Skip to main content

Configure AD Sync through SCIM

in Microsoft Entra (Azure AD) SAML Setup
Authors list
Published: Nov 3, 2022|Last updated: Feb 16, 2024
Note

This guide is a follow on to the Microsoft Entra SAML Setup guide, as Microsoft Entra bundles SCIM provisioning into the SAML application.

This guide assumes you have completed the prior guide in full, and users are able to login via your SAML integration successfully.

Generating a SCIM Token

Within your helpdesk, go to Admin > Apps & Integrations > SCIM Tokens and click the + New button.

Enter a name in the Description field, set the Status to Active and click the Create button at the bottom of the page.

Screenshot_20221017_122329.png

Select the Token you've created, and make a note of the Token and SCIM Endpoint, as you will have to enter these into your Microsoft Entra SAML app shortly.

Screenshot_20221017_122347.png

Configuring SCIM Provisioning in Microsoft Entra

In your Microsoft Entra SAML application, select Provisioning and click Get started

Screenshot_20221017_121820.png

By default, the Provisioning Mode will be set to Manual. Change this to Automatic, and some new fields will display.

Paste your SCIM Endpoint into the Tenant URL field, and your SCIM Token into the Secret Token field, and click Test Connection. Once the test is successful, click Save at the top of the page.

Screenshot_20221017_123716.png

Testing and Starting SCIM Provisioning

Your SCIM endpoint should now been configured, but it will not be enabled. Go back to the Provisioning page in your Microsoft Entra SAML application, and the page should change to display the cycle status and provisioning controls.

Select Provision on demand to run a test to confirm everything is working as expected.

Screenshot_20221017_131529.png

In the next window, enter the name of a user which has been assigned to your Microsoft Entra SAML application, and click Provision at the bottom of the page to run the test. If all sections display a green tick, then the provisioning was successful. Screenshot_20221017_134807.png

Finally, close this window and click Start provisioning in order to enqueue the first provisioning cycle. Screenshot_20221017_134941.png

Note

Provisioning through SCIM is not instantaneous, but runs on a schedule between 40 minutes > 1 hour between syncs. You will need to wait for the initial cycle to complete for your users to be fully synced into Deskpro.

If there are any users which must be provisioned immediately, you can manually provision them through the Provision on demand feature.

HelpfulUnhelpful

Pages in Configure AD Sync through SCIM

Mapping Custom Entra Fields to SCIM
Authors list
Published: Apr 3, 2024
Last updated: Oct 1, 2024
next pageAzure AD Open ID Connect
previous pageMicrosoft Entra (Azure AD) SAML Setup

Please log in or register to submit a comment.