This article explains how to move Happeo's user and group syncing from one identity provider to another, so your intranet stays accurate when your organization changes how it manages identity.
🎯 Who this article is for: This article is for admins managing a change in identity provider, such as moving from Google Workspace to Microsoft Entra ID, or introducing Okta.
🔒 Permissions: Switching a provisioning source is carried out by an admin, working with Happeo Support.
1. Overview
Happeo keeps your users and groups current automatically by syncing them from an identity provider (IdP), such as Google Workspace, Microsoft Entra ID, or Okta. When your organization changes which IdP it relies on, Happeo needs to follow along. Switching your provisioning source is how that happens: it moves the sync from your old provider to your new one, so the people and groups in your intranet keep matching the people and groups in your organization.
This is separate from content migration, which covers moving files, folders, and widgets, such as a Google Drive or SharePoint file list, that are embedded in your pages and channels. Content migration is a manual process your own team carries out, if and when needed.
2. Use cases
- Consolidating identity after a company-wide platform move: When an organization moves from Google Workspace to Microsoft 365, every connected tool needs to follow, not just email and files. Switching Happeo's provisioning source to Microsoft Entra ID keeps users, roles, and groups accurate without anyone re-entering the same information twice.
- Introducing single sign-on for the first time: As an organization grows, IT often consolidates logins under a dedicated identity provider like Okta instead of managing access tool by tool. Pointing Happeo's provisioning at Okta means access reflects the same source of truth the rest of the organization already relies on.
- Bringing identity in line with HR, not IT: Some organizations decide employee data should flow from the HR system where it's entered once, rather than from a general identity provider. Switching to an HR system connected via Merge means Happeo always reflects who is actually employed, without a separate list to maintain.
3. Before you begin
- Happeo supports switching your provisioning source between Okta, Google Workspace, Microsoft Entra ID, and an HR system connected via Merge (covering BambooHR, Workday, Deel, Rippling, and other supported platforms). The same overall process applies whichever of these you're moving from and to.
Important: A user's primary email address must stay exactly the same in both the old and new identity provider for Happeo to carry them over. If an email address changes as part of the switch, Happeo treats that person as a new account, and the old account can then only be deleted, not merged or migrated.
- Groups are not migrated between providers. Once your new source is enabled, new groups sync in from it, while your existing groups remain in place until you're ready to remove them, so access to channels, page groups, and custom apps isn't lost while you make the switch.
- You'll need to manually update sharing settings to reference the new groups once they've synced in, and you can ask Happeo Support to remove the old groups once you're happy that access is fully set up.
Note: While the switch is in progress, expect a few temporary changes:
- Users will appear as invited rather than provisioned until the new source is active.
- Synced profile data, such as job title and manager, may briefly disappear before it's restored from the new provider.
- Users may need to reconfigure some personal integration settings.
- Draft posts saved before the switch won't be visible to users afterward.
- An HR system connected via Merge works a little differently once set up: it's a one-time, permanent connection rather than something you switch into or out of later. If you're planning to connect an HR system, review the full setup details first in Set Up Provisioning from Your HR System (via Merge).
4. How to switch your provisioning source
To begin, contact Happeo Support with your organization details, which provider you're moving from and to, whether email addresses will change, and your target timeline. Support will confirm the expected timeline for your specific combination and guide you through each step below.
- Export your existing groups. In Happeo, go to Admin Settings → Groups Management → Export and download all existing groups. Having this list on hand makes it easier to recreate similar groups in your new provider.
- (Optional): Review your login page. If your login buttons need to change as part of the switch, update your login page setup. Multiple login methods can stay enabled at the same time during the migration period, so this step is optional and doesn't need to happen right away.
- Disable your old provisioning integration. In Admin Settings → Integrations, turn off the old integration and let Happeo know. Then wait until Happeo has converted your existing synced users to invited users. Google Workspace integration can't be disabled manually. Happeo disables it for you as part of the next step.
- Happeo converts your synced users to invited users. This step is carried out by Happeo. If your previous source was Google Workspace, this also stops Google sync.
- Enable your new provisioning source. Follow the relevant setup guide for Google Workspace, Microsoft Entra ID, or Okta. This is also a good moment to enable any other integrations you'll need going forward, such as Outlook, OneDrive, or SharePoint.
- Add your new groups once they've synced in. New groups typically appear within about an hour. Once they do, add them to your channels, page groups, and custom apps. You can keep your old groups in place until you're happy with access, and reconfigure a custom login page if needed.
- Request removal of your old groups. Once sharing settings are fully updated on your new groups, ask Happeo Support to remove the groups synced from your old source.
- Happeo deletes the old groups. This step is carried out by Happeo, completing the switch.
Typical timeline
- Initial assessment and information gathering: Around 1 week.
- Switching the provisioning source itself: Around 1 week, as little as a couple of days if setup steps are completed promptly.
- Content migration, if applicable: On your own timeline.
- Legacy group cleanup: Around 1 week once you confirm you're ready.
5. Frequently asked questions
Will employees lose the ability to log in while the switch is happening?
No. Multiple login methods can stay enabled at the same time during the migration period, so employees can continue signing in even while your login page setup is being reviewed.
Do I need Merge if I'm only moving between Okta, Google Workspace, and Microsoft Entra ID?
No. Merge is only relevant if one side of your migration is an HR system. Moving directly between Okta, Google Workspace, and Microsoft Entra ID doesn't involve Merge at all.
Can a migration be paused or reversed partway through, for example after the old provisioning source is disabled but before the new one is enabled?
No. Once the old provisioning integration is disabled, that step can't be undone. If you need to stop before the new source is enabled, a new integration has to be configured from scratch rather than resuming from where you left off.
What happens to a user who exists in Happeo today but isn't present at all in the new provider?
They stay as an invited user rather than becoming provisioned again. When the old source is disabled, every synced account is converted to invited. Once the new source is enabled, those accounts are overwritten with the matching data from your new provider, except for any user whose record no longer exists there. Since there's nothing to sync them from, they remain invited instead of being carried over.
6. Troubleshooting
Profile data like job title or manager hasn't come back after the new source started syncing
Happeo only restores synced profile fields that exist in your new provider. If a field, such as manager relationship, isn't tracked there, it won't repopulate automatically even after syncing is active.
A channel, page group, or custom app still shows "deleted-group" after cleanup
This appears once your old groups have been removed and a reference to one remains somewhere it was shared. Remove these references manually wherever you see them.