---
name: azion-provision-microsoft-entra-users-with-scim
description: >-
  Turn on SCIM for a Microsoft Entra identity provider, so Entra creates, updates, and deletes the users and teams of your Azion account.
---

# Provision Microsoft Entra users with SCIM

You can let Microsoft Entra ID create, update, and delete the users and teams of your Azion account through **Automated User Provisioning**, which runs on the System for Cross-domain Identity Management (SCIM) protocol. You turn on SCIM with the Azion API and then configure provisioning in the Microsoft Entra admin center. To set up Microsoft Entra as the identity provider first, refer to [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml/).

---

## Prerequisites

- An account with **Enterprise** or **Mission-Critical** support.
- Microsoft Entra configured as the identity provider (IdP) of the account, active and linked to the right SAML application. Refer to [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml/).
- An Azion personal token. To create one, refer to [Manage personal tokens](/en/documentation/guides/platform/account-and-billing/personal-tokens/).
- A terminal with `curl`, or an API client such as Postman or Swagger.

---

## Turn on the SCIM integration

Three requests find the identifier of the IdP, read its SCIM status, and turn SCIM on. In each one, replace `[Token value]` with your personal token.

To find the IdP identifier, send a `GET` request to the identity providers endpoint:

```bash
curl --location 'https://api.azionapi.net/iam/identity_providers' \
--header 'Accept: application/json' \
--header 'Authorization: Token [Token value]'
```

The response is similar to this:

```json
{
  "name": "Microsoft Entra IdP",
  "is_active": true,
  "protocol": "SAML",
  "uuid": "1234abc4567",
  "login_url": "https://api.azion.com/v4/users/scim/<idp_uuid>/login",
  "scim_integration": false,
  "scim_url": null
}
```

`is_active` confirms whether the IdP is active, and `uuid` is the identifier of the IdP in Azion. Copy the `uuid` for the next requests.

To read the SAML details of the IdP, send a `GET` request with the `uuid` in place of `<uuid>`:

```bash
curl --location 'https://api.azionapi.net/iam/identity_providers/saml2/<uuid>' \
--header 'Accept: application/json' \
--header 'Authorization: Token [Token value]'
```

The response is similar to this:

```json
{
  "uuid": "1234abc4567",
  "name": "Microsoft Entra IdP",
  "is_active": true,
  "sign_in_url": "https://login.microsoftonline/123abc/saml2",
  "entity_id_url": "https://sts.windows.net/123abc/saml2",
  "login_url": "https://sso.azion.com/api/saml2v4/users/scim/<idp_uuid>/login",
  "acs_url": "https://sso.azion.com/api/saml2v4/users/scim/<idp_uuid>/login",
  "signature_algorithm": "sha-256",
  "scim_integration": false,
  "scim_url": null
}
```

`scim_integration` holds the status of the SCIM protocol for the IdP. A `false` value means SCIM is off.

To turn SCIM on, send a `PATCH` request with the `uuid` in place of `<uuid>`:

```bash
curl --location --request PATCH 'https://api.azionapi.net/iam/identity_providers/saml2/<uuid>' \
--header 'Accept: application/json' \
--header 'Authorization: Token [Token value]' \
--data '{
    "scim_integration": true
}'
```

The response is similar to this:

```json
{
  "uuid": "1234abc4567",
  "name": "Microsoft Entra IdP",
  "is_active": true,
  "sign_in_url": "https://login.microsoftonline/123abc/saml2",
  "entity_id_url": "https://sts.windows.net/123abc/saml2",
  "login_url": "https://sso.azion.com/api/saml2v4/users/scim/<idp_uuid>/login",
  "acs_url": "https://sso.azion.com/api/saml2v4/users/scim/<idp_uuid>/login",
  "signature_algorithm": "sha-256",
  "scim_integration": true,
  "scim_url": "https://api.azion.com/v4/users/scim/<idp_uuid>/Users"
}
```

SCIM is on for the IdP. Copy the `scim_url` value for Microsoft Entra.

---

## Turn on provisioning in Microsoft Entra

Microsoft Entra connects to Azion through the `scim_url` and a token with the right permissions.

To turn on provisioning in the Microsoft Entra admin center:

1. Go to the [Microsoft Entra admin center](https://entra.microsoft.com/).
2. Select the card of the application that makes Microsoft Entra the IdP for Azion.
3. In the menu, in the **Manage** section, select **Provisioning**.
4. In **Provisioning mode**, select *Automatic*.
5. In the **Admin Credentials** section, paste the `scim_url` value in **Tenant URL**.
6. In **Secret Token**, enter a personal token of the Account owner, or of a user with SCIM integration permissions.
7. Select **Test Connection**. A message confirms that the test succeeded.
8. Select **Save**.

Provisioning is on. Next, map the users and the groups to provision.

> **Note**
>
> You can provision users alone. Each user is then created with no group, and you assign groups and permissions in Azion yourself. When you provision groups, every user in each group is provisioned, and you set the group permissions in Azion afterward.

---

## Map users

Azion does not support the **Enterprise** schema of Microsoft Entra, so always keep the default user schema. Keep only four attributes, so the user data in Microsoft Entra and in Azion stay aligned.

To map users on the Provisioning configuration page:

1. Open the **Mappings** section.
2. Select **Provision Microsoft Entra ID Users**.
3. In **Attribute Mappings**, keep **userName**, **active**, **name.givenName**, and **name.familyName**.
4. Delete every other attribute.
5. Make sure the **Enable** switch is on *Yes*.
6. Select **Save**.

Microsoft Entra sends only the four mapped attributes to Azion.

---

## Map groups

A group in Microsoft Entra becomes a team in Azion. Without group mapping, users are created with no group and no specific permissions, and they reach only unrestricted activities and features.

To map groups on the Provisioning configuration page:

1. Open the **Mappings** section.
2. Select **Provision Microsoft Entra ID Groups**.
3. Make sure the **Enable** switch is on *Yes*.
4. Select **Save**.

Microsoft Entra provisions groups as Azion teams.

---

## Provision users

Microsoft Entra runs a provisioning cycle every *40 minutes*, a fixed interval. A user who becomes **Account owner** stops authenticating through Microsoft Entra and follows the SSO rules configured in Azion. A change in the IdP then cannot lock that user out.

To check the provisioning cycle:

1. Go to the [Microsoft Entra admin center](https://entra.microsoft.com/).
2. Select the card of the application that makes Microsoft Entra the IdP for Azion.
3. In the menu, select **Overview**.

The **Overview** shows the provisioning details and the default settings of the cycle.

---

## Provision a user on demand

To skip the wait for the next cycle, provision a user or a group by hand.

To provision on demand on the Provisioning configuration page:

1. In the menu, select **Provision on demand**.
2. Select the user or group to provision.
3. Select **Provision**.

Microsoft Entra provisions the selected user or group outside the regular cycle.

---

## Check the users in Azion Console

To check the provisioned users:

1. **Open Users Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **Users Management**.

2. **Find the provisioned users**

   Look for the provisioned users in the **Users Management** list.

The list shows the users that Microsoft Entra provisioned.

---

## Next steps

- [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml.md): Set up or review the Microsoft Entra identity provider.
- [Manage teams permissions](/en/documentation/guides/platform/account-and-billing/teams-permissions.md): Set the permissions of the teams that Microsoft Entra provisions.
- [Manage users](/en/documentation/guides/platform/account-and-billing/users-management.md): Review and edit the provisioned users in Azion Console.
- [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso.md): Add any SAML or Open ID provider in SSO Management.
