Connect an identity provider
Integrate your IdP with Threatmatic for identity-aware enforcement
Connect an identity provider
Connecting an identity provider (IdP) allows Threatmatic to automatically resolve user identities, sync groups, and enforce identity-aware policies across your fleet.
Supported providers
- Google Workspace
- Microsoft Azure AD
- Microsoft Active Directory
- Okta
- Any OIDC-compatible provider (Ping Identity, OneLogin, JumpCloud, and others)
Need a provider not listed here? Contact us — we can work with any OIDC or SAML 2.0 compliant directory.
Steps
Open IdP Integration
- Sign in to the Threatmatic Console
- Navigate to Organization → IdP Integration
- Click Add Provider
Select your provider
Choose your identity provider from the list. Threatmatic will display the required configuration fields for that provider.
Configure the connection
- In the Google Cloud Console, create a new OAuth 2.0 client 2. Enable the Admin SDK Directory API 3. Copy the Client ID and Client Secret into the Threatmatic Console 4. Authorize the required scopes for directory access
- In the Azure Portal, register a new application under Entra ID → App Registrations 2. Copy the Client ID, Tenant ID, and create a Client Secret
- Paste these into the Threatmatic Console 4. Grant the following Microsoft Graph permissions:
User.Read.All,Group.Read.All
- Create a service account in Active Directory with read access to users and groups 2. Enter your AD domain, service account username, and password in the Threatmatic Console 3. Specify the base DN for the user and group search scope
- In the Okta Admin Console, go to Applications → Create App Integration 2. Select OIDC as the sign-in method and Web Application as the app type 3. Set the redirect URI to the callback URL shown in the Threatmatic Console 4. Copy the Client ID and Client Secret into the Threatmatic Console 5. Assign the application to the groups you want to sync
- Register a new application in your provider's developer console to obtain a Client ID and
Client Secret 2. Set the redirect URI to the callback URL shown in the Threatmatic
Console 3. Enter your provider's Discovery URL (e.g.
https://your-provider.com/.well-known/openid-configuration) — Threatmatic will auto-discover all required endpoints 4. Configure scopes: at minimumopenid,email,profile; addgroupsif your provider supports it for group sync
Test the connection
Click Test Connection. Threatmatic will verify credentials and attempt to read a sample of users and groups from your directory.
Enable sync
Once the test passes, click Enable Sync. Threatmatic will begin mapping user and group identities immediately.
Identity sync runs continuously. Changes in your IdP — new users, group membership changes, deprovisioned accounts — are reflected in Threatmatic within minutes.
Next steps
How is this guide?
Last updated on