User Management with AskCody
Learn the different ways to manage users in AskCody
An AskCody user is required to access many parts of the platform. How users are created, updated, and removed depends on how user management is configured in your organization.
AskCody currently supports three ways of managing users:
-
SCIM-based User Provisioning with Entra ID (recommended)
-
Active Directory Server Integration
-
Manual user management
Other legacy synchronization methods are deprecated and will be discontinued in the future.
You can read more about AskCody users and user roles here
SCIM-Based User Provisioning with Entra ID (Recommended)
SCIM-based user provisioning is the recommended and best-practice way to manage users in AskCody. It is fully cloud-based, performs better than legacy integrations, and provides the most accurate and scalable user management model.
How it works
-
Users are synchronized from Microsoft Entra ID using SCIM
-
Access to AskCody is granted through Entra ID group memberships
-
Roles and permissions are assigned at the group level
-
All members of a group receive the same level of access in AskCody
User lifecycle behavior
-
Users added to scoped Entra ID groups are created in AskCody
-
Users removed from those groups are deleted from AskCody
-
Users with disabled sign-in in Entra ID are marked as inactive in AskCody
-
If a user is deleted and later re-added in Entra ID, they are automatically re-created in AskCody
Key benefits
-
Centralized access control
-
Cleaner and more accurate user lists
-
No manual maintenance required
-
Improved performance and reliability compared to legacy integrations
Customers using Entra ID are strongly encouraged to use SCIM-based App Provisioning, as this is the standard moving forward.
Active Directory Server Integration
Active Directory Server Integration is an on-premises solution that runs as a service on a Windows server in your network. It uses a service account to access your Active Directory and synchronize users from selected AD security groups to AskCody.
How it works
-
The service runs on your own Windows server
-
Users from configured AD security groups are synchronized to AskCody every hour
-
Users are created and updated automatically based on group membership
Role management behavior
-
You can manually add roles to users managed by this integration
-
The service will not overwrite manually added roles
-
If you manually remove a role that the integration is configured to assign, the service will reapply that role during the next sync
While Active Directory Server Integration is still supported, it is considered a legacy setup. Customers using this integration are encouraged to plan a migration to SCIM-based user provisioning with Entra ID for better performance, security, and long-term support.
To learn more about Active Directory Server Integration and how to set it up, please click here
Manual User Management
Manual user management is handled entirely within the AskCody Management Portal.
How it works
-
Users are created manually in AskCody
-
Roles and permissions are assigned per user
-
Passwords and login details are managed in AskCody
-
Users are updated and deleted manually on a user-by-user basis
When to use manual management
-
Small organizations with very few users
-
Proof of concepts or demo environments
-
Temporary setups where directory integration is not available
For most production environments, manual user management is not recommended due to the administrative overhead involved.