---
title: Manage ID provider users
description: Use IBM Cloud Identity Access Management (IAM) to manage users with or without an IBM Cloud account
source: https://eu-de.quantum.cloud.ibm.com/docs/en/guides/manage-appid
---

# Manage ID provider users

You can integrate with your external identity provider (IDP) to securely authenticate external users to your IBM Cloud account. By using an external provider, you can provide a way for users in your company to use single sign-on (SSO). You can connect your cloud account to an external IDP one of the following ways:

- Use the [IBM Cloud® SAML service provider (SP)](https://cloud.ibm.com/docs/account?topic=account-ibm-idp-integration#federate-cloud-saml)
- Use [App ID](https://cloud.ibm.com/docs/account?topic=account-ibm-idp-integration#federate-appid) (might incur a cost)
- [Federate your users to all IBM® products with IBMid](https://cloud.ibm.com/docs/account?topic=account-ibm-idp-integration#federate-ibmid)

> **Tip**
>
> After connecting your IDP, you can set up dynamic rules so you don't have to manually add every user to every group when they join.  See [Enabling authentication from an external identity provider](https://cloud.ibm.com/docs/account?topic=account-ibm-idp-integration#app-id-dynamic-rules) for instructions.

## Next steps

> **Recommendations**
>
> - Refer to the [Enabling authentication from an external identity provider](https://cloud.ibm.com/docs/account?topic=account-ibm-idp-integration) topic.
> - See [IBM Cloud SAML Federation Guide](https://www.ibm.com/products/tutorials/ibm-cloud-saml-federation-guide) for more information.
> - Refer to the full [App ID documentation](https://cloud.ibm.com/docs/appid?topic=appid-getting-started).
