REMIRA Mirrors Nearly 900 Entra ID Groups Into Files.com While Provisioning Just a Few Dozen Accounts
REMIRA is one of Europe's leading providers of supply chain and omnichannel commerce software, covering the path from demand planning and purchasing through warehousing to the point of sale for retail, logistics, and industrial companies. Much of that software runs installed in its customers' own environments, and REMIRA does not just ship it. For 400–600 installed ERP and POS sites, support routinely means pulling a customer's own database backup into REMIRA's environment for debugging and analysis.
That makes REMIRA's file exchange platform the place where its customers' production data sits while REMIRA works on it, held in Frankfurt to meet German data residency requirements. Which REMIRA employee can reach which customer's data is a serious governance question. On the legacy exchange stack, that question was answered entirely by hand: no central user management, every account and every permission created and maintained manually, with no connection to the corporate directory that already defined exactly who belonged to which team.
A Directory With Nearly 900 Groups and a File Platform That Ignored It
REMIRA's Entra ID directory describes the company in detail, in nearly 900 groups. The legacy file exchange knew none of it. Every grant was a manual task. Every revocation was something an administrator had to remember. The authoritative answer to who could reach a customer's data lived in a file platform's own settings rather than in the directory of record, and keeping the two aligned was nobody's job in particular. The diagnosis was simple: the directory and the file platform did not speak.
Every Group as a Permission, Almost No One as a User
The obvious fix, syncing the directory into the platform, collided with least privilege. Folder permissions only meant something company-wide if every group existed on the platform: a rule like "development can reach this folder" needed a development group to point at. But most members of those groups had no business holding an account on a platform full of customer databases. A team of twenty might contain five people who actually needed to touch it. Directory integrations ordinarily treated the two questions as one decision, where assigning a group to an application turned its members into users. REMIRA needed the opposite: the whole group structure available for authorization, while a single deliberate decision controlled who received an account.
As REMIRA retired its legacy exchange stack, it refused to rebuild hand-managed access on whatever came next. The replacement had to mirror every Entra ID group as a permission object, create accounts only for a controlled population, and take every grant and revocation from the directory rather than from an administrator's to-do list. REMIRA selected Files.com as its customer file exchange platform and led the deployment with identity: before the first customer workflow moved, folder access had to answer to Entra ID.
One Group for Provisioning, Every Other Group for Authorization
Files.com became the point where the directory's authority over file access is enforced. The company's group structure became the permission model without ever becoming the user list.
Files.com's SCIM provisioning supported scope filtering, and REMIRA initially used it to split provisioning from authorization. One designated Entra ID group controlled provisioning: membership there, and only there, created a Files.com account. More than 880 of the nearly 900 groups in the directory synced into Files.com purely as authorization objects, with no accounts riding along. Folder permissions were assigned to those department groups, so a folder grant was a statement about a team, whether or not every member of that team existed on the platform. The initial identity architecture, at more than 800 synced groups, went from a standing start to production in about three months.
For the users who do exist, sign-in runs through Entra ID single sign-on, with per-user two-factor authentication and session lifetimes cut to a single day. That posture fits a staff that regularly logs in from customer premises. REMIRA later consolidated the design onto a single Files.com integration that reads users and group memberships from its directory over LDAP while Entra ID continues to handle authentication, with on-demand syncs keeping memberships current.
Access Granted in Entra ID, Enforced by Files.com
With that architecture in production, REMIRA replaced hand-administered access with access inherited from the directory.
- Granting or revoking access is a group change in Entra ID. Nobody creates accounts, edits permissions, or remembers revocations by hand on the platform, and a person removed in the directory loses their Files.com access along with everything else.
- The account population stays deliberately small, a few dozen people on a platform holding customer production databases, while every department in the company remains available as a permission boundary.
The compounding result is that the model maintains itself. A new team or a reorganization arrives from the directory on the next sync, and extending governance to it means granting a folder to a group that is already there.
Governed by the Directory, Not by Memory
Today, the answer to who at REMIRA can reach a customer's data is the same as the answer to what team they are on. It used to live in a file platform's hand-maintained settings: an account someone created, permissions someone set, access someone had to remember to take away. Now Files.com enforces what Entra ID declares, and REMIRA's IT team governs file access by maintaining the directory, which it was doing anyway. The lesson in REMIRA's architecture is that directory-governed file exchange never required provisioning the directory. Mirror every group for authorization, and let one group decide who exists at all.
Related Customer Stories
Software & Technology
GoDaddy Registry Replaces Its Amazon EC2 SFTP Server With Self-Service Zone File Distribution on Files.com
The registry separated vetting and entitlement from account creation, giving hundreds of approved outsiders self-service access without putting them in GoDaddy's identity systems.
Read story →
Software & Technology
Zillow Retires Ombud for Files.com to Send KYC Documents Across Six Countries
Browser-based links let recipients Zillow could not train securely view or download each sensitive document according to its own retention requirements.
Read story →
Software & Technology
Redis Gives Every Support Ticket Its Own HTTPS or SFTP Intake Route With Files.com
API-driven, write-only intake lets customers deliver diagnostics through their firewalls while Redis keeps no standing credentials for external uploaders.
Read story →