Skip to content

Automated Directory Synchronization (SCIM & IdP)

1. Executive Summary & Value Proposition

In modern enterprises, employee turnover, role changes, and corporate reorganizations occur constantly. Managing user lists manually in a security awareness platform leads to administrative exhaustion, outdated records, and security gaps where new hires remain untrained. SimuPhish’s Automated Directory Synchronization (Main Navigation > Integrations or /connect-sync) provides seamless, real-time user lifecycle integration with enterprise identity providers (IdPs), including Microsoft Entra ID (Azure AD), Google Workspace, and On-Premise Active Directory/LDAP via SCIM 2.0. Employee rosters, departmental hierarchies, and managerial relationships synchronize automatically, ensuring training queues always mirror your active workforce.


2. The Threat Landscape & The Real-World Problem Solved

  • The New-Hire Blind Spot: New employees are 3x more likely to fall for phishing scams during their first 90 days. Without automated directory sync, new hires often wait weeks before receiving security awareness training.
  • Administrative Overhead: IT and HR administrators waste 10–15 hours every month manually exporting, formatting, and uploading employee CSV spreadsheets.
  • Orphaned User Accounts & Inaccurate Metrics: Departed employees left on platform rosters distort simulation failure rates and compromise compliance audit records.

3. How It Works (The User Journey)

graph LR
    A[Enterprise IdP: Microsoft Entra ID / Google / LDAP] -->|SCIM 2.0 / REST Directory API| B[SimuPhish Directory Sync Engine]
    B --> C1[Auto-Provision New Hires]
    B --> C2[Update Department & Manager Hierarchy]
    B --> C3[Deprovision Departing Staff]
    B --> C4[Filter Out Service Accounts & Mail Distribution Lists]
    C1 --> D[Instant Security Onboarding Campaign]

The Administrator Experience

  1. Navigating to Directory Integrations: Go to Main Navigation > Integrations (/connect-sync).
  2. Select Identity Provider:
  3. Microsoft Entra ID (Azure AD) / Microsoft 365: One-click OAuth authorization connecting Microsoft Graph API.
  4. Google Workspace: Direct integration synchronizing Google organizational units (OUs) and user metadata.
  5. SCIM 2.0 / Active Directory / LDAP: Standardized provisioning endpoint for enterprise Okta, Ping Identity, or on-premise LDAP servers.
  6. Configure Sync Rules & Filters:
  7. Target Group Selection: Choose whether to synchronize the entire corporate directory or specific security groups.
  8. Cadence Scheduling: Set automated background sync intervals (Daily, Every 3 Days, or Weekly).
  9. Exclude Distribution Lists: Automatically detect and ignore shared mailboxes and distribution lists (e.g., all-staff@company.com, billing@company.com).
  10. Service Account Wildcards: Add exclusion rules (e.g., *service*, *noreply*, support@*) to prevent non-human accounts from receiving simulations.
  11. Automated Deprovisioning: When an employee is disabled or deleted in Entra ID or Google Workspace, SimuPhish automatically suspends their simulation queue and archives their training history.
  12. Instant On-Demand Synchronization ("Sync Now"): Trigger an immediate delta synchronization with a single click to import newly hired cohorts instantly.

4. Key Business Benefits & Measurable ROI

  • Zero Manual User Administration: Save dozens of IT hours monthly by completely automating user provisioning and deprovisioning.
  • Instant Day-One Protection: Ensure every newly hired employee is automatically enrolled into mandatory security training on their first day of employment.
  • Flawless Compliance Auditing: Guarantee that audit reports reflect only current, active personnel without orphaned accounts.
  • Avoid Operational Mishaps: Intelligent filtering prevents simulated attacks from accidentally landing in customer-facing shared inboxes.

5. Real-World Attack Scenario & Case Study

Scenario: The Day-Three Executive Assistant Phish

  • The Situation: A new executive assistant joined a healthcare system. Attackers identified her via LinkedIn and sent an urgent spear-phishing email impersonating the CEO requesting vendor gift cards.
  • SimuPhish Action: Because Automated Directory Sync ran nightly via Microsoft Entra ID, the assistant was provisioned on Day 1 and immediately enrolled in the "New Hire Threat Onboarding" mission.
  • The Outcome: Having completed an interactive drill on executive impersonation the previous afternoon, the assistant recognized the attacker's spoofed sender address, refused the request, and clicked the Phish Detect button—turning a potential breach into a verified threat capture.