Note: This article is for administrators of an ExpressVPN for Teams account.

System for Cross-domain Identity Management (SCIM) is an open standard for automatically synchronizing users between your identity provider and ExpressVPN for Teams.

This guide explains how to set up SCIM and manage users in ExpressVPN for Teams.

Jump to…


What can you do with SCIM?

After you enable and configure SCIM, users from your organization’s directory automatically appear in your ExpressVPN for Teams dashboard, where you can assign ExpressVPN licenses from the synced user list.

If someone leaves your organization and you remove them from your identity provider, any ExpressVPN for Teams license assigned to them is automatically revoked and unassigned, making it available for another user.

Note: You cannot use the bulk upload via CSV file tool with SCIM.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


How to set up SCIM

Before you begin: Make sure you have an ExpressVPN for Teams subscription with admin access to the ExpressVPN for Teams dashboard. You will also need admin access to your identity provider.

The steps to enable SCIM vary depending on your workspace provider. Follow the instructions below for Google Workspace, or jump to the steps for Okta, Microsoft Entra ID, and other providers.

Google Workspace

Enabling SCIM provisioning with Google will connect Google Workspace to your ExpressVPN for Teams account. To do so, follow these steps:

  1. Log into your ExpressVPN for Teams admin portal.
  2. On the dashboard, click Settings.Express VPN for Teams admin console, showing a highlighted "Settings" tab.
  3. In the SCIM provisioning widget, click Set up now under Google.ExpressVPN for Teams Settings page, showing a highlighted "Set up now" button under Google.
  4. Enter your Google Admin email address and service account key, then click Submit.ExpressVPN for Teams SCIM provisioning page for Google Workspace. The Google admin email field, service account key field, and "Submit" button are highlighted.
    • Note: If you see an error message saying “Failed to save configuration,” verify that you entered the correct Google Admin address or that your service account key is valid.

    ExpressVPN for Teams SCIM provisioning page for Google Workspace, showing a highlighted error message.

  5. If correctly set up, you will see a message saying that the Google Workspace integration has been successful.ExpressVPN for Teams Settings page, showing a highlighted successful integration message.

To sync users from your Google Workspace directory with your ExpressVPN for Teams account, access Settings in your admin dashboard and click Sync Now next to the connected Google SCIM configuration.ExpressVPN for Teams Settings page, showing a highlighted "Sync Now" button for an active SCIM configuration.

Okta, Microsoft Entra ID, and other providers

To set up SCIM on all other identity providers:

  1. Sign into your ExpressVPN for Teams admin portal.
  2. On the dashboard, click Settings.Express VPN for Teams admin console, showing a highlighted "Settings" tab.
  3. Under SCIM provisioning, select Set up now for your identity provider.ExpressVPN for Teams Settings page, showing highlighted identity provider widgets.
  4. Copy the SCIM Base URL and Bearer token. Use these credentials to configure SCIM in your identity provider.ExpressVPN for Teams SCIM provisioning page, showing highlighted Base URL and Bearer toke fields.
    • Important: The Bearer token is shown only once. Store it securely before closing or refreshing the setup window.
  5. Return to the Settings page and check that your SCIM configuration is labeled as CONNECTED.ExpressVPN for Teams Settings page, showing a highlighted SCIM configuration that is active.

Once you have enabled SCIM, users from your organization’s directory are synced automatically to your ExpressVPN for Teams portal.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Manage users and assign licenses

After you enable SCIM, users from your organization’s directory are synced to the portal. You can assign licenses, unassign licenses, and find users who don’t currently have one. You can also turn auto-renewal on and off for single or multiple licenses.

How to assign licenses

  1. Sign into your ExpressVPN for Teams admin portal.
  2. Under Licenses, select Assign Users.ExpressVPN for Teams admin dashboard, showing a highlighted "Assign Users" button.
  3. Select the checkbox(es) next to the user name(s) you want to assign licenses to.ExpressVPN for Teams page for assigning licenses to users. The check boxes next to available users are highlighted.
    • You can also search users by name or email in the search bar.

    ExpressVPN for Teams page for assigning licenses to users, showing a highlighted search field.

  4. Select Assign [number] users.ExpressVPN for Teams page for assigning licenses to users, showing a highlighted "Assign users" button.
  5. You’ll see a confirmation banner once completed.ExpressVPN for Teams admin dashboard, showing a highlighted notification about licensed being successfully assigned to users.

The selected users will receive a welcome email with instructions to activate ExpressVPN.

Note: If you select more users than you have available licenses, you will need to purchase additional licenses.

How to unassign licenses

Note: If you remove a user from your identity provider, their license is automatically unassigned. You do not need to unassign it manually.

To manually unassign a license:

  1. Sign into your ExpressVPN for Teams admin portal.
  2. Under Licenses, find the user whose license you want to unassign.ExpresVPN for Teams admin dashboard, showing highlighted users.
  3. Under Manage/cancel, click the three dots (⋮).ExpressVPN for Teams admin dashboard, showing a highlighted three-dot menu icon for a user.
  4. Select Unassign.ExpressVPN for Teams admin dashboard, showing a highlighted "Unassing license" option for a user.

Once unassigned, the license is available to assign to another user.

How to filter users and licenses

  1. Sign into your ExpressVPN for Teams admin portal.
  2. Under Licenses, select Filter.The "Filter" option under LIcenses section in the ExpressVPN for Teams dashboard.
  3. Select the checkbox next to the filter you want to apply: Assigned, Expired, Unassigned, or Pending invite.The "Filter" options for users in the ExpressVPN for Teams dashboard.
  4. The user list will automatically update to show only users that match the selected filter.

To remove a filter, select the X next to the applied filter.

How to turn auto-renewal on or off for licenses

  1. Sign into your ExpressVPN for Teams admin portal.
  2. Select the licenses you wish to cancel or turn on auto-renewal for by ticking the boxes in the left-hand column under LICENSE ID.ExpressVPN for Teams admin dashboard, showing a highlighted checkbox next to "LICENSE ID."
  3. You will see a black box pop up stating the number of licenses you have selected. Select Manage renewal.Pop-up window for selected user licenses in the ExpressVPN for Teams admin panel. The "Manage renewal" option is highlighted.
  4. Next:
    • If auto-renewal is turned off: You will see the option to Turn On Auto-Renewal. Click to enable it.ExpressVPN for Teams manage renewal options for a license. The "Turn On Auto-Renewal" button is highlighted.
    • If auto-renewal is turned on: You will see the option to Turn Off Auto-Renewal. Select to disable it.ExpressVPN for Teams manage renewal options for a license. The "Turn Off Auto-Renewal" button is highlighted.

For more detailed instructions, see our guide on how to turn on/off auto-renewal for ExpressVPN for Teams licenses.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


How to purchase additional licenses

You can buy additional ExpressVPN for Teams licenses either from the dashboard or while assigning users.

Purchase licenses from the dashboard

  1. Sign into your ExpressVPN for Teams admin portal.
  2. In the top-right corner of the dashboard, select + Add More Licenses.ExpressVPN for Team's welcome page, with a highlighted "Add More Licenses" button.
  3. Use the arrows below Total licenses to select the number of additional licenses you want to purchase.The "Add more licenses" page in the ExpressVPN for Teams dashboard, with a highlighted field for number of licenses.
  4. Select Continue to payment.The "Add more licenses" page in the ExpressVPN for Teams dashboard, with a highlighted "Continue to Payment" button.
  5. On the checkout screen, select your preferred payment method, then click Confirm Subscription.The checkout page for ExpressVPN for Teams.

Your additional licenses will be added automatically and will be available to assign immediately.

Purchase licenses while assigning users

If you try to assign more licenses than you have available, you’ll need to purchase additional licenses. For example, if you try to assign licenses to 11 users but only have 10 available, a banner alert will appear prompting you to purchase additional licenses.

To do so:

  1. In the banner, select purchase additional licenses.ExpressVPN for Teams page for assigning licenses to users, showing a highlighted "purchase additional licenses" option.
  2. Review the order summary, then select Confirm Subscription.ExpressVPN for Teams admin dashboard, showing an order summary for buying additional licenses. The "Confirm Subscription" button is highlighted.
  3. On the checkout page, select your preferred payment method, then select Confirm subscription.Order summary page for purchasing additional ExpressVPN for Teams licenses. The "Confirm Subscription" button is highlighted.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


How to disconnect SCIM

  1. Sign into your ExpressVPN for Teams admin portal.
  2. On the dashboard, click Settings.Express VPN for Teams admin console, showing a highlighted "Settings" tab.
  3. Next to SCIM configuration, select Revoke.ExpressVPN for Teams Settings page, showing a highlighted "Revoke" button for an active SCIM configuration.
  4. Select Remove SCIM in the pop-up to confirm.ExpressVPN for Teams admin panel, showing a pop-up window for revoking a SCIM provisioning. The "Revoke SCIM" button is highlighted.
  5. You will then see a “You have successfully revoked SCIM integration” message at the top of the screen.ExpressVPN for Teams Settings page, showing a highlighted notification about successfully revoking SCIM integration.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top

Was this article helpful?

We're sorry to hear that. Let us know how we can improve.

A member of our Support Team will follow up on your issue.