# Add Members with JIT

Enterprise organizations using [SSO](https://bitwarden.com/ja-jp/help/about-sso/) support just-in-time (JIT) provisioning of members. No extra configuration, beyond the SAML or OIDC setup processes documented in the **SSO Guides**, is required to support JIT.

> [!NOTE] Different user provisioning methods
> This article discusses only one of the available methods to invite users and manage your subscription’s seat count:
> 
> - All organizations can [manually invite users](https://bitwarden.com/ja-jp/help/managing-users/) and update the [seat count](https://bitwarden.com/ja-jp/help/manage-subscription-seats-in-your-organization/).
> - Teams and Enterprise organizations can use [SCIM](https://bitwarden.com/ja-jp/help/about-scim/).
> - Teams and Enterprise organizations can use [Directory Connector](https://bitwarden.com/ja-jp/help/directory-sync/).
> - Enterprise organizations can invite members using a shareable [invite link](https://bitwarden.com/ja-jp/help/managing-users/#tab-invite-by-link-1FpWqHUBGbhM3aGLCHtK6P/).
> - Enterprise organizations can use [just-in-time (JIT)](https://bitwarden.com/ja-jp/help/jit-provisioning/).

## Recommended JIT strategy

An optimized JIT provisioning strategy can make for one of the simplest signup processes available for your members. As an administrator, help your members join quickly and easily by noting the following:

- **Do** issue email invitations to members with [SCIM](https://bitwarden.com/ja-jp/help/about-scim/), with [Directory Connector](https://bitwarden.com/ja-jp/help/directory-sync/), or [manually](https://bitwarden.com/ja-jp/help/managing-users/#confirm/).

 - An added benefit of using SCIM or Directory Connector is that [groups and group membership](https://bitwarden.com/ja-jp/help/about-groups/) can be synced to your organization, which JIT on its own does not support, automatically assigning members to groups for streamlined [collection assignment](https://bitwarden.com/ja-jp/help/assign-users-to-collections/).
- **Do not** allow members to preemptively create Bitwarden accounts before being invited to the organization.

> [!TIP] Why is this the best JIT strategy?
> Invitation-initiated JIT provisioning of new accounts bypasses a few steps that admins or members might otherwise need to take (see **Non-standard signup**). This strategy also ensures that members who should not have master passwords, as a result of a [trusted devices](https://bitwarden.com/ja-jp/help/about-trusted-devices/) or [Key Connector](https://bitwarden.com/ja-jp/help/about-key-connector/) implementation, will not have one set on their accounts.

### Member signup process

Members provisioned with the **Recommended JIT strategy** will only need to:

1. Select the **Finish account setup**button contained in the organization invitation email.
2. When prompted, log in to their IdP with their SSO credentials. If they have an active session with the IdP, this step is skipped.
3. Depending on your organization's chosen [decryption method](https://bitwarden.com/ja-jp/help/sso-decryption-options/):

 - If **master password decryption**, create a master password.
 - If **trusted device decryption**, choose whether to remember the device.

Once complete, members will be moved to the `Accepted` state. At that time, they will need to be [confirmed](https://bitwarden.com/ja-jp/help/managing-users/#confirm/) by an administrator.

### Non-standard signup

In cases that deviate from the **Recommended JIT strategy**, the signup process for members will be somewhat different:

### 私は招待されました

あなたの受信トレイに組織への招待メールがある場合、そのメールアドレスで既にBitwardenアカウントを持っているかどうかにより、以下の手順のいずれかに従ってください：

## 私はすでにBitwardenアカウントを持っています

招待が既にBitwardenアカウントにリンクされていて、IdPによって提供されたメールアドレスと一致するメールアドレスに送信された場合、組織に参加するための次の手順を実行してください:

1. メールアドレスの招待で**組織に参加**ボタンをクリックしてください。
2. Bitwardenの招待ページで、**ログインを選択します。**あなたのメールアドレスを入力し、次にマスターパスワードを入力し、もう一度**ログイン**を選択してください。
3. ログインに成功すると、ページの上部に緑色のバナーが表示され、組織への招待が受け入れられたことを示します。組織の管理者があなたを組織に確認する必要があります。それから進行できます。
4. 確認が完了すると、Bitwardenに再度ログインして、今度は**エンタープライズシングルサインオン**オプションを使用して組織にアクセスできるようになります。

## 私はBitwardenのアカウントを持っていません

招待が既にBitwardenアカウントにリンクされていないメールアドレスに送信された場合、次の手順に従ってください：

1. メール招待で**組織に参加**ボタンをクリックしてください。
2. 招待ページで**ログイン**を選択し、次にメールアドレスを入力します。次のページで、**エンタープライズシングルサインオン**ボタンを選択します。
3. あなたの**SSO識別子**を入力し、**ログイン**を選択してください（あなたのメールアドレスが組織の検証済みドメインと一致する場合、このステップはスキップされます）**。**
4. あなたのIdPにログインしてください。それを行うと、新しいアカウントのための[マスターパスワード](https://bitwarden.com/ja-jp/help/master-password/)を作成できるページにリダイレクトされます。
5. アカウントのマスターパスワードを作成します。組織の管理者があなたを組織に確認する必要があります。それから進行できます。
6. 確認が完了すると、**エンタープライズシングルサインオン**オプションを使用してBitwardenにログインすることで、組織にアクセスできるようになります。

エラーメッセージ`組織への招待がありました、招待を受け入れてください。`が表示されてログインしようとすると、このメールアドレスには既にBitwardenアカウントが関連付けられています。**私はすでにBitwardenアカウントを持っています**上記の指示に従ってください。

### 私は招待されていません

あなたの受信トレイに組織への招待メールがない場合、そのメールアドレスでBitwardenアカウントをすでに持っているかどうかにより、以下の手順のいずれかに従ってください：

## 私はすでにBitwardenアカウントを持っています

このアカウントではSSOを使用して組織に参加することはできません。招待をリクエストするために、組織の管理者に連絡してください。

## 私はBitwardenのアカウントを持っていません

招待なしで、既存のBitwardenアカウントもない状態で組織に参加する場合は、以下の指示に従ってください：

1. Bitwardenのログインページでメールアドレスを入力してください。次のページで、**エンタープライズシングルサインオン**ボタンを選択します。
2. あなたの**SSO識別子**を入力し、**ログイン**を選択してください（あなたのメールアドレスが組織の検証済みドメインと一致する場合、このステップはスキップされます）。
3. あなたのIdPにログインしてください。それを行うと、新しいアカウントのための[マスターパスワード](https://bitwarden.com/ja-jp/help/master-password/)を作成できるページにリダイレクトされます。
4. アカウントのマスターパスワードを作成します。組織の管理者があなたを組織に確認する必要があります。それから進行できます。
5. 確認が完了すると、**エンタープライズシングルサインオン**オプションを使用してBitwardenにログインすることで、組織にアクセスできるようになります。