LogoThreatmatic
Identity

Connect an identity provider

Integrate your IdP with Threatmatic for identity-aware enforcement

Connect an identity provider

Connecting an identity provider (IdP) allows Threatmatic to automatically resolve user identities, sync groups, and enforce identity-aware policies across your fleet.

Supported providers

  • Google Workspace
  • Microsoft Azure AD
  • Microsoft Active Directory
  • Okta
  • Any OIDC-compatible provider (Ping Identity, OneLogin, JumpCloud, and others)

Need a provider not listed here? Contact us — we can work with any OIDC or SAML 2.0 compliant directory.

Steps

Open IdP Integration

  1. Sign in to the Threatmatic Console
  2. Navigate to Organization → IdP Integration
  3. Click Add Provider

Select your provider

Choose your identity provider from the list. Threatmatic will display the required configuration fields for that provider.

Configure the connection

  1. In the Google Cloud Console, create a new OAuth 2.0 client 2. Enable the Admin SDK Directory API 3. Copy the Client ID and Client Secret into the Threatmatic Console 4. Authorize the required scopes for directory access
  1. In the Azure Portal, register a new application under Entra ID → App Registrations 2. Copy the Client ID, Tenant ID, and create a Client Secret
  2. Paste these into the Threatmatic Console 4. Grant the following Microsoft Graph permissions: User.Read.All, Group.Read.All
  1. Create a service account in Active Directory with read access to users and groups 2. Enter your AD domain, service account username, and password in the Threatmatic Console 3. Specify the base DN for the user and group search scope
  1. In the Okta Admin Console, go to Applications → Create App Integration 2. Select OIDC as the sign-in method and Web Application as the app type 3. Set the redirect URI to the callback URL shown in the Threatmatic Console 4. Copy the Client ID and Client Secret into the Threatmatic Console 5. Assign the application to the groups you want to sync
  1. Register a new application in your provider's developer console to obtain a Client ID and Client Secret 2. Set the redirect URI to the callback URL shown in the Threatmatic Console 3. Enter your provider's Discovery URL (e.g. https://your-provider.com/.well-known/openid-configuration) — Threatmatic will auto-discover all required endpoints 4. Configure scopes: at minimum openid, email, profile; add groups if your provider supports it for group sync

Test the connection

Click Test Connection. Threatmatic will verify credentials and attempt to read a sample of users and groups from your directory.

Enable sync

Once the test passes, click Enable Sync. Threatmatic will begin mapping user and group identities immediately.

Identity sync runs continuously. Changes in your IdP — new users, group membership changes, deprovisioned accounts — are reflected in Threatmatic within minutes.

Next steps

How is this guide?

Last updated on

On this page