8.2 Cloud Identity Management, SCIM & Directory Connector

Key Takeaways

  • User identity management in Cisco Webex supports manual provisioning, bulk CSV imports, on-premises Active Directory synchronization via Cisco Directory Connector, and cloud-native SCIM 2.0 push provisioning.

  • Cisco Directory Connector runs as a Windows Server service communicating locally with Domain Controllers over Secure LDAP (LDAPS port 636) and pushes identity updates outbound to Webex Cloud over HTTPS port 443.

  • The Dry-Run mode in Cisco Directory Connector generates an audit simulation report detailing proposed object additions, modifications, and deletions without modifying cloud state, preventing catastrophic user deletions caused by misconfigured search filters.

  • SCIM 2.0 (RFC 7643/7644) delivers real-time, cloud-to-cloud identity lifecycle management from IdPs like Microsoft Entra ID and Okta, executing RESTful user creation, attribute synchronization, and immediate deactivation via long-lived Bearer tokens.

  • SAML 2.0 Single Sign-On (SSO) supports both SP-initiated and IdP-initiated authentication flows, where Webex functions as the Service Provider, validating signed assertions containing the user's primary email address (NameID) against the trusted IdP public X.509 certificate.

Last updated: October 2026

8.2 Cloud Identity Management, SCIM & Directory Connector

Scalable enterprise collaboration relies on seamless identity lifecycle management. User onboarding, attribute synchronization, single sign-on authentication, and administrative privilege scoping must integrate with enterprise identity stores while maintaining security, automated provisioning, and strict role isolation.


1. User Identity Lifecycle in Cisco Webex

In Webex Control Hub, every user account requires a unique email address acting as the primary identity anchor. Organizations utilize three primary methods for populating and maintaining user identities:

  1. Manual User Creation: Entering user attributes (First Name, Last Name, Email, Display Name) individually through the Control Hub UI. Suitable for small pilot deployments or test labs, but unmanageable at enterprise scale.
  2. Bulk CSV Import: Uploading a formatted comma-separated values (CSV) file containing thousands of user records. Control Hub provides a downloadable CSV template with standard column headers:
    • First Name, Last Name, Display Name, Email Address
    • Service entitlements: Webex Calling Professional, Webex Meetings, Webex Messaging
    • Telephony fields: Phone Number (E.164 format, e.g. +14085550100), Extension (e.g. 5100), Location
  3. Automated Directory Synchronization: Establishing continuous, automated synchronization from an enterprise identity store—either on-premises Active Directory via Cisco Directory Connector or cloud Identity Providers via SCIM 2.0.

Domain Verification & Domain Claiming

To enforce enterprise identity governance, an organization must prove ownership of its corporate email domains:

  • Domain Verification: An administrator enters the domain name in Control Hub (e.g., example.com) and adds a DNS TXT record containing the Control Hub-generated verification token to the domain's public DNS. Control Hub queries public DNS to validate domain ownership.
  • Domain Claiming: Once verified, the administrator 'claims' the domain. A claimed domain is controlled by one organization: other Webex organizations can no longer have users with that domain, which lets the company bring stray accounts under its own policies.

User States in Control Hub

  • Active: The user has signed in and can use the assigned services.
  • Not verified: The user was invited but has not completed the first sign-in.
  • Inactive / deactivated: The user cannot sign in, but the account and its data remain (for example, after a SCIM active=false update).
  • Deleted: The user is removed from the organization and the licenses are released.

2. Cisco Directory Connector Architecture & Configuration

Cisco Directory Connector is an on-premises synchronization agent designed for enterprises using Microsoft Active Directory Domain Services (AD DS) as their authoritative identity authority.

+-------------------------------------------------------------------------------------+
|                                ENTERPRISE PERIMETER                                 |
|                                                                                     |
|    +-----------------------------+               +-----------------------------+    |
|    |  Active Directory Domain    |               |  Cisco Directory Connector  |    |
|    |  Controller (LDAP Server)   |               |  (Windows Server 2016-2022) |    |
|    +--------------+--------------+               +--------------+--------------+    |
|                   |                                             |                   |
|                   |<============= LDAPS (TCP 636) =============>|                   |
|                   |               Active Directory Queries      |                   |
+-------------------|---------------------------------------------|-------------------+
                    |                                             |
                    |                                             v Outbound HTTPS (TCP 443)
                    |                                   +-----------------------------+
                    |                                   |  Cisco Webex Cloud          |
                    +---------------------------------->|  Identity Broker            |
                                                        |  (idbroker.webex.com)       |
                                                        +-----------------------------+

Network Architecture & Communication Protocols

  • Local Directory Access: Directory Connector communicates with local Active Directory Domain Controllers over Secure LDAP (LDAPS) on TCP port 636 or Global Catalog over TCP port 3269. LDAPS requires installing the enterprise root CA certificate on the Directory Connector server to establish mutual cryptographic trust.
  • Cloud Synchronization: Directory Connector initiates outbound HTTPS connections over TCP port 443 directly to idbroker.webex.com. No inbound firewall pinholes are required.

Attribute Mapping Engine

Directory Connector maps standard Active Directory attributes to Webex identity fields:

Webex Identity FieldDefault Active Directory AttributeOperational Notes
Email (User ID)mail or userPrincipalNamePrimary unique key; must be a valid, routable email address.
First NamegivenNameDisplayed across Webex App and contact cards.
Last Namesn (Surname)Displayed across Webex App and contact cards.
Display NamedisplayNameComputed user name shown in meetings and spaces.
Phone NumbertelephoneNumberMust be formatted as standard E.164 (e.g. +12125550199).
Mobile PhonemobileSynchronized for directory lookup and SMS notifications.
Department / Titledepartment, titleInformational attributes populated in user profiles.

Synchronization Agreements & LDAP Filters

Administrators configure LDAP search filters to select only authorized user objects while excluding service accounts, generic mailboxes, and disabled accounts:

(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(memberOf=CN=Webex_Users,OU=Groups,DC=corp,DC=example,DC=com))

(Note: Bitwise filter !(userAccountControl:1.2.840.113556.1.4.803:=2) filters out disabled Active Directory accounts).

Operational Modes: Dry-Run vs. Production Sync

  • Full Synchronization: Traverses the entire directory subtree defined in the Base DN and synchronizes all matching objects.
  • Periodic Delta Synchronization: Queries Active Directory using Update Sequence Numbers (USN) or whenChanged timestamps to synchronize only modified objects; scheduled every 30 minutes by default.
  • Dry-Run Mode (Simulation):
    • Executes the full LDAP query and attribute mapping engine without writing changes to Webex cloud.
    • Generates a detailed audit simulation report detailing the exact number of users to be created, modified, or deleted.
    • Critical Best Practice: Administrators must run Dry-Run mode before activating production synchronization. A typo in an LDAP search filter or base DN can inadvertently mark thousands of users for deletion.
  • Object Deletion Threshold: An administrative safety guard (a percentage threshold that stops the sync when too many users would be deleted at once) preventing catastrophic mass deactivation if an OU is moved or deleted in Active Directory.

3. SCIM 2.0 Cloud Identity Provisioning

System for Cross-domain Identity Management (SCIM 2.0), defined by RFC 7643 (Core Schema) and RFC 7644 (Protocol), is the industry standard for automated, cloud-to-cloud identity provisioning.

Architecture: SCIM Client vs. SCIM Service Provider

In modern cloud architectures, enterprises utilize cloud Identity Providers (such as Microsoft Entra ID / Azure AD, Okta, PingFederate, or CyberArk) as their primary directory.

  • The cloud IdP acts as the SCIM Client.
  • Cisco Webex Control Hub acts as the SCIM Service Provider.
  • Communication occurs cloud-to-cloud over outbound HTTPS (port 443), eliminating the need to deploy, patch, or maintain on-premises Windows servers or Directory Connector instances.

SCIM Endpoint & Authentication

  • Base Endpoint URL: https://webexapis.com/identity/scim/{orgId}/v2/
    • Users Endpoint: https://webexapis.com/identity/scim/{orgId}/v2/Users
    • Groups Endpoint: https://webexapis.com/identity/scim/{orgId}/v2/Groups
  • Authentication: Secured with an OAuth 2.0 bearer token issued to a Webex full administrator. Microsoft's Entra ID tutorial obtains it by signing in as that administrator, and the token is valid for 365 days. The token is entered in the IdP's provisioning settings and sent in every request header:
    Authorization: Bearer eyJhbGciOiJSUzI1NiIsIng1YyI6Wy...<token>...
    

Supported SCIM REST Operations

HTTP MethodSCIM EndpointAction Executed in Webex Control Hub
POST/v2/UsersProvisions a new user, applies attribute mappings, and triggers automated license assignment.
GET/v2/Users?filter=userName eq "..."Queries user existence by email / username prior to updates.
PUT/v2/Users/{id}Replaces all user attributes with the complete updated JSON payload.
PATCH/v2/Users/{id}Performs granular delta updates (e.g., updating a phone number or modifying group membership).
PATCH (Deactivate)/v2/Users/{id}Disables user access instantly by sending {"Operations":[{"op":"replace","path":"active","value":false}]}.
DELETE/v2/Users/{id}Permanently deprovisions the user object and reclaims assigned licenses.

Real-Time Deprovisioning Advantage

Unlike on-premises Directory Connector, which relies on scheduled polling intervals (e.g. running every 1 or 2 hours), SCIM 2.0 delivers instant, event-driven deprovisioning. When an employee is deactivated in Entra ID or Okta, the IdP sends an immediate SCIM PATCH request setting active: false. Webex instantly terminates the user's active session tokens, revokes client access, and reclaims calling licenses.


4. Single Sign-On (SSO) with SAML 2.0

While Directory Connector and SCIM govern identity provisioning (creating and maintaining user records), Security Assertion Markup Language (SAML 2.0) governs identity authentication (verifying user passwords and multi-factor credentials).

SAML Federation Roles

  • Service Provider (SP): Cisco Webex Control Hub (idbroker.webex.com).
  • Identity Provider (IdP): Enterprise identity service (Microsoft Entra ID, AD FS, Okta, PingFederate).

Configuration Workflow & Metadata Exchange

+-------------------------------------------------------------------------------------+
|                               SAML METADATA EXCHANGE                                |
|                                                                                     |
|    +-----------------------------+               +-----------------------------+    |
|    |  Cisco Webex Control Hub    |               |  Enterprise Identity        |    |
|    |  Service Provider (SP)      |               |  Provider (IdP)             |    |
|    +--------------+--------------+               +--------------+--------------+    |
|                   |                                             |                   |
|                   |------ 1. Export SP Metadata XML ----------->|                   |
|                   |   (Entity ID, ACS URL, SP Signing Cert)     |                   |
|                   |                                             |                   |
|                   |<----- 2. Upload IdP Metadata XML -----------|                   |
|                   |   (IdP Entity ID, SSO URL, Public Cert)     |                   |
+-------------------|---------------------------------------------|-------------------+
  1. Export SP Metadata: The administrator downloads the SP metadata XML file from Control Hub. The file contains:
    • SP Entity ID: Unique Webex identifier (e.g. https://idbroker.webex.com/a4f1...)
    • Assertion Consumer Service (ACS) URL: The idbroker.webex.com endpoint that receives SAML assertions (copy it from the downloaded metadata rather than typing it)
    • SP Signing Certificate: Public X.509 certificate used by Webex to sign AuthnRequest messages.
  2. Configure Enterprise IdP: The administrator imports the SP metadata into the IdP and configures the SAML claim rules. The IdP must map the user's primary enterprise email address to the SAML NameID attribute (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress or unspecified).
  3. Import IdP Metadata into Control Hub: The administrator downloads the IdP metadata XML (containing the IdP Entity ID, SingleSignOnService redirect URL, and the IdP public X.509 signing certificate) and uploads it into Control Hub.
  4. Mandatory SSO Test: Before allowing the administrator to enable SSO organization-wide, Control Hub enforces an interactive single sign-on test. The administrator must successfully authenticate in a popup browser window. This prevents tenant lockout caused by mismatched claim rules or expired certificates.

SP-Initiated vs. IdP-Initiated Authentication Flows

  • SP-Initiated Flow (Standard for Webex App):
    1. The user launches the Webex App or opens webex.com and enters their email (user@example.com).
    2. Webex identifies the claimed domain and generates a cryptographic SAML AuthnRequest.
    3. The user's client is redirected to the enterprise IdP SingleSignOnService URL.
    4. The user completes authentication at the IdP (entering credentials, completing Duo/FIDO2 MFA).
    5. The IdP generates a SAML Response containing a cryptographically signed assertion and posts it to the Webex ACS URL.
    6. Webex verifies the signature using the uploaded IdP certificate, extracts the NameID email, matches the user record, and issues OAuth session tokens.
  • IdP-Initiated Flow:
    1. The user logs into their enterprise portal (e.g., Microsoft 365 MyApps or Okta Dashboard).
    2. The user clicks the Webex application icon.
    3. The IdP generates an unsolicited signed SAML assertion and sends an HTTP POST directly to the Webex ACS URL.

5. Role-Based Access Control (RBAC) in Control Hub

Control Hub enforces strict separation of duties through granular administrative roles, adhering to the principle of least privilege:

Administrative RoleFunctional PrivilegesKey Restrictions
Full AdministratorUnrestricted access across all services, user lifecycle, security settings, billing, and organizational parameters.Only role capable of managing other Full Admins and organization-wide security keys.
User and Device AdministratorAdd, edit, and delete users; assign service licenses; provision and configure hardware devices and workspaces.Cannot modify billing subscriptions, global SSO configurations, or view compliance archives.
Read-Only AdministratorInspect all configurations, user lists, device health states, and operational reports.Cannot modify any setting, add users, or reallocate licenses.
Compliance OfficerManage message retention policies, configure Legal Holds, perform eDiscovery searches, and export compliance archives.Cannot configure telephony dial plans, register devices, or manage user licenses.
Location AdministratorScoped administrative authority restricted to specific physical locations (e.g., managing local branch auto-attendants, hunt groups, and local phone assignments).Cannot view or modify configurations, dial plans, or devices in other locations.
Support AdministratorView analytics and troubleshooting data, such as call and meeting quality, to support users.Cannot change users, devices, or settings.
Device AdministratorAdd and manage devices and workspaces.Cannot manage users or licenses.

Full administrators can also build custom roles from individual permissions with the role builder, and Webex site administrator roles control individual meeting sites.

Loading diagram...
SCIM 2.0 User Provisioning and SAML 2.0 SP-Initiated Authentication Sequence
Test Your Knowledge

An enterprise is planning to automate user identity provisioning from Microsoft Entra ID to Cisco Webex Control Hub without deploying on-premises servers or maintaining inbound firewall pinholes. Which identity integration protocol and architectural configuration should the enterprise deploy?

A

Administrative XML (AXL) API push queries triggered by an on-premises CUCM Publisher node.

B

SCIM 2.0 cloud-to-cloud provisioning configured with a long-lived Bearer token generated in Control Hub.

C

Cisco Directory Connector installed on a perimeter DMZ Windows Server communicating over LDAP port 389.

D

SAML 2.0 assertion exchange configured with periodic batch imports using CSV files over SFTP.

Test Your Knowledge

A collaboration administrator prepares to deploy Cisco Directory Connector on an on-premises Windows Server to synchronize 8,000 corporate users from Active Directory to Webex Control Hub. Prior to executing the initial production synchronization, which operational mode must the administrator run to verify LDAP query accuracy and prevent accidental bulk user deletions?

A

SAML metadata export mode to validate Identity Provider certificate trust.

B

Kerberos single sign-on verification mode to authenticate local Domain Controller tickets.

C

Full production sync with the deletion threshold disabled to force all changes to commit immediately.

D

Dry-Run mode (simulation) to inspect proposed additions, updates, and deletions in a verification report.

Test Your Knowledge

An organization configures SAML 2.0 Single Sign-On (SSO) between Cisco Webex and Okta. During user login testing, users can successfully authenticate when starting from the Okta application portal, but encounter an authentication error when attempting to sign in directly from the Webex App desktop client. What is the root cause of this discrepancy?

A

The administrator omitted the SCIM 2.0 Bearer token in the SAML AuthnRequest HTTP payload.

B

The enterprise IdP does not support mutual TLS encryption over the SIP signaling port 5061 used by Webex.

C

SSO works only IdP-initiated; the Webex App starts SP-initiated SSO, which needs a correct Assertion Consumer Service configuration.

D

Webex App desktop clients cannot use SAML SSO at all and must authenticate exclusively with static basic credentials stored in Control Hub.

Sections you finish are checked off in the contents.