Merging brings together two duplicate profiles of the same person into one. Email addresses, groups, course progress, Karma, reports and activity history are transferred onto the profile you keep.
1️⃣ When to merge
Merging is for cases where the same person appears twice in your workspace. Two situations come up regularly:
an email address change created a second profile instead of updating the first;
a CSV import recreated someone who was already there.
⚠️ Important: if the two profiles belong to two different people, do not merge. Delete the incorrect profile instead. Merging cannot be undone.
2️⃣ Choosing which one to keep
Merging only goes one way. You designate:
a profile to keep, onto which all data is transferred;
a profile to be deleted once the operation completes.
💡 The rule of thumb: keep the profile that matches the employee's current identity in your directory — their Google, Microsoft, Okta or Slack account. The profile to delete is the outdated duplicate.
3️⃣ How to proceed
👉 Step 1: Open the profile you want to delete.
👉 Step 2: From the ⋯ menu, choose Merge profile [À VÉRIFIER : exact label of the menu entry in the English UI].
👉 Step 3: Select the profile you want to keep.
👉 Step 4: Confirm.
The merge runs as a single operation: either everything is transferred, or nothing is. There is no half-finished state to clean up.
4️⃣ What gets transferred
Essentially everything moves onto the profile you keep: work email addresses, group memberships, current and upcoming course enrolments, phishing reports, Karma events, training feedback, Inbox reports and quarantines, Sonar data, and Simulation campaign targeting. Duplicates are merged rather than doubled up.
Four behaviours are worth your attention.
A course already in progress on both sides. If the profile you keep already has an enrolment in progress on the same course, the copy from the deleted profile is marked as missed.
Personal email addresses are transferred but revert to unverified: the employee will need to verify them again.
Work addresses keep their value, but lose their primary-address status if they were not already primary on the profile you keep.
Directory identifiers and authentication records from the profile you keep take precedence: those from the deleted profile are only carried over if there were none.
👍 Good to know: an audit record of the merge is kept, with the names of both profiles involved.
5️⃣ When the merge is refused
Five situations block the operation. In each case, there is something to do before trying again.
👉 One of the profiles is provisioned through SCIM
A profile provisioned through SCIM cannot be merged: your identity provider would recreate it at the next synchronisation. Remove SCIM provisioning for that employee on the identity provider side, or handle the duplicate from there. See How to use the Microsoft Entra SCIM provisioning service.
👉 Both profiles are linked to the same provider
For example, both profiles are linked to a Google account, or both to an Okta account. Merging would mean arbitrarily dropping one of the two links. Delete or merge the duplicate in your directory so that only one profile remains linked to that provider, then try again.
👉 The profile to delete is also an administrator account
Swap the roles: merge into the administrator profile, not the other way round. If that isn't possible, remove the administrator account first, then merge.
👉 The two profiles are in different workspaces
Merging only works within a single workspace.
👉 You selected the same profile twice
Refresh the page and select again.
6️⃣ Right after the merge
The source profile no longer exists.
Karma is recalculated on the profile you kept, within a few seconds.
Course due dates are recalculated.
Personal email addresses carried over need to be verified again by the employee.
Key takeaways
Merging is for duplicates of the same person, never for two distinct people.
Keep the profile that matches the current identity in your directory.
Start the merge from the profile you want to delete.
SCIM, a double link to the same provider, or an administrator account on the source side will block the operation.
