How to manage Gateway users and groups
- Reading
- 2 mins
- Category
- Proton VPN for Business
Once you’ve created a Gateway(new window) for your organization, add users(new window) and groups(new window) to give them access to your Gateway’s dedicated servers.
How to add users and groups to a Gateway
1. Sign in to account.protonvpn.com.
2. Go to VPN → Gateways. Next to the Gateway you want to edit, you want. Click the vertical three dots (⋮) → Edit users.

To give everyone access to your Gateway, select The whole organization from the dropdown menu, then click Save to confirm.

To limit access to specific people, select Select who can access from the dropdown menu.

Now you can add users, groups(new window), or both
To add users: Select the Users tab. Select users from the list, or Search for their username or email address.

To add groups: Select the Groups tab. Select groups from the list, or Search for the group’s name.

Click Save when you’re done.
How to remove users or groups from a Gateway
To remove users or groups, simply uncheck them. Note that your organization’s main administrator must always have access to your organization’s Gateways and cannot be unchecked.
Provisioning groups through SCIM
If your organization uses an IdP (identity provider) such as Okta or Microsoft Entra, you can create and manage groups there instead of in Proton. Group and membership changes made in your IdP are mirrored automatically in Proton, so there’s no need for manual updates.
This is especially useful for onboarding and offboarding: when someone joins or leaves a team, their access updates automatically without someone having to grant or revoke permissions each time.
To set up SCIM for your organization, see: