Overview
This article explains why a user you deactivated in SalesScreen can become active again, and how to stop it from happening.
The article is for Company Admins, User Admins and IT users who manage users in SalesScreen or in a connected user provisioning system.
This article covers user status (active or inactive). It does not cover how to buy or manage licenses.
Who can do this?
Action | Required access |
Deactivate or reactivate a user in SalesScreen | Company Admin or User Admin |
Set up Azure AD import in SalesScreen | Admin privileges in both SalesScreen and your Azure AD tenant |
Remove the user from Azure AD, Okta or another source system | Admin of that system, usually your IT department |
Activate a pending user | Account Owner, Company Admin or User Admin |
Order more licenses | Account Owner only |
Confirm which system reactivated a user | SalesScreen Support |
Which plans include this?
Deactivating, reactivating and syncing users is available on all plans.
Requirements
Before you start, make sure that:
You have Company Admin or User Admin access in SalesScreen.
The user is already deactivated in SalesScreen.
You know, or can find out, whether the user is managed manually or through an integration.
You have access to the source system, or you can contact the person who manages it.
For Azure AD: you have admin privileges in your Azure AD tenant, or you can contact your Azure AD admin.
When this matters
Use this article when:
A former employee becomes active again after being deactivated.
A user is re-enabled after each sync.
A user is activated or deactivated and nobody in your company made the change manually.
You use Azure AD automatic import, Okta, an API integration or another automated user source.
You are unsure whether a user is managed manually or synced from another system.
How it works
Manually managed users stay deactivated
A user who was created and managed manually in SalesScreen stays deactivated until someone reactivates the user.
Synced users follow the source system
If an integration or provisioning tool controls the user, that system decides whether the user is active. Deactivating the user only in SalesScreen can be temporary, because the source system can re-enable the user.
API changes cannot be overwritten in SalesScreen
If a user is activated through the SalesScreen API, you cannot override the change in SalesScreen. The system that sends data through the API must stop sending the user as active.
Which source controls the user?
Source | What it means | Where to fix it |
A person (email address) | Someone changed the user manually in SalesScreen | SalesScreen |
Microsoft Azure AD | Azure AD automatic import controls the user | Azure AD, usually managed by IT |
Okta | Okta can activate users in SalesScreen | Okta, usually managed by IT |
Integration API | A user provisioning tool that your company controls manages the user | That provisioning tool, usually managed by IT |
SalesScreen API | User data is sent to SalesScreen through the API | The system or integration that sends the data |
You can check which source activated or deactivated a user in User Logs under Manage › Users. User Logs show the action, the source and who or what made the change. If the source is still unclear, contact SalesScreen Support.
How Azure AD automatic import works
Azure AD automatic import keeps SalesScreen users in sync with the Azure AD groups you select.
Any user in a selected group is added to SalesScreen automatically.
SalesScreen checks the selected groups for membership changes.
The sync runs once every hour.
The integration is read-only. SalesScreen never writes data back to Azure AD.
Automatically disable users is an optional setting:
When the setting is on: users removed from the selected Azure AD groups are also disabled in SalesScreen.
When the setting is off: users removed from the groups are not disabled in SalesScreen automatically.
How Okta works with SalesScreen users
SalesScreen supports Okta for single sign-on (SSO), and Okta can activate users in SalesScreen.
Users activated through Okta are not added to a team automatically. Assign the user to a team, otherwise activities cannot be logged to the user.
Users vs. licenses
A user and a license are two different things. Changing licenses does not stop a synced user from coming back. The difference is described in the table under 3.2.1.
Configuration or setup
Step 1: Find out what controls the user
1. Click Manage in the bottom-left corner.
2. Under Company, click Users.
3. Click User Logs.
4. Find the latest activation of the user, and check the source.
If the source is a person's email address, the user was changed manually. If the source is Microsoft Azure AD, an integration or the SalesScreen API, the change must be made in that system. If the source is unclear, contact SalesScreen Support.
Step 2: Remove the user at the source
Remove the user from the source system or from the group or list that feeds SalesScreen.
Azure AD: remove the user from every Azure AD group selected for the SalesScreen import.
Okta or another provisioning tool: ask your IT admin to remove or deactivate the user there.
SalesScreen API or another integration: ask the integration owner to stop sending the user as active.
If the user is still included at the source, the user can become active again on the next sync.
Step 3: Turn on Automatically disable users (Azure AD only)
Go to Users › Add users › Import users from Azure AD.
Open Automatic Import.
Turn on Automatically disable users.
Step 4: Wait for the next sync and check the user
Then go to Manage › Users › Deactivated and confirm that the user is still listed there.
Expected result
The user stays deactivated after the next sync.
The user is listed on the Deactivated tab under Manage › Users.
You can reactivate the user later if needed.
Technical details
3.2.1 Data, fields or objects
Field / object | Description |
Active user | A user who can log in to SalesScreen |
Inactive user | A user who can no longer log in, but is still listed on the Deactivated tab |
Pending user | A user who was added without an available license and cannot log in yet |
License | A paid seat that allows a user to be active |
Azure AD group | A group selected in Azure AD automatic import. Members are added to SalesScreen |
Okta | Identity provider used for SSO. Okta can activate users in SalesScreen |
SalesScreen API | Sends user data to SalesScreen from an external system |
3.2.2 Configuration parameters
Setting | Where to configure it | Default | Notes |
Azure AD automatic import | Users › Add users › Import users from Azure AD › Automatic Import | Off | Click Enable to turn it on |
Selected Azure AD groups | Automatic Import page | None selected | Users in the selected groups are added to SalesScreen |
Automatically disable users | Automatic Import page | Off (optional setting) | Disables users in SalesScreen when they are removed from the selected groups |
Azure AD sync frequency | System-controlled | Once every hour | Cannot be changed by the customer |
Okta SSO | Set up in Okta by your IT admin, then completed by SalesScreen | Not set up | Your IT admin creates the SalesScreen app in Okta and shares the Client ID, Client Secret and Okta domain with SalesScreen |
3.2.3 Limits and behaviour
Area | Behaviour |
Manually managed users | Stay deactivated until someone reactivates them |
Azure AD synced users | Can become active again if they remain in a selected Azure AD group |
Okta users | Can be activated by Okta. Are not added to a team automatically |
API-managed users | API changes cannot be overwritten in SalesScreen |
Provisioning tools and teams | Provisioning tools activate or deactivate users. They do not control teams |
Pending users | Deactivated automatically by SalesScreen if not activated within 2 weeks |
Reactivation | Requires an available license |
Users without a team | Cannot have activities logged to them |
Viewing the activation source | Admins can check the source in User Logs under Manage › Users |
3.2.4 Error codes and typical issues
Error or symptom | Likely cause | How to fix it |
A deactivated user becomes active again after an hour | The user is still in a selected Azure AD group | Remove the user from all selected Azure AD groups |
A user was removed from Azure AD but is still active in SalesScreen | Automatically disable users is turned off | Turn on the setting, or deactivate the user manually |
A user is re-enabled and nobody changed it in SalesScreen | Okta, another provisioning tool, an integration or the API is sending the user as active | Ask your IT admin or the integration owner to update the user at the source |
A user was deactivated without anyone doing it manually | The user was removed from the source system, or the user was pending for more than 2 weeks | Check the source system and whether the user was pending |
A user is pending instead of active | No available licenses | Ask an Account Owner to add licenses |
A synced or reactivated user has no data | The user is not assigned to a team | Assign the user to a team |
What if this doesn't work?
Check the following:
Check User Logs under Manage › Users to see who or what activated the user again.
The user is removed from the source system, not only deactivated in SalesScreen.
The user is not in another Azure AD group, Okta assignment or source list connected to SalesScreen.
The integration or API no longer sends the user as active.
You have waited for the next sync.
The issue is about user status, not license availability.
If the user still comes back, contact SalesScreen Support and include:
Company name
Name and email address of the user
Source system, for example Azure AD, Okta, CRM or API
The Azure AD group, Okta assignment or source list the user belonged to
When the user was deactivated
When the user became active again
Whether the user is active, inactive or pending
Steps you have already tried
