Tessian
Connect Tessian (now part of Proofpoint) to Ploy to automatically discover the users Tessian protects, the groups configured in your Tessian portal, and which users belong to each group. Once connected, Ploy keeps this picture up to date on a regular scan schedule, and can also add users to or remove users from Tessian groups when you ask it to.
What Ploy syncs from Tessian
Users — every user account Tessian is monitoring, including their email address, whether the account is currently live or blocked, when the account was created, and when it last connected.
Groups — each group in your Tessian portal appears in Ploy as a resource.
Group membership — which users are members of which group, so you can see and review group access in Ploy.
What Ploy can change in Tessian
Add a user to a Tessian group.
Remove a user from a Tessian group.
These actions can be triggered from Ploy, for example as part of access requests or offboarding.
Prerequisites
Administrator access to your Proofpoint (Tessian) portal, so you can create an API token.
Your portal subdomain — the first part of the address you use to open the portal. For example, if you sign in at
acme.tessian-platform.com, your subdomain isacme.Knowing which region your instance is hosted in. EU instances live on
tessian-platform.comand US instances live ontessian-app.com.
Step 1 — Create an API token
Sign in to your Proofpoint (Tessian) portal as an administrator.
Open the portal's API or integrations settings and create a new API token.
Make sure the token is granted the Security Events and Integrations permissions — Ploy needs these to read users and groups and to manage group membership.
Copy the token somewhere safe. You will paste it into Ploy in the next step.
Step 2 — Connect Tessian in Ploy
In Ploy, go to Integrations, find Tessian and click to connect.
Select your region — choose EU (Europe) or US (United States), matching where your Tessian/Proofpoint instance is hosted. This is required.
Enter your subdomain — for example,
acmefromacme.tessian-platform.com. This is required.Continue to the next page.
Enter your API Token here — paste the API token you created in Step 1. This is required.
Finish the setup. Ploy tests the connection by calling Tessian's health endpoint, and the first scan starts shortly after.
Updating the API token
If you rotate or replace your API token, open the Tessian integration in Ploy and go through the setup again. The existing token is kept unless you paste a new one, and your region and subdomain are remembered.
Troubleshooting
Failed to authenticate with Tessian — the connection test could not reach or sign in to your Tessian instance. Check that the region and subdomain match your portal address exactly, and that the API token was pasted in full.
Tessian authentication failed - check API key — a scan could not authenticate. This usually means the API token has been revoked or has expired since you connected. Create a new token in the Proofpoint portal and update it in Ploy.
Users or groups are missing — make sure the API token has the Security Events and Integrations permissions. A token without the right permissions may connect but not return complete data.