Target
Customers who meet the following conditions are eligible:
- Using HENNGE One Pro or HENNGE One IdP Pro plan.
- Using HENNGE Access Control and Cybozu for SSO integration.
Purpose
Configure user provisioning for HENNGE Access Control and Cybozu.
By performing this setup, you can synchronize user information from HENNGE Access Control to Cybozu.
Notes
- This article is based on product specifications as of March 2026 and is subject to change without notice.
- Actual screen verification and setting changes require administrator privileges in HENNGE Access Control.
- For Cybozu's limitations, please refer to the following page:
Kintine Provisioning (External Page) - Implementing single sign-on integration with Kintone is not mandatory, but if not done, passwords for users created through the user provisioning feature will need to be set separately in Kintone.
- Users in Kintone are created without licenses (no selected services).
- Users manually added to Kintone while [Provisioning Reflection] is enabled will not be subject to provisioning.
To include manually created users in provisioning, disable and re-enable provisioning settings in Kintone. - It is not possible to activate inactive users in Kintone through provisioning.
To activate users, manually enable them in Kintone. - If the value of the attribute mapped to Kintone's Login Name is changed in HENNGE Access Control, a new user will be created in Kintone during user synchronization.
The handling of users before the value update will follow the settings for [Handling of Users Deleted in HENNGE Access Control].
For more details, refer to Step 6.
Detailed Explanation / Steps
Preparation
- If Cybozu's single sign-on settings are not configured in HENNGE Access Control's [Connected Services], please set it up in advance.
Add Connected Services - Users who have been granted access to the target service provider will be subject to provisioning.
Adjust access permissions as needed.
Edit User Information
Edit Access Policy Groups - Issue an API token in Cybozu's provisioning settings in advance.
cybozu.com Help Enable Provisioning (External Link) - For the initial synchronization, regardless of the presence of user differences between HENNGE Access Control and Cybozu, the information on the HENNGE Access Control side will overwrite. No difference detection will be performed.
Default Attribute Mapping
If you do not configure attribute mapping, please refer to the table below for the items to be synchronized.
Except for the Login Name, attributes cannot be changed through attribute mapping.
| Cybozu | HENNGE Access Control | Description | |
| login name | username | user name | Based on the value set in this field, users are uniquely identified. |
| Email Address | |||
| Family name | family_name | Family name | Cannot change attribute mapping. |
| Given name | given_name | Given name | Cannot change attribute mapping. |
| Display Name | display_name | Display Name | Cannot change attribute mapping. If the Display Name in HENNGE Access Control is blank, the value of the mapped attribute in Cybozu's login name will be synchronized. |
| Email Address | Cannot change attribute mapping. | ||
Procedure
1. Open the Provisioning Settings screen
Open the HENNGE Access Control Administration screen, and select [System] - [Provisioning Settings] from the left menu.
2. Open the Settings screen
Click the [+Add Service] button in SYNC DESTINATION
3. Select the Service
Select [Cybozu].
4. Configure HENNGE One Authentication
If you already have HENNGE One authentication settings, proceed to step 5.
Under the [Verify HENNGE Access Control credentials] screen, click [Generate key].
On the [Authentication settings] screen, click [HENNGE Access Control] and [Next].
Copy the [Client ID] and [Client Secret], and enter them to [Client ID] and [Client private key] in the [Authenticate HENNGE Access Control] screen.
Click the [Authenticate] button.
5. Configure Kintone(Cybozu) Authentication
On the [Authentication settings] screen, click [Kintone] and [Next].
If a connection already exists, click on [Add New Connection] and [Next].
Enter the [SCIM endpoint] and [API token] issued in advance by Kintone(Cybozu), and click the [Authenticate] button.
※ For more details, please refer to Preparation Items.
Once again, the [Authentication settings] screen will appear. Click on [SCIM] to display the list, then click on the pencil icon next to the created connection.
Change the Connection name to any name(Example: Kintone Authentication) that is easy to manage for each service, then click [Configure].
After configuring the verification, click [Next].
6. Configuration of Synchronization Targets
In the [Service providers to be synchronized] field, select [Kintone] from the list of service providers registered in HENNGE One in advance.
Select [Handling of users deleted by HENNGE Access Control].
The available options are as follows:
・Delete: Delete the target user from Kintone.
・Disable: Disable the target user in Kintone. The user will not be deleted.
・Just as: Keep the target user in Kintone as is.
7. Mapping of Synchronization Keys
In the [Linking key mapping] screen, specify the HENNGE Access Control attribute that synchronizes with Kintone's [Login Name].
Select one attribute to map from either [HENNGE One standard attributes] or [HENNGE One custom attributes].
Attributes other than the login name will have default attribute mappings applied.
Default Attribute Mappings
8. Configuration of Users Excluded from Synchronization
Select the users you want to exclude from synchronization.
If there are users you want to exclude from synchronization, please check the box.
If you want to synchronize all users, click [Complete] without selecting anything.
Once the configuration is complete, "Cybozu" will be displayed on the [Provisioning Settings] screen.
Reference
・Executing and Verifying User Provisioning
・Confirming/Deleting User Provisioning Settings