ENTERPRISE IDENTITY LIFECYCLE

Extend Microsoft Entra Identity Lifecycle Beyond Application Access

Microsoft Entra manages authentication, directory identity and application access. CardIQ extends employee identity governance into external company representation. CardIQ does not replace Microsoft Entra ID.

Where Entra ends and CardIQ continues

Different identity layers, one employee lifecycle. Enterprise IAM controls who can access corporate systems. CardIQ controls how employees represent the organization externally.

Microsoft Entra

Directory → Authentication → Application Access

CardIQ

External Identity → Public Representation → Communication Trust → CardIQ-managed Identity Asset Offboarding

HR / DirectoryIAM / Identity ProviderAuthentication & Application AccessCardIQ External Corporate IdentityPublic Trust & Communication VerificationOffboarding

How CardIQ Extends the Microsoft Entra Lifecycle

Controlled Microsoft Entra Lifecycle Reconciliation connects selected Entra directory state to company-governed CardIQ employee identity decisions.

Controlled Microsoft Entra Lifecycle Reconciliation

  1. Microsoft Entra
  2. Scoped Directory Read
  3. CardIQ Preview & Reconciliation
  4. Safety Controls
    • Monitor Only
    • Dry-Run / Review
    • Large-Change Protection
    • Circuit Breaker
  5. Company Policy
  6. Monitor Change or Deactivate CardIQ Identity

    Depending on policy, CardIQ monitors the lifecycle difference or deactivates the corresponding CardIQ employee identity.

CardIQ-managed external identity reflects the employee lifecycle state according to company policy. This can include CardIQ employee status, the public employee profile, the CardIQ digital business card and verification status.

Two platforms, distinct responsibilities

This comparison describes how CardIQ complements Microsoft Entra; it does not suggest a deficiency in either identity layer.

Identity functionMicrosoft EntraCardIQ
Workforce directoryPrimary platformConsumes selected lifecycle data
AuthenticationPrimary platformNot CardIQ's primary role
SSOPrimary platformEntra-based enterprise sign-in supported where configured
Application accessPrimary platformNot provided by CardIQ
Employee public profileNot CardIQ's comparison focusPrimary capability
Digital business cardsNot CardIQ's comparison focusYes
Company-controlled email signatureDifferent product scopeYes
Communication verificationDifferent product scopeYes
Trusted company domainsDifferent identity purposeYes
External employee identity offboardingDifferent product scopeYes, for CardIQ-managed identity assets

Microsoft Entra directory synchronization and controlled lifecycle reconciliation

This is a current CardIQ Enterprise integration. A company-bound Microsoft Entra OIDC configuration provides mapped enterprise sign-in where configured and supports a deliberately controlled directory lifecycle workflow.

Scoped preview before change

Administrators select allowlisted groups and receive a read-only directory preview before applying controlled employee synchronization. Manual dry-run and review controls keep proposed changes visible.

Monitoring first

Scheduled lifecycle reconciliation can begin in monitor-only mode. Controlled auto-apply is optional, policy-bound and can be stopped with Switch to Monitor Only kill-switch behavior.

Safeguarded reconciliation

Large-change protection, circuit breaker safeguards and reconciliation health/status reduce unsafe automation. Review precedes destructive actions. Incomplete Microsoft Graph responses are not treated as deletion evidence.

ConnectPreviewReviewSyncAutomate
CardIQ does not currently implement native SCIM, direct LDAP or direct LDAPS. This capability is Microsoft Entra directory synchronization and controlled lifecycle reconciliation—not a SCIM integration.

Two Different Lifecycle Integration Models

SCIM provisioning and CardIQ’s current Entra reconciliation architecture are different lifecycle approaches. The appropriate model depends on product support, configuration and organizational requirements.

AreaSCIM ProvisioningCardIQ Entra Reconciliation
ModelIdentity provider pushes provisioning changes to an applicationCardIQ reads selected Entra lifecycle state and reconciles it with CardIQ
Current CardIQ supportNot currently implementedYes
ScopeDepends on SCIM implementation and provisioning configurationExplicitly selected CardIQ/Entra scope
Review before applying changesDepends on product implementationPreview, dry-run and monitor-only controls available
Large-change safeguardsDepends on implementationLarge-change protection and circuit-breaker controls
Lifecycle automationDepends on configurationOptional and controlled by company policy
CardIQ currently supports controlled Microsoft Entra lifecycle reconciliation. Native SCIM is not currently implemented.

Visibility before lifecycle action

For organizations that want visibility before lifecycle changes are applied, CardIQ provides directory preview, monitor-only operation, dry-run review, explicit scope, and company-controlled lifecycle policies.

Built for Cautious Automation

Organizations can move from observation to policy-controlled action at their own pace.

Monitor First

Start with lifecycle reconciliation without automated changes.

Review Changes

Preview directory and lifecycle differences before applying them.

Protect Against Bulk Mistakes

Large-change protection and circuit breakers help stop unexpected mass actions.

Automate by Policy

Enable controlled deactivation only when the organization is ready.

A precise offboarding example

CardIQ acts only on identity records and assets within CardIQ according to the company-controlled policy.

1–2. Active identity

The employee is active in Microsoft Entra and the corresponding CardIQ employee identity is active.

3–4. Lifecycle detection

The employee becomes disabled in Entra. CardIQ detects that lifecycle state during a complete, healthy reconciliation.

5. Company policy decides

CardIQ either monitors and reports only or, when explicitly configured, deactivates the CardIQ employee record.

6. External representation

CardIQ-managed external identity assets stop representing that employee as active. CardIQ does not claim to revoke assets outside its scope.

Security boundaries

The integration is designed around selected scope, least privilege and company control.

Explicit directory scope

Selected groups and an allowlisted sync scope limit which directory identities CardIQ previews and reconciles.

No reverse lookup or impersonation

CardIQ does not use public identity surfaces to reverse-lookup directory data and does not impersonate employee identities.

Policy-controlled action

Monitoring is the safe starting point. Company administrators explicitly control scope, review and whether eligible reconciliations may auto-apply.

See the Full Employee Lifecycle in Action

See how CardIQ previews selected Microsoft Entra users, reviews lifecycle changes, applies controlled synchronization, and protects CardIQ-managed external identity during employee offboarding.

Frequently asked questions

Does CardIQ replace Microsoft Entra ID?

No. Microsoft Entra is the workforce directory, authentication and application-access layer; CardIQ controls CardIQ-managed external corporate identity.

Does CardIQ currently support Microsoft Entra?

Yes. CardIQ currently supports company-bound Entra OIDC, selected-group directory preview, controlled employee synchronization and controlled lifecycle reconciliation.

Does CardIQ support SCIM?

Not currently. CardIQ also does not currently implement direct LDAP or direct LDAPS.

Can CardIQ automatically deactivate employees disabled in Entra?

Yes, when explicitly configured under CardIQ's controlled reconciliation policy. Monitor-only operation remains available.

What happens if Microsoft Graph returns incomplete data?

Missing or incomplete response data is not treated as deletion evidence. Health controls and circuit breakers help stop that response from driving an unintended deactivation.

Microsoft, Microsoft Entra, Okta, and related product names and marks are trademarks of their respective owners. CardIQ is not affiliated with, sponsored by, or endorsed by these companies unless expressly stated. This corporate non-affiliation statement does not alter the current technical compatibility described above.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing