> For the complete documentation index, see [llms.txt](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/integrations.md).

# Integrations

Overview of supported provisioning integrations in Veza, with capabilities and supported actions for target applications and sources of identity.

### Overview

This page covers the integrations that power Lifecycle Management workflows and can act as identity sources for LCM policies, and target applications that can be provisioned or deprovisioned.

Enabling provisioning on an integration also makes it available to other Veza products that use write-back capabilities, including Access Intelligence (Disable Accounts) and Access Requests. The integration tables below represent the validated, production-ready set for Lifecycle Management specifically.

Veza supports four implementation pathways:

1. **Native Integrations**: Direct, API-based provisioning, with out-of-the-box support for 25+ validated target applications (listed below).
2. **SCIM 2.0 Protocol**: Standards-based provisioning for any enterprise application that exposes a SCIM 2.0 interface.
3. **OAA Write Framework**: Veza's Open Authorization API (OAA) extends write-back to applications that Veza does not integrate with natively. This pathway is typically used for homegrown and custom applications.
4. **Direct REST, XML, and SQL Actions**: For an application that neither integrates natively nor exposes a SCIM interface, a dedicated **Send REST Payload**, **Send XML Payload**, or **Send SQL Command** action calls the target system directly. Use these actions to notify a platform when a joiner, mover, or leaver (JML) workflow completes, or to start work in that platform as a workflow step.

Combined, these approaches cover the enterprise application landscape reachable via Lifecycle Management target applications and actions: natively integrated systems, any SCIM-compliant application, homegrown and custom applications modeled through OAA, and any remaining system that exposes a reachable REST, XML or SOAP, or SQL interface.

The validated integrations listed below represent tested, production-ready configurations. For additional integration support, contact your Customer Success Manager.

### Supported Integrations

#### Identity Sources

Identity sources are authoritative systems that provide information about user identities. While Veza does not require write permissions to the identity source of truth, some of these integrations are also supported as provisioning targets. Integrations can also allow write-back of a user's newly created email address to the user's record in the source of identity as part of the initial provisioning workflow.

Veza supports leading HR systems, IDPs and directory services, ITSM platforms, payroll systems, custom applications, and flat files:

| Identity Source                                                                                       | Supported Entity Types      | Notes                     |
| ----------------------------------------------------------------------------------------------------- | --------------------------- | ------------------------- |
| [Active Directory](/4yItIzMvkpAvMVFAamTf/integrations/integrations/active-directory.md)               | ActiveDirectoryUser         |                           |
| [ADP Workforce Now](/4yItIzMvkpAvMVFAamTf/integrations/integrations/adp-workforce-now.md)             | CustomHRISEmployee          |                           |
| [Beeline](/4yItIzMvkpAvMVFAamTf/integrations/integrations/beeline.md)                                 | CustomHRISEmployee          |                           |
| [Coupa CCW](/4yItIzMvkpAvMVFAamTf/integrations/integrations/coupa-ccw.md)                             | CustomHRISEmployee          |                           |
| [Custom IDP](/4yItIzMvkpAvMVFAamTf/developers/api/oaa/templates/custom-identity-provider-template.md) | CustomIDPUser               |                           |
| [Custom HRIS (OAA)](/4yItIzMvkpAvMVFAamTf/developers/api/oaa/templates/hris-template.md)              | CustomHRISEmployee          |                           |
| [Database HRIS](/4yItIzMvkpAvMVFAamTf/integrations/integrations/database-hris.md)                     | CustomHRISEmployee          |                           |
| [HiBob](/4yItIzMvkpAvMVFAamTf/integrations/integrations/hibob.md)                                     | CustomHRISEmployee          | Supports email write-back |
| [LDAP](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ldap/provisioning.md)                          | LDAP user                   |                           |
| [Ivanti Neurons HR](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ivanti_nurons_hr.md)              | CustomHRISEmployee          |                           |
| [Azure AD](/4yItIzMvkpAvMVFAamTf/integrations/integrations/azure.md)                                  | AzureADUser                 |                           |
| [Google Workspace](/4yItIzMvkpAvMVFAamTf/integrations/integrations/google.md)                         | GoogleWorkspaceUser         |                           |
| [Okta](/4yItIzMvkpAvMVFAamTf/integrations/integrations/okta.md)                                       | OktaUser                    |                           |
| [Oracle HCM](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-hcm.md)                           | OAA.Oracle HCM.HRISEmployee | Supports email write-back |
| [ServiceNow](/4yItIzMvkpAvMVFAamTf/integrations/integrations/servicenow/provisioning.md)              | ServiceNowUser              |                           |
| [UKGPro](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ukgpro.md)                                   | CustomHRISEmployee          |                           |
| [Workday](/4yItIzMvkpAvMVFAamTf/integrations/integrations/workday.md)                                 | WorkdayWorker               | Supports email write-back |

#### Target Application Support

The following integrations are validated as provisioning targets for Lifecycle Management workflows. Enabling provisioning on an integration enables actions (create, sync, deprovision, manage relationships) that can be triggered from LCM policies and from other Veza products.

**Validated Integrations**

The following table lists the out-of-the-box, Veza-validated target application integrations.

| Target Application                                                                                                    | Manage Relationships | Sync Identities | Deprovision Identity | Additional Actions                                                | Supported Entitlement Types                                                                                   | Notes                                                                                                                                                                                                                         |
| --------------------------------------------------------------------------------------------------------------------- | :------------------: | :-------------: | :------------------: | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [**Active Directory**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/active-directory/provisioning.md)              |           ✅          |        ✅        |           ✅          | Reset Password, Create Entitlement, Delete Identity               | ActiveDirectoryGroup                                                                                          | -                                                                                                                                                                                                                             |
| [**Atlassian Cloud**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/atlassian/provisioning.md)                      |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | AtlassianCloudAdminGroup                                                                                      | -                                                                                                                                                                                                                             |
| [**AWS SSO**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/aws/provisioning.md)                                    |           ✅          |        ✅        |           ✅          | Create Entitlement                                                | AwsSsoGroup                                                                                                   | -                                                                                                                                                                                                                             |
| [**Azure**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/azure/provisioning.md)                                    |           ✅          |        ✅        |           ✅          | Reset Password, Create Email, Create Entitlement, Delete Identity | AzureADGroup, AzureADRole, ExchangeOnlineDistributionGroup, AzureADLicense                                    | Email management includes mailbox configuration (size limits, quotas, auditing) and client access settings (OWA, ActiveSync, MAPI, POP, IMAP)                                                                                 |
| [**Custom Application (OAA Template)**](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/integrations/oaa-scim.md) |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | ApplicationGroup, ApplicationRole                                                                             | -                                                                                                                                                                                                                             |
| [**Database Application**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/database-application.md)                   |           ✅          |        ✅        |           ❌          | Delete Identity                                                   | `OAA.<application type>.Group`, `OAA.<application type>.Role`                                                 | Requires feature enablement. Relationship management depends on configuration: group entitlements require the add and remove group stored procedures, and role entitlements require the add and remove role stored procedures |
| [**Exchange Server**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/exchange-server/provisioning.md)                |           ❌          |        ❌        |           ❌          | Create Email                                                      | -                                                                                                             | -                                                                                                                                                                                                                             |
| [**GitHub**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/github/provisioning.md)                                  |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | GithubOrganization, GithubTeam                                                                                | -                                                                                                                                                                                                                             |
| [**LDAP**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ldap/provisioning.md)                                      |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | LDAP group                                                                                                    | Includes Red Hat Identity Manager and FreeIPA                                                                                                                                                                                 |
| [**Google Workspace (Google Cloud)**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/google/provisioning.md)         |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | GoogleWorkspaceGroup                                                                                          | -                                                                                                                                                                                                                             |
| [**MySQL**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/mysql/provisioning.md)                                    |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | MySQLRoleInstance                                                                                             | -                                                                                                                                                                                                                             |
| [**Okta**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/okta/provisioning.md)                                      |           ✅          |        ✅        |           ✅          | Reset Password, Create Entitlement, Delete Identity               | OktaGroup                                                                                                     | Supports two deprovision types: SUSPENDED (temporary) and DISABLED (permanent deactivation)                                                                                                                                   |
| [**Oracle Database**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-database/provisioning.md)                |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | OracleDBRole                                                                                                  | -                                                                                                                                                                                                                             |
| [**Oracle Fusion Cloud**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-fusion-cloud/provisioning.md)        |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | OracleRole                                                                                                    | -                                                                                                                                                                                                                             |
| [**Oracle HCM**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-hcm/provisioning.md)                          |           ❌          |        ✅        |           ❌          | Write Back Email                                                  | -                                                                                                             | -                                                                                                                                                                                                                             |
| [**PagerDuty**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/pagerduty/provisioning.md)                            |           ✅          |        ✅        |           ❌          | Delete Identity                                                   | PagerDutyTeam                                                                                                 | Platform does not support user deactivation; use Delete Identity instead                                                                                                                                                      |
| [**PostgreSQL**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/postgresql/provisioning.md)                          |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | PostgreSQLGroup                                                                                               | -                                                                                                                                                                                                                             |
| [**Salesforce**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/salesforce/provisioning.md)                          |           ✅          |        ✅        |           ✅          | -                                                                 | SalesforceGroup, SalesforcePermissionSet, SalesforcePermissionSetGroup, SalesforceProfile, SalesforceUserRole | -                                                                                                                                                                                                                             |
| **SAP ECC**                                                                                                           |           ✅          |        ✅        |           ✅          | -                                                                 | SapEccRole                                                                                                    | Manage Relationships supports role assignment only (revocation is not supported)                                                                                                                                              |
| [**SCIM**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/scim/provisioning.md)                                      |           ✅          |        ✅        |           ✅          | Delete Identity                                                   | SCIMGroup                                                                                                     | Supports token authentication and OAuth2 client credentials                                                                                                                                                                   |
| [**ServiceNow**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/servicenow/provisioning.md)                          |           ✅          |        ✅        |           ✅          | Update ServiceNow Table                                           | ServiceNowGroup, ServiceNowRole                                                                               | Manage Relationships covers directly granted roles only; roles inherited through group membership are not managed                                                                                                             |
| [**Snowflake**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/snowflake/provisioning.md)                            |           ✅          |        ✅        |           ✅          | -                                                                 | SnowflakeRole                                                                                                 | -                                                                                                                                                                                                                             |
| [**Splunk Enterprise**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/splunk-enterprise/provisioning.md)            |           ✅          |        ✅        |           ❌          | Delete Identity                                                   | SplunkEnterpriseRole                                                                                          | Platform does not support user deactivation; use Delete Identity instead                                                                                                                                                      |
| [**Workday**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/workday/provisioning.md)                                |           ✅          |        ✅        |           ❌          | Write Back Email                                                  | WorkdaySecurityGroup                                                                                          | -                                                                                                                                                                                                                             |
| **Veza**                                                                                                              |           ✅          |        ✅        |           ✅          | -                                                                 | VezaRoleBinding, VezaAccessProfile, VezaGroup                                                                 | -                                                                                                                                                                                                                             |

**Other Supported Integrations**

For any Veza-supported application not listed above, contact your Customer Success Manager for more details on how to enable the specific Veza integration for use with provisioning as a target application for provisioning and de-provisioning.

**Direct REST, XML, and SQL Actions**

For an application that does not integrate with Veza natively and does not expose a SCIM interface, a workflow can call the target system directly:

* [**Send REST Payload**](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/policies-workflows/actions/send-rest-request.md) makes an HTTP request to an external API, webhook, or REST-based service.
* [**Send XML Payload**](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/policies-workflows/actions/send-xml-payload.md) sends an XML or SOAP-over-HTTP body to a legacy endpoint.
* [**Send SQL Command**](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/policies-workflows/actions/send-sql-command.md) runs a SQL statement against MySQL, Microsoft SQL Server, Oracle, PostgreSQL, or SAP IQ (Sybase IQ).

Use these actions to notify a platform when a joiner, mover, or leaver workflow completes, to start work in that platform, or to coordinate provisioning across multiple downstream applications. Because each action targets an endpoint you supply, the three actions together extend provisioning support to systems that have no native or SCIM connector.

### Configuring Integrations for Provisioning

#### Insight Points for provisioning

An Insight Point is required to enable provisioning operations and identity discovery for systems that Veza cannot access directly, such as an on-premises application server behind a firewall. The Insight Point is a lightweight connector that runs in your environment, enabling secure gathering and processing of authorization metadata for provisioning tasks.

A Veza Insight Point is typically deployed as a Docker container or VM OVA, running within your network for metadata discovery and provisioning job execution. This ensures secure communication between your environment and Veza.

For deployment instructions, refer to the [Insight Point Documentation](/4yItIzMvkpAvMVFAamTf/integrations/connectivity.md).

#### Scheduled and Manual Extractions

You can configure extraction intervals for your integrations to ensure data is regularly updated for provisioning workflows.

1. Go to Veza **Administration** > **System Settings**
2. In the **Integrations** section, set the global **Extraction Interval**
3. To override the global setting for specific integrations, use the *Active Overrides* section

Available extraction intervals are:

* Auto (each integration's default, which is 1 hour for most of them)
* 1 Hour
* 6 Hours
* 12 Hours
* 1 Day
* 2 Days
* 3 Days
* 7 Days
* 30 Days

One hour is the shortest extraction interval for most integrations. A 15-minute option appears in the **Discovery Interval** control, which is a separate setting and does not apply to extraction. See [Extraction and Discovery Intervals](/4yItIzMvkpAvMVFAamTf/integrations/configuration/extraction.md).

To manually trigger an extraction:

1. Go to **Integrations** > **All Data Sources**
2. Search for the desired data source
3. Select **Actions** > **Start Extraction**

**Note**: Custom application payloads are extracted after the payload is pushed to Veza using the Open Authorization API.

#### Enabling provisioning

To enable provisioning for a specific integration:

1. Open the **Integrations** page (in the Featured section of the navigation sidebar), or **Lifecycle Management** > **Integrations** (in the Products section).
2. Search for the integration you want to enable and open its settings.
3. Check the **Enable usage for Provisioning** checkbox, then click **Save Configuration**.

![The Edit Integration panel showing the Enable usage for Provisioning checkbox](https://1967633068-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZDkWMxox3pekd0NsZJ%2Fuploads%2Fgit-blob-4602ab239918fa66cf85a42dfffdab3dfae0310d%2Fenable-provisioning.png?alt=media)

After saving, the integration shows **Enabled** in the **Lifecycle Management** column on the Integrations overview.

![The Integrations overview showing Enabled in the Lifecycle Management column for configured integrations](https://1967633068-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZDkWMxox3pekd0NsZJ%2Fuploads%2Fgit-blob-2b7c2bf18b53578f548efccb8544b65f89ad4eae%2Flcm-overview-enabled.png?alt=media)

#### Checking provisioning data sources

To verify the health of the provisioning data source:

1. Open **Lifecycle Management** > **Integrations** (in the Products section of the navigation sidebar), or the main **Integrations** page (in the Featured section)
2. Search for the integration and click the name to view details
3. In the **Properties** sidebar on the right (not the **Properties** tab), click the magnifying glass icon next to the **Provisioning Support** value

## Best practices for identity sources

### API rate limits

Many identity source systems have API rate limits that can affect extraction timing. Avoid forcing repeated extractions within short time windows (typically 5 minutes) to prevent API errors that delay workflow execution.

### Custom field management

For systems using custom or user-defined fields (UDFs), maintain clear documentation of:

* Field purpose and mapping
* Expected data formats and validation rules
* Which fields are used in workflow trigger conditions

This documentation ensures consistency when fields are added or modified.

### Data retention policies

Understand the data retention policies of your identity sources, particularly for terminated employees or contractors. Some systems retain terminated records for limited periods (e.g., 90 days), which affects leaver workflow design. Plan workflow timing to ensure LCM can process records before they're purged from the source system.

### Critical field changes

Changes to core identity fields can break LCM workflows. Coordinate with system administrators before modifying:

* Unique identifiers (employee ID, username)
* Employment status fields
* Date fields (hire date, termination date)
* Location or department identifiers
* Any fields used in workflow trigger conditions

Communicate planned changes in advance and test in sandbox environments before applying to production identity sources.

### Additional Resources

For more information:

* Refer to individual integration documentation for detailed provisioning capabilities
* Consult the Veza documentation for troubleshooting and best practices
* Contact Veza support for assistance with enabling or configuring provisioning for your integrations


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veza.com/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/integrations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
