Browse guides
Admin

Organization Onboarding

Set up a new ScrambleID tenant: console access, organization settings, directory connection, and your first enrolled user.

Updated June 11, 2026

This guide takes a new organization from nothing to a first verified login. It's the admin-side companion to the end-user guides: by the end, your tenant is configured, your directory is connected, and one real user has enrolled and signed in. Budget a working session for the configuration and minutes for the first enrollment.

Before you start

  • Console access. Your ScrambleID admin console URL and your initial Super Admin assignment are provided during onboarding by your ScrambleID team. If you don't have them, that's the first ask.
  • Directory decisions. Know which identity provider you're keeping (Okta, Microsoft Entra ID, Ping, or another). ScrambleID overlays your existing directory and SSO; it doesn't replace them. You keep provisioning, groups, and governance where they already live.
  • A pilot user. Pick someone patient for the first enrollment, ideally yourself.

Step 1: Log in to the admin console

Open the admin console in your browser and log in. Your first login uses the credentials from onboarding; once your own device is enrolled, switch to signing in with ScrambleID itself.

Review the role model before inviting other admins: a Super Admin has access to everything the other admin roles have, combined. Assign the narrower admin roles for day-to-day operation; the Admin Console guide details what each role can do.

Step 2: Configure organization settings

Work through Org Settings top to bottom:

  • Login options. Which sign-in methods your users see (QR, type code, passkey) and session policy (cookie lifetime, console timeout). Session lifetime is policy-configurable; set it to match your security baseline.
  • Branding. Your logo and colors on the login page, so users recognize the page they're approving.
  • Token expiration. Defaults are sensible; tighten for high-risk environments.

Step 3: Connect your directory

Two connections, both standard:

  • SCIM provisioning keeps ScrambleID's user records anchored to your directory. Users you deactivate in the directory deactivate here; nothing drifts.
  • SAML or OIDC federation wires ScrambleID into your SSO flow, as the phishing-resistant verification step in front of (or alongside) your existing IdP.

The integration mechanics for specific IdPs are covered in the Learn deployment patterns for Okta and Microsoft Entra ID.

Step 4: Invite your first users

In the admin console, generate activation codes. Invite by mobile and manual input are selected by default: provide one or more users in the text box and click Generate Codes. Each user gets a six-digit activation code tied to their corporate email.

Start with the pilot user, not the whole company. The two-week pattern that works: pilot, then a department, then everyone, with your help desk briefed before each ring.

Step 5: First enrollment and first login

Have your pilot user:

  1. Install the ScrambleID app and create their profile (Mobile App guide or the Quickstart).
  2. Enter the company activation code when prompted, connecting their profile to your organization.
  3. Sign in to a connected application via the ScrambleID login page (Web Login guide).

Then confirm the round trip on your side: the user appears in the console with an enrolled device, and the login shows up in the history with method and device recorded.

Where to go next

  • Roll out by ring, watching enrollment and login success in the console as you go.
  • Voice verification for your contact center and M2M for your services extend the same tenant: see the M2M / API guide and the Learn IVR Integration Guide.
  • Set up the LDAP integration if you have LDAP-backed applications.