- In Dust, navigate to Admin > People & Security > Domain and Members > User provisioning > Setup Directory sync
- Select you identity provider (IdP) from the list
- Follow the steps
- Important note for Enterprise customers: to enable department-segmented analytics, customers must provision relevant groups to Dust.
Check your IdP documentation along the way The setup experience may vary depending on the selected IdP. We recommend checking the documentation of your IdP (specifically the sections about SSO, SAML and SCIM) as each might have specificities. (For example, Okta (OIDC) might require you to create 2 applications - one for SSO, one for SCIM)
Assign roles from groups
You can automatically grant the Admin or Manager role to your users based on their group membership. In Dust, go to Settings & Governance > Roles (admin only) and map any workspace group to a role:- Members of a group mapped to a role inherit that role.
- A user always keeps the highest role granted across their groups (admin > manager).
- A group can grant at most one role.
This replaces the previous behavior where roles were assigned through groups named exactly “dust-admins” and “dust-managers”.