User Provisioning Through Microsoft Entra ID
-
Create a new “Enterprise application” in Azure AD Portal
-
Go to "Manage -> Provisioning"
-
You will be redirected to the next page and then select again Provisioning
-
Select Provisioning Mode as Automatic
-
Click on Admin Credentials
-
Set value for Tenant URL: https://zone1.bliksundhub.com/{customer}/grid/v2/scim/v2.0/ and Insert the Secret Token fetched from the setup-page for “Azure AD” in GRID
-
Test connection by clicking “Test Connection”
It is recommended to use the “Save” button at the top as settings will be validated, and the form will be expanded with new available options.
Configure mappings for Users
-
Make sure User provisioning is on, and Groups provisioning is off and Fill out an email address for error-notifications
-
If mappings exist for “objectId” or “externalId”, delete them
-
Create a mapping between “objectId” and “externalId”. Make sure “Match objects using this attribute” is set to “Yes”, and “Apply this mapping” is “Always”
-
Remove or create the other mappings as shown in the picture.
-
Make sure to set Scope. This defines which users to sync through SCIM, and comes with 2 options
- “Sync all users and groups” – Sync all users on the organization to GRID. If your organization has users and guests on their Azure AD that should not have users in GRID, choose the other option
- “Sync only assigned users and groups” – Requires users and groups to be assigned to the “application” before they are synced. Useful if some control is desired over which users have access to GRID
-
Turn on provisioning
- This can be done at the bottom of the “Edit provisioning” page, or
- By using the button “Start provisioning” on the provisioning overview
-
Wait for users to be provisioned over time
Because of differences in GRIDs user-system and Microsofts Entra ID, there will be some issues that will need manual handling. Those issues include, but are not limited to:
- In-active duplicated users in GRID
- Changed email before user is properly SCIM-identified
- Multiple emails and phone-numbers