As your organisation grows, keeping user accounts accurate across every system becomes harder. New hires need access on day one, role changes need to be reflected quickly, and people who leave need to be removed promptly. Managing all of this manually in Motive is slow and error-prone.
Directory Sync solves this by connecting Motive directly to your identity provider (IdP) tenant and treating the IdP as the single source of truth for your users. When you add, update, or remove a user in your IdP, Motive stays in sync automatically.
| Note: To set up Directory Sync for your fleet with any supported identity provider, reach out to us at ssosupport@gomotive.com or contact your designated Customer Success Manager. |
Overview
Directory Sync automatically provisions and manages your Motive users, both drivers and fleet users, based on what happens in your identity provider. It uses the industry-standard SCIM protocol to keep the two systems aligned.
With Directory Sync enabled:
- New users are created automatically in Motive when they're assigned in your IdP.
- User details stay current changes made in your IdP (name, role, group, and more) flow into Motive.
- Departing users are deactivated automatically in Motive when they're removed or unassigned in your IdP.
This removes the need to manage users in two separate systems, reduces manual errors, and ensures the right people always have the right access.
| Note: Directory Sync (provisioning) is complementary to Single Sign-On (SSO), which handles how users log in. Directory Sync manages which users exist and their details; SSO manages how they authenticate. They can be used independently or together. When used together, they are configured as two separate applications in your identity provider tenant, one for SSO and one for Directory Sync. |
What information can be synced
Once a user is synced, the following details are managed from your identity provider:
For Drivers:
- First name and last name
- Username
- Time-tracking method (HOS logs, Timecards, Exempt, Electronic Logbook)
- Groups
- Driver ID
- Mobile phone number
- Start date
- Driver's licence information
For Fleet users:
- First name and last name
- Role(s)
- Group(s)
- Fleet User ID
- Mobile phone numbers
| Important: Once a driver or fleet user is successfully synced, the fields above can only be updated through your identity provider. They are locked for editing within Motive to prevent the two systems from drifting out of sync. |
How roles are assigned
Roles and groups can be mapped and assigned using a combination of push groups and custom attributes in your identity provider, matched to the role/group name configured in Motive. Please reach out to ssosupport@gomotive.com for more information.
Dual-role users
Some people both manage a fleet and are drivers. For example, a supervisor or dispatcher who also operates a vehicle. Directory Sync supports these users by letting a single person hold both a fleet-side role and a driver-side role, linked to one set of credentials for both their driver and fleet user accounts.
What identity providers are supported
Motive Directory Sync works with any identity provider (IdP) that uses the industry-standard SCIM protocol. This includes the leading enterprise identity platforms as well as common HRIS (human resource information system) platforms.
Identity providers:
- Okta
- Microsoft Entra ID (formerly Azure AD)
- Google Workspace
- OneLogin
- PingFederate
- CyberArk
- JumpCloud
- SailPoint
HRIS platforms:
- Workday
- Rippling
- BambooHR
- HiBob
- Access People HR
- Breathe HR
- Cezanne HR
- Fourth
To use Directory Sync, you'll need an active identity provider that supports SCIM, the appropriate licensing (for example, a Microsoft Entra ID Premium edition or an Okta integration that supports SCIM provisioning), and administrator access in your IdP to create an application, configure provisioning, map attributes, and create groups.
Enabling Directory Sync for your Motive account
Directory Sync is set up in partnership with Motive's team. To get started:
- Reach out to Motive. Email ssosupport@gomotive.com or contact your designated Customer Success Manager to request Directory Sync.
- Connect with our Integrations team. A Motive Integration Engineer will reach out to coordinate setup, confirm your identity provider, and share a secure setup link along with the details you'll need.
- Configure your identity provider. Using the setup link, you'll create the Directory Sync application in your IdP, map the supported attributes, and create the required push groups.
- Assign your users to the application and the appropriate groups.
- Go live. Once configuration is confirmed, Motive enables Directory Sync and your users begin provisioning automatically.
Once Directory Sync is enabled
Viewing profiles that have been synced
Synced users appear alongside your other users in the Motive Dashboard:
- Drivers appear in your Drivers list.
- Fleet users appear in your Fleet Users list.
Synced users typically populate automatically within about 10 minutes of a change in your identity provider, because changes are grouped together before they're applied. You can open any user's profile to confirm they landed with the expected role and group.
What actions can and cannot be performed on synced users
Because your identity provider is the source of truth, some actions are managed there rather than in Motive.
Managed in your identity provider (locked in Motive):
- First name, last name, and email
- Role and group assignment
- Time-tracking method (for drivers)
- Other synced attributes such as username, IDs, phone number, and licence details
- Activating or deactivating the user (done by assigning/unassigning them in your IdP)
Filtering synced drivers and fleet users on the Fleet Dashboard
To quickly see which users are managed by Directory Sync, use the filters on your Drivers and Fleet Users lists:
- Open the Drivers or Fleet Users page in the Fleet Dashboard.
- Open the filter options.
- Filter by ‘Active: Synced’ or ‘Deactivated: Synced’ status to show only synced (or only non-synced) users.
This makes it easy to distinguish automatically provisioned users from any users you manage manually.
Auditing changes on the Audit Log
Every change Directory Sync makes is recorded in your Audit Log, so you can see exactly what was created, updated, or deactivated automatically.
-
Go to Admin Dashboard > Security and data > Account Access > View Audit Log.
- Use the Modified By filter and select Directory Sync to show only changes made by the sync system.
-
Review the entries’ creations, updates, role and attribute changes, and deactivations. Where applicable, attribute changes show the before and after values.
This gives you a clear, self-service record for troubleshooting and for security and compliance reviews.
Reviewing sync failures and running a sync
Motive gives you a self-service view of sync health so you can spot and resolve issues without waiting on support.
To review sync health and failures:
- Go to Admin Dashboard > Security and data > Account Access > Directory Sync.
-
Review the sync overview, including the last sync time and how many users are in your identity provider compared to Motive.
-
Click View failures to open the Directory Sync Failures and see a per-user list of anything that didn't sync, each with the affected user, the action type (Create/Update), the failure reason, and a description of what to fix.
Glossary of sync failures and how to resolve them
The Directory Sync Failures view groups issues under three failure reasons. Each reason can appear with a specific message that tells you exactly what to fix. Nearly every failure is resolved in your identity provider, not in Motive. The failures below are organised by reason, and for each one you'll find the exact message shown, the possible causes, and the steps to remedy it.
Failure reason: "User details need attention"
This is a catch-all reason that covers several distinct issues. The specific message tells you which one applies.
Message shown: The user is not assigned to any push group in your identity provider tenant.
- Possible causes: The user exists in the Directory Sync application but hasn't been added to any Motive push group. Without a push group, Motive has no way to determine the user's role or category, so the profile cannot be created or updated.
-
Remedies: In your identity provider, add the user to exactly one valid push group, for example, motive_admin, motive_fleet_user, or one of the motive_driver_* groups. The user will provision on the next sync.
Message shown: This user is assigned to a group combination that cannot be synced. Validate group assignments and try again.
- Possible causes: The user belongs to conflicting push groups that resolve to more than one user category (for example, a fleet-side group and a driver-side group that don't form a supported pairing). A user must resolve to a single, clear category.
-
Remedies: Review the user's group memberships in your identity provider and remove the conflicting assignment so they resolve to one category. If the person genuinely needs both a fleet and a driver role, use a supported dual-role pairing (one fleet-side group plus one driver-side group).
Message shown: This user is assigned to an invalid combination of push groups. Remove and try again.
- Possible causes: The specific set of push groups assigned to the user isn't an allowed combination, most often two groups of the same type (such as two driver groups or two fleet groups).
-
Remedies: Remove the extra or conflicting groups in your identity provider so only a valid assignment remains (a single group, or one supported fleet + driver pairing).
Message shown: This user is assigned to an invalid push group. Adjust the push group name and try again.
- Possible causes: A group the user is assigned to doesn't match any supported Motive push group. Push-group names are case- and space-sensitive, so an extra space or a spelling difference will cause a mismatch.
- Remedies: Rename the group in your identity provider to an exact, supported push-group name. Confirm there are no leading or trailing spaces and that the capitalization matches.
Message shown: Employee ID is already in use for another person in your organisation. Enter a different Employee ID and try again.
- Possible causes: The Fleet User ID being synced is already assigned to another person in your Motive account.
-
Remedies: Assign a unique Employee ID (applies only to Fleet User ID) to the user in your identity provider, then let the change sync.
Message shown: This driver could not be deactivated during sync. Try again. If the issue continues, contact Support.
- Possible causes: A driver was removed or unassigned in your identity provider, but Motive couldn't complete the deactivation automatically; it's often a temporary condition.
- Remedies: Run a sync again. If the driver still can't be deactivated after a retry, contact Motive Support.
Message shown: This email address cannot receive email. Enter a different email address and try again.
- Possible causes: The email address on the user is invalid, malformed, or undeliverable.
-
Remedies: Correct the email address in your identity provider so it's a valid, deliverable address, then let the change sync.
Failure reason: "Email already in use"
Message shown: A user with this email address already exists in Motive.
- Possible causes: The email address being synced already belongs to another user in Motive, commonly a pre-existing profile that was created manually through self-signup that wasn’t associated with your Motive company account.
-
Remedies: Verify the user hasn't already self-registered via the web or mobile app. If an account exists, ask them to either deactivate it or change its email address before you attempt provisioning again.
Failure reason: "Role or group not found"
Message shown: The role [name] was not found in Motive. Check that it exists and is spelled correctly.
- Possible causes: A custom role or group mapped from your identity provider doesn't exist in Motive, or its name is misspelled or formatted differently than in Motive.
-
Remedies: Create the role or group in Motive with the exact same name, or correct the spelling in your identity provider so the names match precisely (names are case- and space-sensitive).
Message shown: The assigned push group or role is not a valid Motive group name. Update the group name and try again.
- Possible causes: The assigned group or role name isn't a valid Motive name.
- Remedies: Update the name in your identity provider to match a valid Motive group or role exactly.
Good to know: SCIM is "push-based," meaning Motive only receives users your identity provider actively sends. A user whose IDP never pushes won't appear in Motive and won't show up as a failure. If you suspect users are missing entirely, confirm they're assigned to the sync application in your IdP, then run a sync.
Run a sync manually (“re-sync"):
If you've corrected an issue in your identity provider or you suspect Motive has drifted out of step with your IdP, you can trigger a full re-sync from the Admin Dashboard. This pulls your entire current directory and reconciles every user to match your IdP.
-
Go to Admin Dashboard > Security and data > Account Access, then click Re-sync to run the sync.
-
A pop-up message appears to confirm the action. Click Continue.
-
The sync starts, and the Re-sync button changes to Syncing…
| Note: Before running a sync, fix the root cause first (for example, correct a group assignment or spelling in your IdP). Running a sync before fixing the underlying issue will simply re-import the same problem. If the status shows changes are still pending, wait a few minutes before triggering a re-sync. |
After a re-sync completes, you will receive a summary notification of what happened and how many users were synced, created, updated, and deactivated, along with any errors.
FAQs
A user I added in my identity provider isn't showing up in Motive. What should I check?
First, allow about 10 minutes; changes are grouped before they're applied. Then, confirm the user is assigned to the Directory Sync application in your IdP and belongs to a valid push group. Finally, check the Directory Sync Failures view for a specific reason.
Why can't I edit a synced user's name, email, or role in Motive?
Those fields are locked because your identity provider is the source of truth. Make the change in your IdP and it will sync to Motive automatically.
Can a user be both a fleet user and a driver?
Yes. This is the one supported case where a user belongs to two groups, one fleet-side group and one driver-side group (for example, Motive_admin + Motive_driver_exempt). The user is linked to a single account and signs in once to access both experiences. Do not assign more than one fleet group or more than one driver group.
How do I change a driver's time-tracking method?
The time-tracking method is derived from the driver's push group. Because a driver's type can't simply be switched between driver groups, deactivate the driver in Motive first, then reprovision them into the new driver group in your IdP.
How do I move someone between admin and non-admin?
Move them between the Motive_admin and Motive_fleet_user groups in your identity provider.
I removed a user in my identity provider, but they're still active in Motive. Why?
To verify SCIM linkage, look for the "This user's info is synced with identity provider" banner at the top of their Motive profile; if it is missing, the user was never provisioned via SCIM and should be manually deactivated in Motive.
A user was reactivated in my identity provider. Will their old profile come back?
Motive matches returning users by email, so a reactivated user is re-linked to their existing profile rather than creating a duplicate.
I see duplicate driver profiles. How do I resolve them?
Driver records can't be merged. Add the email to the profile that holds the driving history and deactivate the empty duplicate.
How often does Directory Sync run?
Changes from your identity provider are grouped and applied continuously, typically within about 10 minutes. You can also trigger a full re-sync at any time from the Directory Sync dashboard.
Does Directory Sync replace SSO?
No. Directory Sync manages which users exist and their details; SSO manages how users log in. They're set up as separate applications in your identity provider and can be used independently or together.
Share this with others