About
Provisioning groups come into play if you have synced your organization with a Google Workspace or Entra ID (formerly Azure AD). Once a Workspace or Entra ID domain is synced, by default, all users in that domain become licensed users. If you have purchased email licenses for only a subset of your users, then you need to implement a provisioning group to maintain licensing compliance.
If your subscription includes our file solutions, Secure Share and/or Drive, the provisioning group will control access to those products, as well. If you would like to license these products separately, please review our product-specific provisioning instructions for Secure Share and Virtru for Drive.
Jump to:
Configuring a Provisioning Group
Finding Provisioned Users
User Experience and Impact
Configuring a Provisioning Group
The provisioning group is created and maintained within the Workspace or Microsoft environment. Virtru customers can create a Google Group on their Workspace or a mail-enabled group in Exchange and add only their desired Virtru senders to that group. Follow the steps below to configure a provisioning group:
1. Create a Google Group or Microsoft distribution group on your domain with the group email addressed as "virtru-provisioning-group@[yourdomain.com]"
Note for organizations with multiple domains
Set the provisioning group domain to match the domain of the administrator who configured the sync with Virtru
2. Add the users you want to license to this group
3. Sync with Virtru:
- If you have already synced with Virtru, you can perform a domain refresh
- If you have not synced with Virtru, you will want to install Virtru on the domain level in Google Workspace or Entra ID
4. Once complete, use this group to manage email plugin access for your organization
Note
After creating the provisioning group, the list will need to be maintained into perpetuity. A "domain refresh" will need to be performed for any provisioning group changes to take effect in Virtru (or any other changes to groups and/or users).
Finding Provisioned Users
Inside of the Virtru Control Center, you have the ability to filter your users by members of your Virtru provisioning group. In order to see those users, you may perform the following steps:
- Sign in to the Virtru Control Center
- Go to the Users & Groups page > Users tab
- Using the filter drop-downs, select All Users in Groups and type in virtru-provisioning-group@[yourdomain.com]
- Click the magnifying glass to submit the search
- This will list the users within your organization's Virtru provisioning group
User Experience and Impact
A provisioned user will have full plugin access. However, non-provisioned users will have limitations:
- Non-provisioned users can still decrypt messages in the Secure Reader like external recipients
- They will also be able to reply in the Secure Reader
- If a non-provisioned user does install a plugin:
- This will require a license
- They will have read-only access
- Security Rules will not scan or apply
- They will NOT be able to create new encrypted emails, replies, or drafts
- Non-provisioned users will still appear in the Control Center and may appear as "Activated" if they ever activated a plugin in the past