Connecting Integration
Rippling brings HR, IT, and Finance into one system so you can manage payroll, benefits, devices, and the rest of the employee lifecycle in one place.
To connect Rippling:
Go to Integrations and open the Available tab.
Search for Rippling. (If you have Custom Integrations, click Add native connection.)
Click Connect and complete the steps in Rippling.
Return to Secureframe and confirm the connection under Integrations.
Note: If connect opens Rippling but Secureframe never finishes connecting, open IT → Third-Party Access (or App Shop → Secureframe), confirm the Secureframe app / third-party access entitlement is enabled, then reconnect from Secureframe.
Permissions, Fields Pulled, Controls, and Automated Tests
Click the provided link or navigate to the Integrations page.
Select the Available tab.
Search for the integration.
Click View Details.
Frequently Asked Questions (FAQ)
Important: Secureframe no longer retrieves user roles or MFA status from Rippling. All other supported Rippling user data continues to sync.
Will Rippling “Core” subscription work as an integration with Secureframe?
No. Secureframe needs Rippling’s IT add-on that exposes third-party app APIs. In Rippling this is under IT → Third-Party Access (Rippling may still label the purchase flow as Identity / third-party access). It is not included in basic Core. Without that add-on, connect usually drops you back on the Rippling home page instead of completing OAuth.
Connect opens Rippling, but Secureframe never connects. What should I do?
This can happen when the connection link lands on the Rippling home page instead of the Secureframe app install flow.
In Rippling, open the App Shop, search for Secureframe, and install the Secureframe app.
Return to Secureframe and confirm Rippling appears as connected under Integrations.
Does Secureframe sync user roles and MFA status from Rippling?
No. Rippling discontinued the SOC 2 reports API that Secureframe previously used for those fields.
Secureframe still syncs other Rippling user data. User roles and MFA status are no longer available from this integration.
Why don't password policy or firewall statuses appear for devices synced from Rippling MDM?
Secureframe pulls device fields from Rippling through its Third-Party Access APIs. If password policy or firewall do not appear, it usually means those settings are not being enforced by a Rippling device profile, or Rippling is not exposing that field for that operating system.
Confirm a Rippling device policy actually enforces password, screen lock, and firewall, then run a manual sync. For anything Rippling does not report, enforce it with a Rippling configuration profile, use the Secureframe Agent on those devices, or upload manual evidence.
Rippling stays Disconnected after I reconnect, and I never see an OAuth authorization prompt. How do I fix it?
This usually means the prior OAuth connection is stuck. A normal reconnect from Secureframe is not enough.
In Secureframe, archive the existing Rippling connection.
In Rippling, uninstall the Secureframe app.
In Secureframe, add Rippling again and complete the OAuth prompt when it appears.
Rippling Identity & Access Management is required for this connection path. Confirm that plan is enabled in Rippling before reconnecting.
If the OAuth prompt still does not appear after archive, uninstall, and reconnect, contact [email protected] with screenshots of the Rippling connection status in Secureframe.
Why did Rippling monitors show up as devices in Asset Inventory?
Secureframe updated how Rippling inventory is classified so monitors are not added as devices in Asset Inventory.
After the next Rippling sync, review Asset Inventory
Can I sync only one Rippling department, location, or legal entity?
Not on the Rippling connection today. Rippling may send department and related fields, but Secureframe does not offer department, location, legal entity, or group include/exclude on that connection. Customer-controlled scoping is email domain and/or integration conditions under Personnel filtering. If two entities share one Rippling tenant and the same email domains, email filters alone may not separate them cleanly.
and remove any leftover monitor rows if they still appear from earlier syncs.
