Skip to main content
Connect Origin to your identity provider so that users, groups, group memberships, and device-to-user assignments stay in sync with your source of truth. Once an integration is connected, the synced data appears in the Directory Browser in your Origin dashboard, giving every investigator richer context when reviewing endpoint activity.

What Directory Integration Does

After you connect a provider, Origin periodically pulls directory data and surfaces it throughout the console:
  • Users — every account in your directory, including display name, email, department, job title, and last sign-in time.
  • Groups — security groups, distribution lists, and Microsoft 365 groups, with direct memberships and nested sub-groups.
  • Device-to-user assignments — hardware serial numbers and assigned owners from your MDM or device management platform, used to correlate observed endpoints with real identities.
All of this data is browsable in the Directory Browser, and where serial numbers match endpoints already registered in Origin, you’ll see an Assigned identity appear directly on the endpoint detail panel.

Supported Providers

Microsoft Entra ID

Grant tenant-wide admin consent to Origin’s managed application and choose what to sync — no app registration required. A manual setup method is also available for advanced tenants.

Okta

Create a read-only Okta API Services app with public-key authentication — no client secret to store or rotate.

Google ID

Create a Google Cloud service account with domain-wide delegation to sync users, groups, organizational units, and devices from Google Workspace.