Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Company identity-group synchronization. Read Microsoft Entra, Google Workspace, Okta or OneLogin groups and grant a company role only to explicitly linked active company users. No user is created or linked by email similarity. Current availability: Four direct-membership adapters and scheduled worker implemented; company credentials, reviewed links and live scheduler acceptance required. Before you start. An active Company Workspace and an authorized TLS owner or company role administrator. Existing company users must already have their own approved accounts. A protected company Microsoft 365, Google Workspace, Okta or OneLogin connection in Licenses. Its status must not be paused or in Trash. Dedicated credentials are recommended. Microsoft: Graph application permissions GroupMember.Read.All and User.Read.All with administrator consent. Hidden-membership groups also require Member.Read.Hidden. Google: domain-wide delegation for admin.directory.group.readonly and admin.directory.user.readonly, a delegated administrator and the actual customer ID beginning C. Okta: a token issued to a dedicated read-only administrator with access to the mapped group and users. OneLogin: a dedicated Read All API credential pair. A OneLogin group ID differs from a OneLogin role ID. Step 1. Open Companies > company > Users as the TLS owner, or Company > Users as a company administrator. Under Access groups, create a Dynamic identity-provider group with its immutable group ID and a permitted company role. Company owner, company administrator and TLS roles cannot be inherited from these groups. Step 2. Open Provider membership and synchronization > Read provider members. This performs provider reads and shows returned identities and status. Previewing does not grant permissions or create a sign-in binding. Step 3. For each approved active provider member, select the verified existing company user and Save identity link. Compare the provider’s immutable ID and the person’s company account. Connect re-reads membership before saving. Do not link solely because two displayed email addresses match. Step 4. Review saved links and the group role, select the explicit authorization checkbox, then Enable and synchronize reviewed links. Only linked active members receive inherited permissions. Unmapped people, inactive or unavailable accounts, nested groups and external/guest identities do not receive inherited access from this snapshot. Step 5. Review the last attempt, reported result and grant expiration. The scheduled worker selects groups due after five minutes, with a bounded batch per invocation. Confirm that the hosting scheduler actually invokes it in your production deployment. An installed scheduled handler is not proof of successful scheduled operation. Use Sync now for a direct acceptance test. Step 6. Remove a linked person from the provider group and run Sync now. The inherited role must disappear on the next authorized request. The person’s independent base company role and sign-in account remain unchanged. Step 7. A complete successful snapshot authorizes group access for at most one hour. Failed pagination, provider errors or a failed database batch retain the previous complete snapshot without extending that deadline. Stale inherited permissions expire even if no background job runs. Step 8. Pause inherited access to revoke the group’s inherited permissions immediately. Pausing a group or its directory credential source also pauses inherited access. Unlinking or changing an identity link requires review and explicit enable again. Credential replacement, a recreated source or a different provider tenant cannot silently reuse current grants. Step 9. Test with dedicated provider tenants before customer acceptance. Production provider calls remain disabled in Dev and QA. Retain the provider authorization, identity review, successful sync/removal evidence and scheduled-run evidence in the company’s approved records system. Now verify the result. Previewing a group with an email identical to a company user does not grant access. Only a reviewed immutable identity link plus explicit enable can grant the mapped role. Another company’s users cannot be linked or changed. The group cannot grant owner or administrator roles, create users, alter vendor memberships or modify sign-in identity bindings. Removed provider members lose group-derived permissions after a complete sync. Failed pages preserve the prior snapshot; expired grants and paused sources cannot authorize access. A result arriving after a pause, link change, credential revision or group change cannot overwrite the new state. Database failure rolls the membership transaction back. Provider scope is direct human membership. Microsoft uses active Member directory accounts; Google requires active membership and an unsuspended, unarchived user in the configured customer; Okta requires ACTIVE; OneLogin requires active users with consistent group membership. The last-attempt timestamp advances through real scheduled runs. The reader supports at most 1,000 direct human members and bounded directory pages; oversized groups fail without partial grants. If you get stuck. Directory credentials required: configure the same company’s supported connection in the license center. A generic SSO catalog setting is not sufficient authorization for directory reads. Preview changed: credentials or the provider scope changed. Read members again and review the current links before enabling. Identity already linked: verify the existing association. Unlink deliberately before assigning the provider identity to a different company user. Missing read permissions, hidden-group errors or rate limits: correct the provider’s dedicated application permissions or wait for the documented limit, then retry. Provider response bodies and tokens are not shown. No scheduled attempts: verify the production hosting schedule. Manual Sync now remains available, and stale permissions expire after one hour. Do not assume a scheduler is running because synchronization is enabled. Large groups or directories: split the approved access rule into appropriately scoped groups or arrange a separately reviewed directory integration; Connect does not accept a partial snapshot as complete. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.