JIT Provisioning
Enterprise organizations using
Recommended JIT strategy
An optimized JIT provisioning strategy can make for one of the simplest signup processes available for your members. As an administrator, help your members join quickly and easily by noting the following:
Do issue email invitations to members with
SCIM, withDirectory Connector, ormanually.An added benefit of using SCIM or Directory Connector is that
groups and group membershipcan be synced to your organization, which JIT on its own does not support, automatically assigning members to groups for streamlinedcollection assignment.
Do not allow members to preemptively create Bitwarden accounts before being invited to the organization.
tip
Invitation-initiated JIT provisioning of new accounts bypasses a few steps that admins or members might otherwise need to take (see Non-standard signup). This strategy also ensures that members who should not have master passwords, as a result of a
Member signup process
Members provisioned with the Recommended JIT strategy will only need to:
Select the Finish account setup button contained in the organization invitation email.
When prompted, log in to their IdP with their SSO credentials. If they have an active session with the IdP, this step is skipped.
Depending on your organization's chosen
decryption method:If master password decryption, create a master password.
If trusted device decryption, choose whether to remember the device.
Once complete, members will be moved to the Accepted state. At that time, they will need to be
Non-standard signup
In cases that deviate from the Recommended JIT strategy, the signup process for members will be somewhat different:
In cases where invitations were not sent to members, the organization can still be joined with relative ease. Instruct members to follow
tip
Unless your organization has already