> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect your employee directory

> Choose where Cimento imports employees and groups from, whether Okta, Microsoft Entra ID or Google Workspace, and what gets imported.

Cimento's employee list drives everything else: phishing audiences, training assignments and reporting. Import it from the directory your organization already uses. Cimento supports three: Okta and Microsoft Entra ID, which send employees to Cimento over SCIM, and Google Workspace, which Cimento reads with read-only access.

## Choose your directory

| | Okta | Microsoft Entra ID | Google Workspace |
| - | - | - | - |
| How employees reach Cimento | Okta sends users and groups to Cimento over SCIM | Entra sends users and groups to Cimento over SCIM | Cimento reads users and groups from Google once a day |
| Setup guide | [Connect Okta](/integrations/okta) | [Connect Microsoft Entra ID](/integrations/microsoft-entra-id) | [Connect Google Workspace](/integrations/google-workspace#import-your-directory) |
| Admin you need | An Okta Super Administrator or Application Administrator | An Entra Application Administrator, Cloud Application Administrator or Global Administrator | A Google Workspace Super Admin |
| Who is imported | The people and groups you assign to the app in Okta | The people and groups you assign to the application in Entra | Active users in your organization's email domains, and their groups |
| Single sign-on | Set up in the same app | Set up in the same application | Not part of this setup |
| Access Cimento gets | None. Cimento only receives what Okta sends. | None. Cimento only receives what Entra sends. | Read-only access to users, groups and group memberships |

<Note>
  Your organization connects one directory. Once it's configured, the choice is locked; contact support to change it.
</Note>

## Before you start

* **Where to start.** Go to **Admin → Integrations → Employee data** in Cimento and choose your provider under **Directory provider**. If you don't see **Employee data**, ask your Cimento contact to enable it.
* **Your email domains.** Cimento records your organization's email domains when it creates your account. Single sign-on covers only those domains, and Google Workspace sync imports only people in them. Ask your Cimento contact to add any that are missing.
* **Manual employee management turns off.** As soon as you click **Begin Setup**, employees come from your directory. You can no longer add or upload employees in Cimento, or edit their names, email addresses, status or departments. You can still change their roles.

## What Okta and Microsoft Entra ID send

### Employee attributes

| SCIM attribute | In Cimento |
| - | - |
| `userName` | The identifier your directory uses to match the employee |
| `emails`, the entry marked primary | The employee's email address |
| `name.givenName`, `name.familyName`, `displayName` | The employee's name |
| `active` | Whether the employee is active |
| `title` | Title |
| `phoneNumbers` | Phone numbers, used to enroll employees in [SMS and voice](/phishing/sms-and-voice) simulations |
| `addresses` | Location, from the primary address |
| Enterprise `department` | Department. Cimento matches the name exactly, including capitalization, and creates the department if none matches. |
| Enterprise `manager` | Manager |
| Enterprise `employeeNumber`, `costCenter`, `organization`, `division` | Stored on the employee's record |

### Groups

Pushed groups become Cimento groups with the same members. A group can only include people your directory has already provisioned to Cimento. Group names must be unique in Cimento regardless of capitalization, so rename any existing Cimento group that has the same name as one you push.

### When someone leaves

When you deactivate or unassign someone in Okta or Entra, Cimento deactivates them. They can no longer sign in, and they drop out of campaign audiences. If your directory deletes the account, Cimento also removes them from their groups. Cimento never deletes the employee record, so their history stays in your reports.

<Warning>
  The API token (Okta) or secret token (Entra) lets your directory create, update and deactivate employees in Cimento. Store it like a password. To stop provisioning, turn it off in Okta or Entra.
</Warning>

## What Cimento imports from Google Workspace

* **Users** in your email domains: primary email, name, and the department and job title from their employee information. Suspended and archived users aren't imported.
* **Groups** in your email domains, with their names and descriptions.
* **Group members** who are users in your directory. Members of nested groups and addresses outside your directory are skipped.

Cimento doesn't import phone numbers, managers, aliases or locations from Google. Its scopes give it no access to mail, files or anything else outside the directory.

### When someone leaves

At the next daily sync, anyone suspended, archived or deleted in Google, or moved out of your email domains, is deactivated in Cimento and signed out of Cimento. Cimento never deletes the employee record, so their history stays in your reports. Restoring the user in Google reactivates them at the following sync.

### Keep accounts out of Cimento

If your organization has **Admin → Integrations → Sync exclusions**, use it to keep service accounts, shared mailboxes or whole Google groups out of Cimento. Excluded people and groups are hidden everywhere and aren't imported again. Re-including one brings it back with an immediate re-import.
