2026-10-01}
}