Ai News
Ai News

OpenAI Centralizes Enterprise Identity and SCIM Management in Admin Console

Published Aug 27, 2026 Sources checked Aug 28, 2026

OpenAI's August 27 Enterprise and Edu update adds centralized tenant-wide SCIM plus member, group, role, permission and supported Ads-account administration in Admin Console.

OpenAI moves more enterprise identity controls into Admin Console

OpenAI published an August 27, 2026 update for eligible ChatGPT Enterprise and Edu customers that centralizes more identity and workspace administration in its Admin Console. The change is available now for eligible customers rather than being described as a future preview.

The most consequential addition is centralized, tenant-wide SCIM provisioning. Administrators can sync users and groups once at the tenant level and then assign those groups to supported ChatGPT workspaces or Ads accounts. OpenAI says existing workspace-level SCIM configurations remain supported, so organizations are not being forced to replace an existing setup immediately.

What administrators can manage centrally

According to OpenAI's Enterprise and Edu release notes, the Admin Console can now be used to manage workspace members, groups, roles, permissions and general settings. For Ads accounts where the capability is available, administrators can also manage users and roles from the same broader administrative environment.

For organizations with several ChatGPT workspaces, the tenant-wide SCIM option is important because identity synchronization no longer has to be conceived only as a separate workspace-by-workspace configuration. A centralized directory sync can become the common source for user and group provisioning, while supported workspaces can receive assignments from that tenant-level structure.

This does not mean every organization should immediately remove its current workspace SCIM configuration. OpenAI explicitly states that existing workspace-level SCIM remains supported. Teams should therefore treat the new tenant-wide approach as an additional centralized administration path and review migration or consolidation plans against their own identity-provider, access-control and change-management requirements.

Why the change matters for AI governance

Enterprise AI deployments increasingly involve more than model access. Organizations need to control who can use agentic tools, connected applications, workspace data and administrative functions. Identity groups and role assignments are a practical enforcement layer for those controls.

Centralizing users, groups, roles and permissions can make it easier for security and IT teams to align ChatGPT access with an organization's existing identity lifecycle. When a person's directory status or group membership changes, SCIM-based provisioning can help keep supported AI workspaces aligned with the same authoritative identity source instead of relying on disconnected manual administration.

The update also fits OpenAI's broader 2026 expansion of enterprise administration. Earlier August release notes added workspace-scoped Admin APIs, clearer tenant and workspace context in the Global Admin Console, audit-log access, additive role-based access controls, Codex service accounts and other governance features. The August 27 change specifically advances the identity-management layer by adding centralized tenant-wide synchronization and assignment.

What enterprise teams should check

Before changing an existing provisioning design, administrators should verify whether their organization is eligible for the centralized controls, which ChatGPT workspaces or Ads accounts are supported, and how their current identity-provider groups map to intended roles and permissions. Teams should also document who owns tenant-level administration because a centralized configuration can affect multiple workspaces.

Security teams should continue applying least-privilege principles to administrative roles and test provisioning changes before broad rollout. The release notes establish the new management capabilities, but they do not imply that SCIM by itself replaces an organization's access reviews, offboarding controls, audit processes or other governance requirements.

For enterprise AI platform teams, the practical takeaway is straightforward: OpenAI has shipped a more centralized identity-management model for eligible Enterprise and Edu environments, while preserving compatibility with existing workspace-level SCIM setups.

Sources

This article is built from the source material below. Open the originals for full context and the latest updates.

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books