8.2 Cloud Identity Management, SCIM & Directory Connector
Key Takeaways
User identity management in Cisco Webex supports manual provisioning, bulk CSV imports, on-premises Active Directory synchronization via Cisco Directory Connector, and cloud-native SCIM 2.0 push provisioning.
Cisco Directory Connector runs as a Windows Server service communicating locally with Domain Controllers over Secure LDAP (LDAPS port 636) and pushes identity updates outbound to Webex Cloud over HTTPS port 443.
The Dry-Run mode in Cisco Directory Connector generates an audit simulation report detailing proposed object additions, modifications, and deletions without modifying cloud state, preventing catastrophic user deletions caused by misconfigured search filters.
SCIM 2.0 (RFC 7643/7644) delivers real-time, cloud-to-cloud identity lifecycle management from IdPs like Microsoft Entra ID and Okta, executing RESTful user creation, attribute synchronization, and immediate deactivation via long-lived Bearer tokens.
SAML 2.0 Single Sign-On (SSO) supports both SP-initiated and IdP-initiated authentication flows, where Webex functions as the Service Provider, validating signed assertions containing the user's primary email address (NameID) against the trusted IdP public X.509 certificate.
8.2 Cloud Identity Management, SCIM & Directory Connector
Scalable enterprise collaboration relies on seamless identity lifecycle management. User onboarding, attribute synchronization, single sign-on authentication, and administrative privilege scoping must integrate with enterprise identity stores while maintaining security, automated provisioning, and strict role isolation.
1. User Identity Lifecycle in Cisco Webex
In Webex Control Hub, every user account requires a unique email address acting as the primary identity anchor. Organizations utilize three primary methods for populating and maintaining user identities:
- Manual User Creation: Entering user attributes (First Name, Last Name, Email, Display Name) individually through the Control Hub UI. Suitable for small pilot deployments or test labs, but unmanageable at enterprise scale.
- Bulk CSV Import: Uploading a formatted comma-separated values (CSV) file containing thousands of user records. Control Hub provides a downloadable CSV template with standard column headers:
First Name,Last Name,Display Name,Email Address- Service entitlements:
Webex Calling Professional,Webex Meetings,Webex Messaging - Telephony fields:
Phone Number(E.164 format, e.g.+14085550100),Extension(e.g.5100),Location
- Automated Directory Synchronization: Establishing continuous, automated synchronization from an enterprise identity store—either on-premises Active Directory via Cisco Directory Connector or cloud Identity Providers via SCIM 2.0.
Domain Verification & Domain Claiming
To enforce enterprise identity governance, an organization must prove ownership of its corporate email domains:
- Domain Verification: An administrator enters the domain name in Control Hub (e.g.,
example.com) and adds a DNS TXT record containing the Control Hub-generated verification token to the domain's public DNS. Control Hub queries public DNS to validate domain ownership. - Domain Claiming: Once verified, the administrator 'claims' the domain. A claimed domain is controlled by one organization: other Webex organizations can no longer have users with that domain, which lets the company bring stray accounts under its own policies.
User States in Control Hub
- Active: The user has signed in and can use the assigned services.
- Not verified: The user was invited but has not completed the first sign-in.
- Inactive / deactivated: The user cannot sign in, but the account and its data remain (for example, after a SCIM
active=falseupdate). - Deleted: The user is removed from the organization and the licenses are released.
2. Cisco Directory Connector Architecture & Configuration
Cisco Directory Connector is an on-premises synchronization agent designed for enterprises using Microsoft Active Directory Domain Services (AD DS) as their authoritative identity authority.
+-------------------------------------------------------------------------------------+
| ENTERPRISE PERIMETER |
| |
| +-----------------------------+ +-----------------------------+ |
| | Active Directory Domain | | Cisco Directory Connector | |
| | Controller (LDAP Server) | | (Windows Server 2016-2022) | |
| +--------------+--------------+ +--------------+--------------+ |
| | | |
| |<============= LDAPS (TCP 636) =============>| |
| | Active Directory Queries | |
+-------------------|---------------------------------------------|-------------------+
| |
| v Outbound HTTPS (TCP 443)
| +-----------------------------+
| | Cisco Webex Cloud |
+---------------------------------->| Identity Broker |
| (idbroker.webex.com) |
+-----------------------------+
Network Architecture & Communication Protocols
- Local Directory Access: Directory Connector communicates with local Active Directory Domain Controllers over Secure LDAP (LDAPS) on TCP port 636 or Global Catalog over TCP port 3269. LDAPS requires installing the enterprise root CA certificate on the Directory Connector server to establish mutual cryptographic trust.
- Cloud Synchronization: Directory Connector initiates outbound HTTPS connections over TCP port 443 directly to
idbroker.webex.com. No inbound firewall pinholes are required.
Attribute Mapping Engine
Directory Connector maps standard Active Directory attributes to Webex identity fields:
| Webex Identity Field | Default Active Directory Attribute | Operational Notes |
|---|---|---|
| Email (User ID) | mail or userPrincipalName | Primary unique key; must be a valid, routable email address. |
| First Name | givenName | Displayed across Webex App and contact cards. |
| Last Name | sn (Surname) | Displayed across Webex App and contact cards. |
| Display Name | displayName | Computed user name shown in meetings and spaces. |
| Phone Number | telephoneNumber | Must be formatted as standard E.164 (e.g. +12125550199). |
| Mobile Phone | mobile | Synchronized for directory lookup and SMS notifications. |
| Department / Title | department, title | Informational attributes populated in user profiles. |
Synchronization Agreements & LDAP Filters
Administrators configure LDAP search filters to select only authorized user objects while excluding service accounts, generic mailboxes, and disabled accounts:
(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(memberOf=CN=Webex_Users,OU=Groups,DC=corp,DC=example,DC=com))
(Note: Bitwise filter !(userAccountControl:1.2.840.113556.1.4.803:=2) filters out disabled Active Directory accounts).
Operational Modes: Dry-Run vs. Production Sync
- Full Synchronization: Traverses the entire directory subtree defined in the Base DN and synchronizes all matching objects.
- Periodic Delta Synchronization: Queries Active Directory using Update Sequence Numbers (USN) or
whenChangedtimestamps to synchronize only modified objects; scheduled every 30 minutes by default. - Dry-Run Mode (Simulation):
- Executes the full LDAP query and attribute mapping engine without writing changes to Webex cloud.
- Generates a detailed audit simulation report detailing the exact number of users to be created, modified, or deleted.
- Critical Best Practice: Administrators must run Dry-Run mode before activating production synchronization. A typo in an LDAP search filter or base DN can inadvertently mark thousands of users for deletion.
- Object Deletion Threshold: An administrative safety guard (a percentage threshold that stops the sync when too many users would be deleted at once) preventing catastrophic mass deactivation if an OU is moved or deleted in Active Directory.
3. SCIM 2.0 Cloud Identity Provisioning
System for Cross-domain Identity Management (SCIM 2.0), defined by RFC 7643 (Core Schema) and RFC 7644 (Protocol), is the industry standard for automated, cloud-to-cloud identity provisioning.
Architecture: SCIM Client vs. SCIM Service Provider
In modern cloud architectures, enterprises utilize cloud Identity Providers (such as Microsoft Entra ID / Azure AD, Okta, PingFederate, or CyberArk) as their primary directory.
- The cloud IdP acts as the SCIM Client.
- Cisco Webex Control Hub acts as the SCIM Service Provider.
- Communication occurs cloud-to-cloud over outbound HTTPS (port 443), eliminating the need to deploy, patch, or maintain on-premises Windows servers or Directory Connector instances.
SCIM Endpoint & Authentication
- Base Endpoint URL:
https://webexapis.com/identity/scim/{orgId}/v2/- Users Endpoint:
https://webexapis.com/identity/scim/{orgId}/v2/Users - Groups Endpoint:
https://webexapis.com/identity/scim/{orgId}/v2/Groups
- Users Endpoint:
- Authentication: Secured with an OAuth 2.0 bearer token issued to a Webex full administrator. Microsoft's Entra ID tutorial obtains it by signing in as that administrator, and the token is valid for 365 days. The token is entered in the IdP's provisioning settings and sent in every request header:
Authorization: Bearer eyJhbGciOiJSUzI1NiIsIng1YyI6Wy...<token>...
Supported SCIM REST Operations
| HTTP Method | SCIM Endpoint | Action Executed in Webex Control Hub |
|---|---|---|
POST | /v2/Users | Provisions a new user, applies attribute mappings, and triggers automated license assignment. |
GET | /v2/Users?filter=userName eq "..." | Queries user existence by email / username prior to updates. |
PUT | /v2/Users/{id} | Replaces all user attributes with the complete updated JSON payload. |
PATCH | /v2/Users/{id} | Performs granular delta updates (e.g., updating a phone number or modifying group membership). |
PATCH (Deactivate) | /v2/Users/{id} | Disables user access instantly by sending {"Operations":[{"op":"replace","path":"active","value":false}]}. |
DELETE | /v2/Users/{id} | Permanently deprovisions the user object and reclaims assigned licenses. |
Real-Time Deprovisioning Advantage
Unlike on-premises Directory Connector, which relies on scheduled polling intervals (e.g. running every 1 or 2 hours), SCIM 2.0 delivers instant, event-driven deprovisioning. When an employee is deactivated in Entra ID or Okta, the IdP sends an immediate SCIM PATCH request setting active: false. Webex instantly terminates the user's active session tokens, revokes client access, and reclaims calling licenses.
4. Single Sign-On (SSO) with SAML 2.0
While Directory Connector and SCIM govern identity provisioning (creating and maintaining user records), Security Assertion Markup Language (SAML 2.0) governs identity authentication (verifying user passwords and multi-factor credentials).
SAML Federation Roles
- Service Provider (SP): Cisco Webex Control Hub (
idbroker.webex.com). - Identity Provider (IdP): Enterprise identity service (Microsoft Entra ID, AD FS, Okta, PingFederate).
Configuration Workflow & Metadata Exchange
+-------------------------------------------------------------------------------------+
| SAML METADATA EXCHANGE |
| |
| +-----------------------------+ +-----------------------------+ |
| | Cisco Webex Control Hub | | Enterprise Identity | |
| | Service Provider (SP) | | Provider (IdP) | |
| +--------------+--------------+ +--------------+--------------+ |
| | | |
| |------ 1. Export SP Metadata XML ----------->| |
| | (Entity ID, ACS URL, SP Signing Cert) | |
| | | |
| |<----- 2. Upload IdP Metadata XML -----------| |
| | (IdP Entity ID, SSO URL, Public Cert) | |
+-------------------|---------------------------------------------|-------------------+
- Export SP Metadata: The administrator downloads the SP metadata XML file from Control Hub. The file contains:
- SP Entity ID: Unique Webex identifier (e.g.
https://idbroker.webex.com/a4f1...) - Assertion Consumer Service (ACS) URL: The idbroker.webex.com endpoint that receives SAML assertions (copy it from the downloaded metadata rather than typing it)
- SP Signing Certificate: Public X.509 certificate used by Webex to sign
AuthnRequestmessages.
- SP Entity ID: Unique Webex identifier (e.g.
- Configure Enterprise IdP: The administrator imports the SP metadata into the IdP and configures the SAML claim rules. The IdP must map the user's primary enterprise email address to the SAML NameID attribute (
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddressorunspecified). - Import IdP Metadata into Control Hub: The administrator downloads the IdP metadata XML (containing the IdP Entity ID, SingleSignOnService redirect URL, and the IdP public X.509 signing certificate) and uploads it into Control Hub.
- Mandatory SSO Test: Before allowing the administrator to enable SSO organization-wide, Control Hub enforces an interactive single sign-on test. The administrator must successfully authenticate in a popup browser window. This prevents tenant lockout caused by mismatched claim rules or expired certificates.
SP-Initiated vs. IdP-Initiated Authentication Flows
- SP-Initiated Flow (Standard for Webex App):
- The user launches the Webex App or opens
webex.comand enters their email (user@example.com). - Webex identifies the claimed domain and generates a cryptographic SAML
AuthnRequest. - The user's client is redirected to the enterprise IdP SingleSignOnService URL.
- The user completes authentication at the IdP (entering credentials, completing Duo/FIDO2 MFA).
- The IdP generates a SAML Response containing a cryptographically signed assertion and posts it to the Webex ACS URL.
- Webex verifies the signature using the uploaded IdP certificate, extracts the NameID email, matches the user record, and issues OAuth session tokens.
- The user launches the Webex App or opens
- IdP-Initiated Flow:
- The user logs into their enterprise portal (e.g., Microsoft 365 MyApps or Okta Dashboard).
- The user clicks the Webex application icon.
- The IdP generates an unsolicited signed SAML assertion and sends an HTTP POST directly to the Webex ACS URL.
5. Role-Based Access Control (RBAC) in Control Hub
Control Hub enforces strict separation of duties through granular administrative roles, adhering to the principle of least privilege:
| Administrative Role | Functional Privileges | Key Restrictions |
|---|---|---|
| Full Administrator | Unrestricted access across all services, user lifecycle, security settings, billing, and organizational parameters. | Only role capable of managing other Full Admins and organization-wide security keys. |
| User and Device Administrator | Add, edit, and delete users; assign service licenses; provision and configure hardware devices and workspaces. | Cannot modify billing subscriptions, global SSO configurations, or view compliance archives. |
| Read-Only Administrator | Inspect all configurations, user lists, device health states, and operational reports. | Cannot modify any setting, add users, or reallocate licenses. |
| Compliance Officer | Manage message retention policies, configure Legal Holds, perform eDiscovery searches, and export compliance archives. | Cannot configure telephony dial plans, register devices, or manage user licenses. |
| Location Administrator | Scoped administrative authority restricted to specific physical locations (e.g., managing local branch auto-attendants, hunt groups, and local phone assignments). | Cannot view or modify configurations, dial plans, or devices in other locations. |
| Support Administrator | View analytics and troubleshooting data, such as call and meeting quality, to support users. | Cannot change users, devices, or settings. |
| Device Administrator | Add and manage devices and workspaces. | Cannot manage users or licenses. |
Full administrators can also build custom roles from individual permissions with the role builder, and Webex site administrator roles control individual meeting sites.
An enterprise is planning to automate user identity provisioning from Microsoft Entra ID to Cisco Webex Control Hub without deploying on-premises servers or maintaining inbound firewall pinholes. Which identity integration protocol and architectural configuration should the enterprise deploy?
Administrative XML (AXL) API push queries triggered by an on-premises CUCM Publisher node.
SCIM 2.0 cloud-to-cloud provisioning configured with a long-lived Bearer token generated in Control Hub.
Cisco Directory Connector installed on a perimeter DMZ Windows Server communicating over LDAP port 389.
SAML 2.0 assertion exchange configured with periodic batch imports using CSV files over SFTP.
A collaboration administrator prepares to deploy Cisco Directory Connector on an on-premises Windows Server to synchronize 8,000 corporate users from Active Directory to Webex Control Hub. Prior to executing the initial production synchronization, which operational mode must the administrator run to verify LDAP query accuracy and prevent accidental bulk user deletions?
SAML metadata export mode to validate Identity Provider certificate trust.
Kerberos single sign-on verification mode to authenticate local Domain Controller tickets.
Full production sync with the deletion threshold disabled to force all changes to commit immediately.
Dry-Run mode (simulation) to inspect proposed additions, updates, and deletions in a verification report.
An organization configures SAML 2.0 Single Sign-On (SSO) between Cisco Webex and Okta. During user login testing, users can successfully authenticate when starting from the Okta application portal, but encounter an authentication error when attempting to sign in directly from the Webex App desktop client. What is the root cause of this discrepancy?
The administrator omitted the SCIM 2.0 Bearer token in the SAML AuthnRequest HTTP payload.
The enterprise IdP does not support mutual TLS encryption over the SIP signaling port 5061 used by Webex.
SSO works only IdP-initiated; the Webex App starts SP-initiated SSO, which needs a correct Assertion Consumer Service configuration.
Webex App desktop clients cannot use SAML SSO at all and must authenticate exclusively with static basic credentials stored in Control Hub.
Sections you finish are checked off in the contents.