What is cloud repair with Assist?
Cloud actions are fixes Assist makes in your cloud systems rather than on the computer, such as resetting a password or MFA in Microsoft Entra ID or Okta. The employee describes the issue, such as “I’m locked out of Okta”, and Assist checks the account to confirm the cause, shows exactly what it will change, and waits for approval. It then makes the change through your connected identity provider, confirms it worked, and records the run as a ticket.Cloud repair only ever act on the signed-in employee’s own account, so identity resolution must be set up.
Cloud skills and tools
Each cloud action follows a skill, a playbook for one type of problem. Its tools, such asc_okta_unlock_account or c_entra_reset_mfa, reach your identity provider through the idemeum cloud gateway.
Some skill examples:
- entra-password-reset - resets a forgotten Microsoft Entra password and emails a temporary one to the employee’s recovery address, which also clears a sign-in lockout
- entra-mfa-reset - clears the employee’s Entra MFA methods, such as after a lost phone, so they can set MFA up again at next sign-in
- okta-password-reset - resets a forgotten Okta password and emails a temporary one to the employee’s recovery address
- okta-mfa-reset - clears the employee’s Okta authenticators so they can enroll again at next sign-in
- okta-account-unlock - unlocks an Okta account locked after too many failed sign-in attempts
Skill and tool library
Browse every skill and tool in our library.
Ticketing integrations
Once your ticketing system is connected, Assist sends a ticket to it after every run. Each run is also recorded in the idemeum admin portal with its full audit trail and context. Learn more about tickets and runs, or see the integration guides.Set up Assist cloud actions
- Log in to the idemeum admin portal, go to Agents → Skills, and check that the cloud skills you want are enabled.
- Go to Agents → Connectors, connect Microsoft Entra ID or Okta, and select Use as identity provider. See Identity resolution.
- In Agents → Connectors, connect your ticketing system and, optionally, Intune or Jamf. See Integrations.
- Install the Assist app on macOS and Windows devices, using your usual deployment tool.
- On a test device, sign in as a test employee, ask Assist to “reset my password”, and approve the change. Check that the temporary password reaches the recovery address and the run appears in the admin portal.
