Provision Microsoft Entra users with SCIM
Turn on SCIM for a Microsoft Entra identity provider, so Entra creates, updates, and deletes the users and teams of your Azion account.
You can let Microsoft Entra ID create, update, and delete the users and teams of your Azion account through Automated User Provisioning, which runs on the System for Cross-domain Identity Management (SCIM) protocol. You turn on SCIM with the Azion API and then configure provisioning in the Microsoft Entra admin center. To set up Microsoft Entra as the identity provider first, refer to Configure Microsoft Entra SAML for SSO.
Prerequisites
- An account with Enterprise or Mission-Critical support.
- Microsoft Entra configured as the identity provider (IdP) of the account, active and linked to the right SAML application. Refer to Configure Microsoft Entra SAML for SSO.
- An Azion personal token. To create one, refer to Manage personal tokens.
- A terminal with
curl, or an API client such as Postman or Swagger.
Turn on the SCIM integration
Three requests find the identifier of the IdP, read its SCIM status, and turn SCIM on. In each one, replace [Token value] with your personal token.
To find the IdP identifier, send a GET request to the identity providers endpoint:
The response is similar to this:
is_active confirms whether the IdP is active, and uuid is the identifier of the IdP in Azion. Copy the uuid for the next requests.
To read the SAML details of the IdP, send a GET request with the uuid in place of <uuid>:
The response is similar to this:
scim_integration holds the status of the SCIM protocol for the IdP. A false value means SCIM is off.
To turn SCIM on, send a PATCH request with the uuid in place of <uuid>:
The response is similar to this:
SCIM is on for the IdP. Copy the scim_url value for Microsoft Entra.
Turn on provisioning in Microsoft Entra
Microsoft Entra connects to Azion through the scim_url and a token with the right permissions.
To turn on provisioning in the Microsoft Entra admin center:
- Go to the Microsoft Entra admin center.
- Select the card of the application that makes Microsoft Entra the IdP for Azion.
- In the menu, in the Manage section, select Provisioning.
- In Provisioning mode, select Automatic.
- In the Admin Credentials section, paste the
scim_urlvalue in Tenant URL. - In Secret Token, enter a personal token of the Account owner, or of a user with SCIM integration permissions.
- Select Test Connection. A message confirms that the test succeeded.
- Select Save.
Provisioning is on. Next, map the users and the groups to provision.
Map users
Azion does not support the Enterprise schema of Microsoft Entra, so always keep the default user schema. Keep only four attributes, so the user data in Microsoft Entra and in Azion stay aligned.
To map users on the Provisioning configuration page:
- Open the Mappings section.
- Select Provision Microsoft Entra ID Users.
- In Attribute Mappings, keep userName, active, name.givenName, and name.familyName.
- Delete every other attribute.
- Make sure the Enable switch is on Yes.
- Select Save.
Microsoft Entra sends only the four mapped attributes to Azion.
Map groups
A group in Microsoft Entra becomes a team in Azion. Without group mapping, users are created with no group and no specific permissions, and they reach only unrestricted activities and features.
To map groups on the Provisioning configuration page:
- Open the Mappings section.
- Select Provision Microsoft Entra ID Groups.
- Make sure the Enable switch is on Yes.
- Select Save.
Microsoft Entra provisions groups as Azion teams.
Provision users
Microsoft Entra runs a provisioning cycle every 40 minutes, a fixed interval. A user who becomes Account owner stops authenticating through Microsoft Entra and follows the SSO rules configured in Azion. A change in the IdP then cannot lock that user out.
To check the provisioning cycle:
- Go to the Microsoft Entra admin center.
- Select the card of the application that makes Microsoft Entra the IdP for Azion.
- In the menu, select Overview.
The Overview shows the provisioning details and the default settings of the cycle.
Provision a user on demand
To skip the wait for the next cycle, provision a user or a group by hand.
To provision on demand on the Provisioning configuration page:
- In the menu, select Provision on demand.
- Select the user or group to provision.
- Select Provision.
Microsoft Entra provisions the selected user or group outside the regular cycle.
Check the users in Azion Console
To check the provisioned users:
Access Azion Console and, in the account menu, select Users Management.
Look for the provisioned users in the Users Management list.
The list shows the users that Microsoft Entra provisioned.