Provisioning Users with JIT
You can provision user access to Digital Risk Protection (Threat Command) with SAML Just in Time (JIT) from your single sign-on (SSO) provider. The service is available for Azure AD and Okta SSO.
When using JIT to provision users, the following apply to those users:
- Logging in to DRP is done from the SSO application, not through the DRP login.
- The user does not have a DRP password.
- Deleting a user from the SSO application does not delete them from DRP.
- A user deleted from the SSO application cannot Log in to DRP (as they have no password). You can manually delete that user from DRP.
- Users are assigned the same time zone as the account.
- To change the time zone or make other changes to user settings, go to Administration > Digital Risk Protection > DRP Users page.
- Users have a notation in their user card that their user was provisioned by SAML JIT.
For more information on configuring SSO and user provisioning, see these sections: