Overview
Just-in-Time (JIT) provisioning allows Valimail to automatically create user accounts the first time a user successfully authenticates through a configured Identity Provider (IdP). This eliminates the need for manual user creation and helps streamline user onboarding and access management.
With JIT provisioning enabled, users are provisioned dynamically during the Single Sign-On (SSO) login process, ensuring that authorized users can access Valimail immediately without prior administrative setup.
Prerequisites
Before enabling JIT provisioning, ensure the following requirements are met:
SAML-based SSO is already configured and functioning correctly
Users can successfully authenticate through the organization’s Identity Provider
Required user attributes are included in the SAML assertion (FirstName, LastName, and EmailAddress are required)
Steps to Enable JIT Provisioning
Log in to your Valimail account.
Go to Account Settings.
Click Edit Settings on the Single Sign-On tile.
Check the Just in Time provisioning (JIT) box.
Provision up to 3 domains, then click Save at the bottom.
Domain Requirements
JIT provisioning supports up to three email domains. These domains are validated against the user’s email address provided by the Identity Provider during authentication.
The corresponding domains must already exist within the Valimail account configuration before being added to the JIT configuration.
If a user attempts to authenticate with an email domain that has not been added to the Valimail account, JIT provisioning will fail, and the user account will not be created.



