Skip to main content

JIT Provisioning

Just-in-Time (JIT) provisioning allows Files.com to automatically create user accounts the moment a user logs in through a configured identity provider. This approach offers a fast and easy way to onboard users without requiring manual account setup or synchronization.

Files.com supports JIT provisioning with a wide range of identity providers including Microsoft Entra ID, OneLogin, JumpCloud, Auth0, and others.

When to Use JIT vs SCIM

JIT provisioning is useful when you want to create users automatically at login without managing them in advance. It works well for simple environments that do not require group synchronization, user updates, or automated deactivation.

SCIM is preferred when you need to manage users over time. SCIM supports automatic user updates, group membership synchronization, and user deactivation. It is especially important when using Microsoft Entra ID, which sends group identifiers as unreadable UUIDs during JIT provisioning. SCIM avoids this limitation by managing groups properly.

Choose JIT if you only need to create users once and do not rely on groups or lifecycle changes. Choose SCIM if you need to manage access, roles, and user status automatically.

Setting Up JIT Provisioning

To enable JIT provisioning, add a new identity provider in Files.com and choose Use JIT Provisioning under Provisioning Method. Files.com will then create user accounts automatically when users log in for the first time. You can customize the provisioning behavior using the available configuration options.

Configuration Options

Configuration OptionDetails
Provision users to this company nameAutomatically sets the company name in the user profile for newly created users.
Add users to these default groups on first loginAutomatically adds each newly created user to one or more predefined groups.
Two-Factor Authentication settingsControls the 2FA requirement for provisioned users. You can inherit the site-wide policy, always require 2FA, or never require it. For example, if your site-wide 2FA policy mandates Always required for all users, but you need to exempt JIT provisioned users from this requirement, select Never require 2FA.
Protocol permissionsSpecifies which protocols (FTP, SFTP, WebDAV) users are allowed to use. These can be toggled individually.
Default time zone for auto-provisioned usersSets the default time zone for new users. If left blank, the site-level time zone is applied.

Get Instant Access to Files.com

The button below will take you to our Free Trial signup page. Click on the white "Start My Free Trial" button, then fill out the short form on the next page. Your account will be activated instantly. You can dive in and start yourself or let us help. The choice is yours.

Start My Free Trial