Okta
SAML sign-in with SCIM provisioning.
Identity
Identity · Two-way sync · Live since 2024 · About 15 minutes to connect
Finly registers as an enterprise application in Entra ID, so conditional access applies before anyone reaches a card. Groups map to roles and cost centres, and a disabled account is out of Finly the same minute it is out of the tenant.
What syncs
Both directions, on every sync.Nothing here is a nightly batch —a record that changes at 14:02 is in the ledger before you look at it.
Connected


Everyone signs in through Microsoft Entra ID and lands on the role their group says they should have.Deprovision there and the Finly session ends the same minute, with the cards frozen behind it.
Before you start
You need a Microsoft Entra ID tenant with rights to add an application, and a Finly plan on Scale or above —SSO is not on Core.Finly is a SAML 2.0 service provider with SCIM 2.0 for provisioning, so setup is the metadata exchange you have done before:upload ours, paste yours, map three attributes, test with one user.
Two things it deliberately will not do.It will not lock you out —break-glass password access stays on for the owner account until you switch it off yourself, and it can be restored from the recovery flow.And it will not grant spend:Microsoft Entra ID decides who gets in and which role they land on, while card limits and approval rights stay in Finly, where finance owns them.
Related
SAML sign-in with SCIM provisioning.
Workspace sign-in, groups as roles.
One directory, one set of card rights.
Device-aware sign-in for smaller teams.
Get started
Book a 30-minute demo and we'll run your own last month through a sandbox, so you can see the close before you commit to anything.