Microsoft Entra
Directory → Authentication → Application Access
ENTERPRISE IDENTITY LIFECYCLE
Microsoft Entra manages authentication, directory identity and application access. CardIQ extends employee identity governance into external company representation. CardIQ does not replace Microsoft Entra ID.
Different identity layers, one employee lifecycle. Enterprise IAM controls who can access corporate systems. CardIQ controls how employees represent the organization externally.
Directory → Authentication → Application Access
External Identity → Public Representation → Communication Trust → CardIQ-managed Identity Asset Offboarding
Controlled Microsoft Entra Lifecycle Reconciliation connects selected Entra directory state to company-governed CardIQ employee identity decisions.
Controlled Microsoft Entra Lifecycle Reconciliation
Depending on policy, CardIQ monitors the lifecycle difference or deactivates the corresponding CardIQ employee identity.
CardIQ-managed external identity reflects the employee lifecycle state according to company policy. This can include CardIQ employee status, the public employee profile, the CardIQ digital business card and verification status.
This comparison describes how CardIQ complements Microsoft Entra; it does not suggest a deficiency in either identity layer.
| Identity function | Microsoft Entra | CardIQ |
|---|---|---|
| Workforce directory | Primary platform | Consumes selected lifecycle data |
| Authentication | Primary platform | Not CardIQ's primary role |
| SSO | Primary platform | Entra-based enterprise sign-in supported where configured |
| Application access | Primary platform | Not provided by CardIQ |
| Employee public profile | Not CardIQ's comparison focus | Primary capability |
| Digital business cards | Not CardIQ's comparison focus | Yes |
| Company-controlled email signature | Different product scope | Yes |
| Communication verification | Different product scope | Yes |
| Trusted company domains | Different identity purpose | Yes |
| External employee identity offboarding | Different product scope | Yes, for CardIQ-managed identity assets |
This is a current CardIQ Enterprise integration. A company-bound Microsoft Entra OIDC configuration provides mapped enterprise sign-in where configured and supports a deliberately controlled directory lifecycle workflow.
Administrators select allowlisted groups and receive a read-only directory preview before applying controlled employee synchronization. Manual dry-run and review controls keep proposed changes visible.
Scheduled lifecycle reconciliation can begin in monitor-only mode. Controlled auto-apply is optional, policy-bound and can be stopped with Switch to Monitor Only kill-switch behavior.
Large-change protection, circuit breaker safeguards and reconciliation health/status reduce unsafe automation. Review precedes destructive actions. Incomplete Microsoft Graph responses are not treated as deletion evidence.
SCIM provisioning and CardIQ’s current Entra reconciliation architecture are different lifecycle approaches. The appropriate model depends on product support, configuration and organizational requirements.
| Area | SCIM Provisioning | CardIQ Entra Reconciliation |
|---|---|---|
| Model | Identity provider pushes provisioning changes to an application | CardIQ reads selected Entra lifecycle state and reconciles it with CardIQ |
| Current CardIQ support | Not currently implemented | Yes |
| Scope | Depends on SCIM implementation and provisioning configuration | Explicitly selected CardIQ/Entra scope |
| Review before applying changes | Depends on product implementation | Preview, dry-run and monitor-only controls available |
| Large-change safeguards | Depends on implementation | Large-change protection and circuit-breaker controls |
| Lifecycle automation | Depends on configuration | Optional and controlled by company policy |
For organizations that want visibility before lifecycle changes are applied, CardIQ provides directory preview, monitor-only operation, dry-run review, explicit scope, and company-controlled lifecycle policies.
Organizations can move from observation to policy-controlled action at their own pace.
Start with lifecycle reconciliation without automated changes.
Preview directory and lifecycle differences before applying them.
Large-change protection and circuit breakers help stop unexpected mass actions.
Enable controlled deactivation only when the organization is ready.
CardIQ acts only on identity records and assets within CardIQ according to the company-controlled policy.
The employee is active in Microsoft Entra and the corresponding CardIQ employee identity is active.
The employee becomes disabled in Entra. CardIQ detects that lifecycle state during a complete, healthy reconciliation.
CardIQ either monitors and reports only or, when explicitly configured, deactivates the CardIQ employee record.
CardIQ-managed external identity assets stop representing that employee as active. CardIQ does not claim to revoke assets outside its scope.
The integration is designed around selected scope, least privilege and company control.
Selected groups and an allowlisted sync scope limit which directory identities CardIQ previews and reconciles.
CardIQ does not use public identity surfaces to reverse-lookup directory data and does not impersonate employee identities.
Monitoring is the safe starting point. Company administrators explicitly control scope, review and whether eligible reconciliations may auto-apply.
See how CardIQ previews selected Microsoft Entra users, reviews lifecycle changes, applies controlled synchronization, and protects CardIQ-managed external identity during employee offboarding.
No. Microsoft Entra is the workforce directory, authentication and application-access layer; CardIQ controls CardIQ-managed external corporate identity.
Yes. CardIQ currently supports company-bound Entra OIDC, selected-group directory preview, controlled employee synchronization and controlled lifecycle reconciliation.
Not currently. CardIQ also does not currently implement direct LDAP or direct LDAPS.
Yes, when explicitly configured under CardIQ's controlled reconciliation policy. Monitor-only operation remains available.
Missing or incomplete response data is not treated as deletion evidence. Health controls and circuit breakers help stop that response from driving an unintended deactivation.
Microsoft, Microsoft Entra, Okta, and related product names and marks are trademarks of their respective owners. CardIQ is not affiliated with, sponsored by, or endorsed by these companies unless expressly stated. This corporate non-affiliation statement does not alter the current technical compatibility described above.
Explore the CardIQ platform or review the workflow from verification through identity deactivation.
See how CardIQ works View pricing