Connect 3CX to Corma to remove extensions, direct numbers and admin roles when people leave, and keep your phone system in step with HR records.
The Corma integration for 3CX connects your phone system to the same joiner, mover and leaver workflows as the rest of your SaaS stack, so extensions, direct numbers and admin roles follow the HR record instead of a ticket queue. It is built for IT teams that run 3CX in the cloud or self-hosted and want one view of who can call, answer and listen to recordings.
Key takeaways
In 3CX, a user is an extension. Each one is created with an extension number, an email address, a department, a role and often one or more DIDs (direct inward dialing numbers). System-wide rights sit with two roles, System Owner and System Administrator, while department roles range from User and Receptionist up to Manager and Owner.
3CX can import users from Microsoft 365 or Google Workspace, but the sync is one-way and runs nightly. No SCIM endpoint is documented, and the configuration API (XAPI) is only included in the AI edition from 8 simultaneous calls.
Because licensing is not per user, nobody chases unused seats, and extensions quietly pile up. The sync rules add to it: an account disabled in Microsoft 365 stays active in 3CX, and an extension deleted only in 3CX comes back after the next nightly sync while its source account still exists. On Google Workspace, a suspended user leaves a disabled extension behind rather than a deleted one.
The result is a stock of orphaned accounts that still hold DIDs and call permissions, exactly what an ISO 27001 or NIS2 auditor will ask you to explain.
3CX documents no SCIM support. Users come from the Microsoft 365 or Google Workspace sync, the admin console or the XAPI. For the general method, see our guide to offboarding apps that don't support SCIM, SAML or SSO.
Yes. Where the XAPI is not available, Corma's AI agents carry out admin console steps in an isolated browser session, using credentials from your own vault, with a video replay and a step log for every run.
Corma runs on AWS data centres inside the European Union, encrypts data in transit and at rest, and is ISO/IEC 27001:2022 certified.
Running 3CX next to Microsoft 365 or Google Workspace? Book a demo and we will map your leaver process on your own stack.
Check out other integrations that could help you on managing your software licences and accesses!