A phased reference architecture for automating identity, SaaS, and device provisioning — built on Zero Trust principles — for ExampleCo's global offices.
From day-one: verified identity → least-privilege access → compliant device. Entirely automated from a single IT approval.
Enable every new hire to start securely on day one with verified identity, least privilege, and compliant devices — no manual provisioning, no standing over-permission, no unmanaged endpoints.
flowchart LR
subgraph ZT["Zero-Trust Principles"]
direction LR
P1["🔍 Verify explicitly<br/><i>identity · device · location · risk</i>"]
P2["🔐 Least privilege<br/><i>JIT · JEA · adaptive policy</i>"]
P3["🧨 Assume breach<br/><i>segment · monitor · contain</i>"]
end
| # | Principle | How ZTOA applies it |
|---|---|---|
| 1 | Verify explicitly | Phishing-resistant MFA + risk-based Conditional Access on every sign-in |
| 2 | Use least privilege | PIM (JIT) admin access, per-app SCIM scoping, compliant-device grants |
| 3 | Assume breach | Device compliance + EDR, Sentinel/XDR telemetry, automated offboarding |
📘 Full blueprint: docs/zero-trust.md
flowchart TD
classDef src fill:#e0f2fe,stroke:#0284c7,color:#0c4a6e
classDef n8n fill:#fdf2f8,stroke:#db2777,color:#831843
classDef idp fill:#eef2ff,stroke:#4f46e5,color:#312e81
classDef saas fill:#f0fdf4,stroke:#16a34a,color:#14532d
classDef dev fill:#fffbeb,stroke:#d97706,color:#78350f
classDef skip fill:#f1f5f9,stroke:#94a3b8,color:#475569
subgraph SRC["🗂️ Source & Approval"]
HR["👤 HR<br/>Submits Notion form<br/>(all offices)"]:::src
NDB["📋 Notion DB — new hire page<br/><i>Country · Approval Status = Pending Review</i>"]:::src
IT["👨💻 IT Admin<br/>Reviews & approves"]:::src
HR --> NDB --> IT
end
IT -->|"⚡ Approval = Approved"| N8N
N8N["⚙️ n8n<br/>Detects via Notion Webhook<br/>claims run · Automation State = Running"]:::n8n
subgraph IDP["🔐 Identity Provisioning"]
EID["<b>Entra ID — Primary IdP</b><br/>• Create user<br/>• Assign M365 license<br/>• Add to Intune group (USA/DE/FR)<br/>• Apply Conditional Access"]:::idp
OKTA["<b>Okta — Secondary IdP</b><br/>• Create/sync user via API"]:::idp
SCIM["📦 Okta SCIM provisioning<br/>• Google Workspace · KnowBe4 · Box<br/>• RingCentral · Shopify Plus · Zendesk<br/>• Basecamp (Okta-exclusive)<br/>• FrontApp · ProcessMaker"]:::saas
N8N --> EID
N8N --> OKTA
OKTA --> SCIM
end
subgraph DEV["💻 Device Enrollment"]
EMAIL["✉️ n8n sends enrollment guide email"]:::dev
JOIN["👤 User joins Entra ID<br/>+ automatic Intune enrollment"]:::dev
DETECT["🔔 n8n detects via Graph Webhook<br/>→ Update Notion"]:::dev
EMAIL --> JOIN --> DETECT
end
EID -->|"USA / Germany / France"| EMAIL
EID -->|"Korea / China / Japan"| EXIT["⏭️ No device step"]:::skip
The workflow is fully event-driven: a single Notion approval fans out to identity, SaaS, and device provisioning — then loops back to update the source of truth.
flowchart TD
subgraph IDP["Identity Providers"]
direction LR
E["Entra ID<br/><b>Primary</b><br/>M365 · Intune · CA"]
O["Okta<br/><b>Secondary</b><br/>non-Microsoft SaaS"]
end
E -->|"user creation"| ALL["All new hires"]
O -->|"SCIM provisioning"| SAAS2["SaaS apps"]
| Layer | System | Role |
|---|---|---|
| Primary IdP | Microsoft Entra ID | User creation, M365 license, Intune device group, Conditional Access |
| Secondary IdP | Okta | Non-Microsoft SaaS provisioning only |
mindmap
root((Zero-Trust))
Identity
MFA / FIDO2
Conditional Access
PIM (JIT)
Endpoints
Autopilot / ADE
Intune
Defender for Endpoint
Data
Purview
DLP
Apps
CASB
SSPM
Network
ZTNA
Analytics
Sentinel
XDR
| Pillar | Key Controls |
|---|---|
| 🪪 Identity | Phishing-resistant MFA, risk-based Conditional Access, PIM |
| 💻 Endpoints | Windows Autopilot / Apple ADE, compliance policies, EDR |
| 🗂️ Data | Purview sensitivity labels, DLP, encryption |
| 📦 Apps | Defender for Cloud Apps (CASB), OAuth governance, SSPM |
| 🌐 Network | ZTNA (Global Secure Access), microsegmentation |
| 📊 Analytics | Sentinel (SIEM/SOAR), Defender XDR, UEBA |
sequenceDiagram
autonumber
participant N8N as n8n
participant EID as Entra ID
participant OKTA as Okta
participant SAAS as SaaS Apps
N8N->>EID: Create user + assign M365 license
EID-->>N8N: User object + Intune group
N8N->>OKTA: Create/sync user (Okta API)
OKTA->>SAAS: SCIM provisioning
Note over SAAS: Google Workspace · KnowBe4 · Box<br/>RingCentral · Shopify · Zendesk · Basecamp
OKTA-->>N8N: Provisioning status
sequenceDiagram
autonumber
participant N8N as n8n
participant USER as New Hire
participant INTUNE as Intune
participant NT as Notion
N8N->>USER: Enrollment guide email
N8N->>NT: Device Status = Pending Enrollment
USER->>INTUNE: Entra ID join + enroll
INTUNE-->>N8N: Graph webhook (enrolled)
N8N->>NT: Device Status = Enrolled
🚀 Recommended upgrade: move from user-driven enrollment to Windows Autopilot / Apple ADE for zero-touch, hardware-identified provisioning. See docs/device-enrollment.md.
gantt
title ZTOA Implementation Roadmap
dateFormat YYYY-MM-DD
section Foundation
Phase 0 Foundation :p0, 2026-01-05, 14d
section Identity
Phase 1 Identity & Approval :p1, after p0, 21d
section SaaS
Phase 2 SaaS Provisioning :p2, after p1, 21d
section Device
Phase 3 Device Enrollment :p3, after p2, 21d
section Verify
Phase 4 Continuous Verify :p4, after p3, 14d
section Zero-Trust
Phase 5 Zero-Trust Hardening :p5, after p4, 28d
- Phase 0: Foundation — Notion DB, n8n, Entra ID/Okta one-time setup
- Phase 1: Core Identity & Approval Gate — HR form → IT approval → Entra ID user creation
- Phase 2: SaaS Provisioning Automation — Okta sync + SCIM apps + Adobe UMAPI
- Phase 3: Device Enrollment & Compliance — enrollment guide emails, Intune enrollment, detection
- Phase 4: Continuous Verification & Maturity — reminders, monitoring, hardening
- Phase 5: Zero-Trust Hardening — MFA, compliant-device CA, EDR, Purview DLP, CASB, Sentinel, offboarding
📘 Full roadmap: docs/phases.md
| Pillar | Recommended Service | Purpose |
|---|---|---|
| Identity | Entra ID P2, Identity Protection, PIM | Risk-based CA, JIT admin |
| Identity | Authenticator + FIDO2, Windows Hello | Phishing-resistant / passwordless MFA |
| Endpoints | Windows Autopilot, Apple ADE, Intune | Zero-touch device provisioning |
| Endpoints | Defender for Endpoint | EDR |
| Data | Purview Information Protection, DLP | Classification + exfiltration control |
| Apps | Defender for Cloud Apps, Entra Permissions Mgmt | CASB, CIEM |
| Network | Global Secure Access, Entra Private Access | ZTNA |
| Analytics | Sentinel, Defender XDR | SIEM/SOAR, XDR |
| Lifecycle | Entra ID Lifecycle Workflows, Access Reviews | On/offboarding + certification |
| Document | Contents |
|---|---|
| docs/project-charter.md | Goals, scope, stakeholders, IdP strategy, success criteria |
| docs/architecture.md | Overall architecture, SaaS automation matrix, n8n roles |
| docs/device-enrollment.md | Laptop enrollment policy, user-driven procedure, guide email, detection |
| docs/compliance.md | Regulatory compliance by country |
| docs/zero-trust.md | Zero-Trust blueprint (6 pillars, lifecycle, maturity, services) |
| docs/phases.md | Phased implementation roadmap |
zero-trust-onboarding/
├── README.md # Overview, vision, architecture, infographics
├── note.md # Notes index
└── docs/
├── project-charter.md
├── architecture.md
├── device-enrollment.md
├── compliance.md
├── zero-trust.md
└── phases.md
| Item | Details |
|---|---|
| IdP Structure | Entra ID (Primary) + Okta (non-Microsoft SaaS only) |
| Device Enrollment | USA/DE/FR: User-driven enrollment (Entra ID join → auto Intune enrollment) |
| Device Provisioning (ZT) | Windows Autopilot / Apple ADE recommended — zero-touch, hardware-identified |
| Device Management Excluded | Korea / China / Japan |
| n8n Role | Orchestration + alert hub + Adobe UMAPI workaround + device enrollment guide/tracking |
| Fully Automated Tools | Google Workspace, KnowBe4, Box, RingCentral, Shopify Plus, Zendesk, Basecamp |
| Plan Upgrades Required | Slack (Business+), Notion (Enterprise) |
| Okta SCIM Not Supported | Adobe → n8n + UMAPI maintained |
| Regulatory Compliance | Germany Works Council consultation, France CSE consultation required |
With this structure, once IT admin approves, the entire process — account creation → SaaS provisioning → laptop enrollment guide → enrollment tracking — is automated.