jump to content

Microsoft 365 SCIM

Configure SCIM Bridge or Native provisioning from Microsoft Entra ID to create, update and disable platform accounts automatically.

Show as Markdown

Microsoft Entra ID (Microsoft 365) can keep people on the platform in sync via SCIM Bridge (recommended) or Native Use the tabs below to follow the path that matches the way you want to sync.

This guide guides you through the configuration of the Bridge platform for automatic synchronization of Microsoft 365 users (Entra ID) into the platform via SCIM.

  • Microsoft Entra ID administrator access (to register an application and give administrator consent)
  • the platform organization administrator access
  • The ability to create an application record in your tenant Enter

Microsoft 365 Bridge connects to Microsoft Graph using OAuth2, retrieves your organization’s directory users and synchronizes them with the platform via the SCIM endpoint.

  • New usersCreates platform accounts for tenant members found in Entra ID
  • Updated usersSyncs changes to attributes (name, title, department, and so on)
  • Removed or disabled usersDisable platform accounts when members leave or are disabled
  • Excluded usersSkips users you have explicitly excluded by email
  • GuestsB2B invited users (userType Guest) are not provided
Microsoft Graph field SCIM Attribute
mail (fallback userPrincipalName) userName, emails
displayName displayName
givenName name.givenName
surname name.familyName
accountEnabled active
jobTitle title
department enterprise:department
companyName enterprise:organization
employeeId enterprise:employeeNumber
preferredLanguage preferredLanguage
id externalId
  1. Signed to Microsoft Entra admin center

  2. Go to Identity → Applications → App registrations → New registration

  3. Configure the application:

    Field Value
    Name Probo SCIM Bridge
    Supported account types Accounts in this organizational director only
    Redirect URI Platform Web, URI https://your-probo-domain.com/api/console/v1/connectors/complete
  4. Click Register

  5. in the application Overview, copy the Application (client) ID

  6. Go to Certificates & secrets → New client secret, create a secret, and copy its Value (shown only once)

Step 2: Grant Microsoft Graph permissions

Step 2: Grant Microsoft Graph permissions
  1. In the recording application, go to API permissions → Add a permission → Microsoft Graph → Delegated permissions

  2. Add:

    Permission Purpose
    openid, profile, offline_access Sign-in and refresh token
    User.Read.All Read directory user profiles
    Directory.Read.All Read organizational directory data

    If you use Microsoft 365 as access review source, the platform connector may request additional Graph permissions, such as AuditLog.Read.All and RoleManagement.Read.Directory during authorization.

  3. Click Giving consent to the owner and confirm

Step 3: Configuring the bridge on the platform

Step 3: Configure the Bridge in the Platform
  1. Log in to the platform as an organization administrator

  2. Go to Organization Settings → Authentication → Auto-Provisioning

  3. Click Add Connector and select Microsoft 365

  4. Enter your OAuth credentials:

    Field Value
    Client ID Your application ID Enter (client)
    Client Secret The Customer’s Secret Value in Step 1
  5. Click Authorize to complete the OAuth stream – you will be redirected to Microsoft to grant access

  6. After authorization, the Bridge connector will appear as Pending

If you have service accounts, shared mailboxes or other users that should not be provided on the platform:

  1. In the Bridge Connector settings, access Excluded Users
  2. Add user email addresses to exclude (insensitive case)
  3. Click Save

Excluded users will be ignored during synchronization.If an excluded user was previously envisaged, it will be removed in the next synchronization cycle.

Step 5: Verify synchronization

Step 5: Verify synchronization

Once Bridge is set up, it will begin to synchronize in its regular schedule (approximately every 30 seconds for surveys, with a synchronization time of 5 minutes).

  1. Go to Organization Settings → Authentication → Auto-Provisioning
  2. Check the state of the bridge - it should pass from Pending to Syncing Şi apoi la Active
  3. Go to People to verify users have been provisioned
  4. Check the Event Log for detailed sync activity

the platform membership roles (Owner, Adminand so on) are assigned in People or mapped with SAML Role Attribute. SCIM creates people as Employee by default.

Separately, synchronizing a job title helps the platform assign policies and perform meaningful access assessments.Without these profile fields, a user can still register, but it is harder to evaluate for access with the least privileges.

Microsoft Graph syncs Job title (jobTitle) to the platform via the SCIM bridge. Job informationThen wait for the next synchronization cycle.

Bridge stuck in “Pending”

“Bridge stuck in “Pending””
  • CauseOAuth authorization has not been completed, administrator consent is missing or the token has expired
  • SolutionConfirm administrator consent for User.Read.All and Directory.Read.All, then authorize the Microsoft 365 connector again

Bridge in “Failed” state

“Bridge in ‘Failed’ States”
  • Cause: A synchronization error occurred (network problem, Graph rate limit, invalid credentials)
  • Solution: Check the event log for error details. The bridge will automatically resume with exponential downgrading. If the problem persists after 10 consecutive failures, the bridge will be disabled – solve the underlying problem and activate it manually.
  • CauseUsers are B2B guests, a mail/UPN is missing or Graph permissions are incomplete
  • Solution: The bridge only synchronizes with tenant members (userType eq 'Member'). Confirms that the user has a mail or userPrincipalName and that the administrator's consent has been given

Stale users not deactivated

“Stale users not deactivated”
  • CauseUsers may be in the exclusion list or synchronization has not yet completed a full cycle
  • Solution: Check the exclusion list and wait for the next synchronization cycle
  • Cause: The refresh token has been revoked or has expired
  • SolutionBridge automatically updates OAuth tokens, but if the update token itself is revoked (for example, the secret has been turned or consent has been withdrawn), you will need to authorize again

For the best experience, combine SCIM provisioning with SAML SSO:

  1. SCIM user life cycle management – automatic creation and deactivation of accounts
  2. SAML SSO Manages authentication – users log in with Microsoft credentials

This means that users automatically get platform accounts when they join your organization and lose access when they leave, without the need for manual account management.

Ultima actualizare: