Target
This article applies to customers who meet the following conditions.
- Using the HENNGE One Pro or HENNGE One IdP Pro plan.
- Using Access Control and Cybozu with SSO integration.
Purpose
- Configure user provisioning between Access Control and Cybozu.
- By completing this configuration, you can synchronize user information from Access Control to Cybozu.
Notes
- The content of this article is based on the product specifications as of March 2025 and may change without notice.
- Global administrator privileges for Access Control are required to view actual screens or make configuration changes.
- For Cybozu limitations, please refer to the following page.
cybozu.com Help - Provisioning Limitations (external link) - Single sign-on integration with Cybozu is not a mandatory requirement. However, if SSO is not configured, you will need to set passwords for users created via user provisioning separately on the Cybozu side.
- Users in Cybozu are created without licenses assigned (no services selected for use).
- Users manually added to Cybozu while [Reflect provisioning] is enabled in Cybozu will not be subject to provisioning.
To include manually created users in provisioning, temporarily disable and then re-enable the provisioning settings in Cybozu. - Users who are deactivated in Cybozu cannot be reactivated via provisioning.
To reactivate users, please manually enable them in Cybozu. - If you change the value of the attribute mapped to Cybozu's Login Name from Access Control, a new user will be created in Cybozu during user synchronization.
The status of the user before the value was updated will follow the setting for [Handling of users deleted in Access Control].
For details, please refer to Step 6.
Procedure
Pre-configuration Checklist
- If you have not yet configured SSO for Cybozu in [Connected Services] of Access Control, please do so in advance.
Add Connected Service - Only users who are permitted access to the target Connected Service will be subject to provisioning.
Configure access permissions as needed.
Access Control Create / Edit New User
Access Control Create / Edit Access Policy Group - Beforehand, issue an API token in the provisioning settings of Cybozu.
cybozu.com Help - Enable Provisioning (external link) - The initial synchronization will overwrite Cybozu with the information from Access Control, regardless of any differences between Access Control and Cybozu. No difference detection will be performed.
Default Attribute Mapping
Please refer to the table below for the items that will be synchronized if attribute mapping is not configured.
Attributes other than Login Name cannot be changed in attribute mapping.
| Cybozu | Access Control | Description | |
| Login Name | username | Username | The value set for this item is used to uniquely identify users. |
| Email Address | |||
| Family Name | family_name | Family Name | Attribute mapping cannot be changed for this item. |
| Given Name | given_name | Given Name | Attribute mapping cannot be changed for this item. |
| Display Name | display_name | Display Name | Attribute mapping cannot be changed for this item. If the Display Name in Access Control is blank, the value of the attribute mapped to Cybozu's Login Name will be synchronized. |
| Email Address | Attribute mapping cannot be changed for this item. | ||
Procedure
1. Open the [Provisioning Settings] Screen
Open the Access Control Administration, and select [System] - [Provisioning Settings] from the left menu.
2. Open the Settings Screen
Click the [Settings] button for [Sync from Access Control].
If you already have services in use, click the [Add Service] button.
3. Select the Service
On the [Step 1: Select the service to synchronize users with] screen, select [Cybozu].
4. Configure HENNGE One Authentication
If HENNGE One authentication is already configured, proceed to Step 5.
On the [Step 2: Verify your account.] screen, click [Generate Authentication Key].
On the [Configure Authentication] screen, click [Add New Authentication] for HENNGE One.
Copy the [Client ID] and [Client secret], and enter them in the respective fields on the [HENNGE One Authentication] screen.
Click the [Verify] button.
5. Configure Cybozu Authentication
On the [Configure Authentication] screen, click [Add New Authentication] for SCIM.
If a connection already exists, click [Add New Connection].
Enter the [SCIM Endpoint] and [API Token] issued in Cybozu in advance, then click the [Verify] button.
* For details, please refer to Pre-configuration Checklist.
The [Configure Authentication] screen will appear again. Click SCIM to display the list, then click the pencil icon to the right of the created connection.
Change the connection name to any name that makes it easy to manage by service, then click [Settings].
Once authentication settings are complete, click [Next].
6. Configure Synchronization Targets
In the [Target Connected Service] field, select Cybozu from the list of HENNGE One Connected Services registered in advance.
Select the option for [Handling of users deleted in Access Control].
The available options are as follows:
・Delete: Remove the target user from Cybozu.
・Disable: Deactivate the target user in Cybozu. The user will not be deleted.
・Keep: Leave the target user as is in Cybozu.
7. Map Integration Key
On the [Integration Key Mapping] screen, specify the Access Control attribute to synchronize with Cybozu's [Login Name].
Select one attribute to map from either [Standard Attributes] or [Custom User Attributes].
Attributes other than Login Name will use the default attribute mapping.
Default Attribute Mapping
8. Configure Users to Exclude from Synchronization
Select users you want to exclude from synchronization.
Check the box for any users you want to exclude from synchronization.
If you want to synchronize all users, do not select anything and click [Finish].
Once configuration is complete, "Cybozu" will appear on the [Provisioning Settings] screen.
Reference
・Run and Check User Provisioning Results
・Check / Delete User Provisioning Settings