Hjemmeside for Proton

How to set up and manage SCIM groups

Lesetid
5 min
Kategorier
Manage users
Proton for business

Groups are natively supported for SCIM on Proton Pass and Proton VPN, meaning you are able to create groups on your identity provider (IdP) such as Okta or Microsoft Entra, and they will be synced with Proton automatically.

Currently, SCIM groups on Proton are available for organizations with the following plans:

  • Pass Professional
  • VPN Professional
  • VPN and Pass Professional bundle

In this article, we explain how to create and manage SCIM groups in Microsoft Entra ID and Okta for your user groups in Proton. We’ll cover how to:

Create SCIM groups on Proton with Microsoft Entra

Before proceeding, ensure you’ve already set up SCIM on Microsoft Entra for Proton Pass and/or Proton VPN, depending on the Proton app you want to use. 

1. Sign in to the Microsoft Entra admin center(nytt vindu). In the sidebar, click Groups, then select All groupsNew group.

2. Set Group type to Security, enter a Group name and optional description, then click Create. Your group is now created and you can add members to it.

3. Open your new group. Click MembersAdd members, select the users you want to include, and click Select.

Now that your group is created and members are added, you can assign this group to the Proton application you want.

4. Open ApplicationsEnterprise applications. Choose the Proton application you want to assign this group to (such as Proton Pass or Proton VPN), then click Users and groupsAdd user/group. Click None Selected, find and select your group, click Select, and then Assign.

This will trigger provisioning, meaning your group and its members will be created in the selected Proton application automatically on the next provisioning cycle. If provisioning isn’t running yet, go to ProvisioningStart provisioning.

Note that Microsoft Entra’s provisioning cycle operates on a schedule (roughly every 40 minutes), so the group may not appear in Proton instantly.

5. Next, you’ll need to approve the group in Proton. Sign in to account.proton.me and select the Proton Pass or Proton VPN app.

6. In the sidebar, go to OrganizationGroups. You should see a notification saying Approve changes from your identity provider.

7. Click Review changes in the notification modal, then review the changes and click Approve. Note that SCIM group members must log in to the platform for the first time before they can be approved.

All done. You can now use this group for all group features on Proton Pass or Proton VPN, depending on the application you assigned it to.

Manage SCIM groups on Proton with Microsoft Entra

SCIM groups can’t be edited or deleted through Proton. Instead, you’ll need to do so in Microsoft Entra.

To remove specific members from a SCIM group on Microsoft Entra:

1. Sign in to the Microsoft Entra admin center(nytt vindu). Go to GroupsAll groups → select the group → Members.

2. Select the member, click Remove, and confirm.

The change will be automatically synced to Proton on the next provisioning cycle.

To delete a SCIM group on Microsoft Entra:

1. Sign in to the Microsoft Entra admin center(nytt vindu). Open ApplicationsEnterprise apps → your chosen Proton application → Users and groups.
2. Select the group, click Remove assignment, and confirm.

The group is now deleted. The change will be automatically synced to Proton on the next provisioning cycle.

Create SCIM groups for Proton with Okta

Before proceeding, ensure you’ve already set up SCIM on Okta for Proton Pass and/or Proton VPN, depending on the Proton application you want to use. 

1. Sign in to Okta(nytt vindu). Go to DirectoryGroups and select Add group. Enter a name and optional description, and press Save.

Your group is now created and you can add members to it.

2. Open your new group and click Assign people. Select the users you want to include with the + icon, then click Done.

Now that your group is created and members are added, you can assign this group to the Proton application you want.

3. Go to ApplicationsApplications → select the Proton application you want to use this group with (such as Proton Pass or Proton VPN). Go to the Assignments tab, then click AssignAssign to Groups, select your group, and click Done

This ensures your group’s members are provisioned to Proton as users.

4. Next, go to the Push Groups tab, click Push GroupsFind groups by name and select your group. Choose Create group and press Save, then wait until the push status shows Active.

5. Next, you’ll need to approve the group in Proton. Sign in to account.proton.me and select the Proton Pass or Proton VPN app.

6. In the sidebar, go to OrganizationGroups. You should see a notification saying Approve changes from your identity provider.

7. Click Review changes in the notification modal, then review the changes and click Approve. Note that SCIM group members must log in to the platform for the first time before they can be approved.

All done. You can now use this group for all group features on Proton Pass or Proton VPN, depending on the application you assigned it to.

Manage SCIM groups for Proton with Okta

SCIM groups can’t be edited or deleted through Proton. Instead, you’ll need to do so in Microsoft Entra.

To remove specific members from a SCIM group on Okta:

1. Sign in to Okta(nytt vindu), then go to DirectoryGroups → select the group.

2. Look for the member you want to remove, then click the ✕ next to their name and confirm the change.

The change syncs automatically to Proton on the next push.

To delete a SCIM group on Okta:

1. Sign in to Okta(nytt vindu), then open your Proton application and go to the Push Groups tab. Click the group’s Active status, then click Unlink pushed group.

2. In the dialog, choose Delete the group in the target app, then confirm.

The group is now unlinked and will be removed from Proton automatically on the next push.