Support administrator provisioning from Entra ID / cloud identity providers (cloud-only environments)

Which aspect of EPP are you submitting for?

Endpoint Protector Server

What is a one sentence summary of your feature request?

Add the ability to provision and synchronize Endpoint Protector console administrators (System Administrators) from a cloud identity provider — primarily Microsoft Entra ID (Azure AD) — for customers who have no on-premises Active Directory.

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Problem / Gap
Today, EPP has two distinct directory mechanisms:

Azure AD (Entra ID) Sync — imports directory entities (users, groups, computers) for policy assignment. It does not touch the System Administrators list.
Administrator sync — the only mechanism that auto-populates System Administrators from a directory group. It works exclusively over on-premises Active Directory via LDAP.
As a result, cloud-only customers with no on-premises AD have no automated way to provision console administrators. They can authenticate existing admins via SAML SSO, but every administrator must be created manually in the console first. There is no path from an Entra ID group → System Administrators.

How do you currently solve the challenges you have by not having this feature?

By manual creation of administrators

1 Like