Your employees changes departments. Did your IT systems notice?

Your employees changes departments. Did your IT systems notice?

An employee joins your Marketing team. HR adds their details to the organization's user directory. The IT admin, in turn, creates their Zoho One account, assigns the required applications, adds them to groups and provides access based on the organization's hierarchy.
A few months later, the same employee moves from Marketing to Sales. Their departments change, and so does their access roles and assigned applications.
Now someone has to remember what needs to change and which systems to update.
When the same employee leaves the organization, someone should disable their accounts, revoke their access where necessary, and update information across multiple systems.
If your IT or admin team has to maintain the same employee information in more than one place, you already know where this can become complicated.

One employee, multiple admin tasks

Most organizations already have a system that acts as a source of employee information, such as a cloud directory, an identity provider, or an on-premises directory solution.
At the same time, employees use several business applications - including those you have deployed through Zoho One.
When an employee changes roles or leaves the company, several systems might need to be updated.
As your organization grows, so does the number of users, groups, applications, and the changes administrators have to keep track of.
Connecting your user directory with Zoho One can simplify this user-management process.

What if your existing directory could work with Zoho One?

If you're already using another directory service, you don't have to replace it with Zoho One. You can integrate your existing directory with Zoho One as a Directory Store, and delegate users and groups to be managed from Zoho One. This allows your existing directory and Zoho One to work together instead of treating them as two completely separate environments.
This is particularly useful when your organization already has an established identity-management process and wants to bring Zoho One into that environment.

Learn more about Directory Stores


How exactly does Directory Stores work?

Setting up a Directory Store involves configuring how user information is brought into Zoho One. The exact steps can vary depending on the directory service you're integrating, but the process generally involves the following.

Step 1: Connect your directory service

The first step is to integrate the directory service with Zoho One by configuring provisioning.
Once integrated, you can initiate a synchronization as and when required or schedule it to happen automatically at regular intervals.

Step 2: Tell Zoho One where each piece of information belongs

Your directory might store employee data using a set of fields different from that of Zoho One.
For example, your directory may store an employee's email address in the "Email" field, whereas Zoho One uses the "Primary email" field.
Field Mapping tells how the data received from your directory should correspond to the relevant information in Zoho One.
You don't just move user data from your directory to Zoho One, you define how the two systems understand the data.


Step 3: Define how users access their accounts

With Directory Stores, you can configure how users receive their one-time password to set up their account.
This is one of those configuration details that can easily be overlooked when you're thinking only about user synchronization.
But user onboarding isn't just about getting someone's name and email address into a system. The user also needs a way to access the environment securely.

Step 4: Decide what happens when a user's status changes

What happens when an employee changes departments or leaves the organization?
Directory stores enables administrators to configure how user changes in the directory should reflect in Zoho One.
This matters because user lifecycle management isn't only about creating accounts.
Joining, changing roles, and leaving are all part of the same employee lifecycle.


Step 5: Choose who gets synchronized

You don't necessarily have to synchronize every user in your directory.
Directory Stores lets you set up a criteria that users should meet in order to be synchronized with Zoho One. You can also schedule the time and frequency of the synchronization process based on your organization's requirements.
This gives flexibility for administrators, especially for larger organizations with multiple systems involved.

What about groups?

Many organizations manage access and administrations around groups based on departments, geographical locations, designations, and others. In such cases, keeping group information aligned between systems is an important part of the administration process.
Directory Stores also enables group sync, where groups from supported third-party applications can be imported and synchronized with Zoho One. Check out the app-specific directory store guides to know if Zoho One supports group sync for the user directory you use.

Learn more about Group Sync

Think about the employee lifecycle, not just the login

Instead of looking at Directory Stores setup as a one-time process, think about what happens to an employee throughout their time in your organization.
When a new employee joins, their information is added to the organization's directory. With the appropriate Directory Store configured, the employee information is synchronized with Zoho One.
Six months later, the employee moves to another department, and their information changes in the directory. The routine sync schedule configured in the relevant Directory Store reflects the changes in Zoho One, thereby updating access across the organization.
Similarly, when the employee leaves the organization, the changes updated in the directory will be reflected in Zoho One during the subsequent sync schedule.
Directory Stores reduce the number of manual hand-offs involved in the process, thus making it easier for administrators to maintain a consistent user lifecycle.

The bigger picture

Managing users isn't a one-time task.
Employees join, move between teams, change responsibilities, and eventually leave. Your systems need to keep up with those changes.
If your organization already has a directory service, connecting it with Zoho One can help reduce the need to treat managing user information as a discrete administrative task.
Instead of asking "Can I sync users?", ask yourself "Can I build a user-management process where the right information reaches the right systems with less manual intervention?"
That's a question worth asking before your next round of employee onboarding.

Get started with Directory Stores in Zoho One

Getting Started with Directory Stores In Zoho One

Zoho One provides guides for integrating several cloud directories, including services such as Microsoft Entra ID, Okta, Google Workspace, OneLogin, JumpCloud, and others. The exact configuration and capabilities can vary depending on the service.

If your organization uses an on-premises directory, you can explore the corresponding Directory Store options and choose the integration approach that fits your environment.

And, what if your directory service isn't listed among the available integrations?
You can also create a Custom Directory Store and configure the integration using supported authentication methods such as SCIM or OAuth. Custom stores provide options for field mapping, synchronization criteria, status synchronization, and sync frequency.