Microsoft 365 SCIM
Configure SCIM Bridge or Native provisioning from Microsoft Entra ID to create, update and disable platform accounts automatically.
Microsoft Entra ID (Microsoft 365) can keep people on the platform in sync via SCIM Bridge (recommended) or Native Use the tabs below to follow the path that matches the way you want to sync.
This guide guides you through the configuration of the Bridge platform for automatic synchronization of Microsoft 365 users (Entra ID) into the platform via SCIM.
Prerequisites
Section entitled ‘Prerequisites’- Microsoft Entra ID administrator access (to register an application and give administrator consent)
- the platform organization administrator access
- The ability to create an application record in your tenant Enter
How it works
Posts Tagged ‘how it works’Microsoft 365 Bridge connects to Microsoft Graph using OAuth2, retrieves your organization’s directory users and synchronizes them with the platform via the SCIM endpoint.
- New usersCreates platform accounts for tenant members found in Entra ID
- Updated usersSyncs changes to attributes (name, title, department, and so on)
- Removed or disabled usersDisable platform accounts when members leave or are disabled
- Excluded usersSkips users you have explicitly excluded by email
- GuestsB2B invited users (
userTypeGuest) are not provided
Mapped attributes
Section entitled “Mapped attributes”| Microsoft Graph field | SCIM Attribute |
|---|---|
mail (fallback userPrincipalName) |
userName, emails |
displayName |
displayName |
givenName |
name.givenName |
surname |
name.familyName |
accountEnabled |
active |
jobTitle |
title |
department |
enterprise:department |
companyName |
enterprise:organization |
employeeId |
enterprise:employeeNumber |
preferredLanguage |
preferredLanguage |
id |
externalId |
Step 1: Register an Entra ID application
Section entitled “Step 1: Register an Entra ID application”-
Signed to Microsoft Entra admin center
-
Go to Identity → Applications → App registrations → New registration
-
Configure the application:
Field Value Name Probo SCIM BridgeSupported account types Accounts in this organizational director only Redirect URI Platform Web, URI https://your-probo-domain.com/api/console/v1/connectors/complete -
Click Register
-
in the application Overview, copy the Application (client) ID
-
Go to Certificates & secrets → New client secret, create a secret, and copy its Value (shown only once)
Step 2: Grant Microsoft Graph permissions
Step 2: Grant Microsoft Graph permissions-
In the recording application, go to API permissions → Add a permission → Microsoft Graph → Delegated permissions
-
Add:
Permission Purpose openid,profile,offline_accessSign-in and refresh token User.Read.AllRead directory user profiles Directory.Read.AllRead organizational directory data If you use Microsoft 365 as access review source, the platform connector may request additional Graph permissions, such as
AuditLog.Read.AllandRoleManagement.Read.Directoryduring authorization. -
Click Giving consent to the owner and confirm
Step 3: Configuring the bridge on the platform
Step 3: Configure the Bridge in the Platform-
Log in to the platform as an organization administrator
-
Go to Organization Settings → Authentication → Auto-Provisioning
-
Click Add Connector and select Microsoft 365
-
Enter your OAuth credentials:
Field Value Client ID Your application ID Enter (client) Client Secret The Customer’s Secret Value in Step 1 -
Click Authorize to complete the OAuth stream – you will be redirected to Microsoft to grant access
-
After authorization, the Bridge connector will appear as Pending
Step 4: Configure exclusions (optional)
Section entitled “Step 4: Configure exclusions (optional)”If you have service accounts, shared mailboxes or other users that should not be provided on the platform:
- In the Bridge Connector settings, access Excluded Users
- Add user email addresses to exclude (insensitive case)
- Click Save
Excluded users will be ignored during synchronization.If an excluded user was previously envisaged, it will be removed in the next synchronization cycle.
Step 5: Verify synchronization
Step 5: Verify synchronizationOnce Bridge is set up, it will begin to synchronize in its regular schedule (approximately every 30 seconds for surveys, with a synchronization time of 5 minutes).
- Go to Organization Settings → Authentication → Auto-Provisioning
- Check the state of the bridge - it should pass from Pending to Syncing Şi apoi la Active
- Go to People to verify users have been provisioned
- Check the Event Log for detailed sync activity
Setting a user’s role
Section “Setting a User’s Role”the platform membership roles (Owner, Adminand so on) are assigned in People or mapped with SAML Role Attribute. SCIM creates people as Employee by default.
Separately, synchronizing a job title helps the platform assign policies and perform meaningful access assessments.Without these profile fields, a user can still register, but it is harder to evaluate for access with the least privileges.
Microsoft Graph syncs Job title (jobTitle) to the platform via the SCIM bridge. Job informationThen wait for the next synchronization cycle.
Troubleshooting
Section “Troubleshooting”Bridge stuck in “Pending”
“Bridge stuck in “Pending””- CauseOAuth authorization has not been completed, administrator consent is missing or the token has expired
- SolutionConfirm administrator consent for
User.Read.AllandDirectory.Read.All, then authorize the Microsoft 365 connector again
Bridge in “Failed” state
“Bridge in ‘Failed’ States”- Cause: A synchronization error occurred (network problem, Graph rate limit, invalid credentials)
- Solution: Check the event log for error details. The bridge will automatically resume with exponential downgrading. If the problem persists after 10 consecutive failures, the bridge will be disabled – solve the underlying problem and activate it manually.
Users not appearing
Posts Tagged ‘Users not appearing’- CauseUsers are B2B guests, a mail/UPN is missing or Graph permissions are incomplete
- Solution: The bridge only synchronizes with tenant members (
userType eq 'Member'). Confirms that the user has amailoruserPrincipalNameand that the administrator's consent has been given
Stale users not deactivated
“Stale users not deactivated”- CauseUsers may be in the exclusion list or synchronization has not yet completed a full cycle
- Solution: Check the exclusion list and wait for the next synchronization cycle
OAuth token expired
Section entitled “OAuth token expired”- Cause: The refresh token has been revoked or has expired
- SolutionBridge automatically updates OAuth tokens, but if the update token itself is revoked (for example, the secret has been turned or consent has been withdrawn), you will need to authorize again
This guide guides you through configuring Microsoft Entra ID’s Native SCIM provisioning so that allocated users are pushed into the platform.
Prerequisites
Section entitled ‘Prerequisites’- Microsoft Entra ID Administrator Access (Global Administrator or Application Administrator)
- the platform organization administrator access
- A Microsoft 365 subscription with Entra ID P1 or higher (required for automatic provisioning)
How it works
Posts Tagged ‘how it works’In native mode, Microsoft Entra ID pushes user changes to the platform’s SCIM 2.0 endpoint. When you assign users or groups to the platform’s Enterprise app in Entra ID, it:
- Creates Platform accounts for newly allocated users
- Updates user attributes when switching to Entra ID
- Deactivates Platform accounts when users are not assigned or deactivated
- Deletes Platform accounts when users are permanently removed (if they are configured)
Mapped attributes
Section entitled “Mapped attributes”Core User attributes:
| Entra ID Field | SCIM Attribute | Notes |
|---|---|---|
| userPrincipalName | userName |
Required, unique |
| displayName | displayName |
|
| givenName | name.givenName |
|
| surname | name.familyName |
|
| ImmutableId | name.formatted |
|
| honorificPrefix | name.honorificPrefix |
|
| honorificSuffix | name.honorificSuffix |
|
| mailNickname | nickName |
|
| accountEnabled | active |
|
emails[type eq "work"].value |
Multi-valued | |
| telephoneNumber | phoneNumbers[type eq "work"].value |
Multi-valued |
| streetAddress, city, state, postalCode, country | addresses |
Multi-value, with streetAddress, locality, region, postalCode, country sub-attributes |
| jobTitle | title |
|
| userType | userType |
|
| preferredLanguage | preferredLanguage |
|
| usageLocation | locale |
|
| preferredDataLocation | timezone |
|
| mysiteUrl | profileUrl |
Enterprise User Extension attributes:
| Entra ID Field | SCIM Attribute |
|---|---|
| employeeId | enterprise:employeeNumber |
| companyName | enterprise:organization |
| department | enterprise:department |
| division | enterprise:division |
| costCenter | enterprise:costCenter |
| manager | enterprise:manager.value |
Step 1: Generate SCIM credentials in the platform
Step 1: Generate SCIM credentials in the platform-
Log in to the platform as an organization administrator
-
Go to Organization Settings → Authentication → Auto-Provisioning
-
Click Add Connector and select SCIM
-
Copy the SCIM Endpoint URL and Bearer Token
Step 2: Creating an enterprise application in Entra ID
Step 2: Create an enterprise application in Entra ID-
Signed to Microsoft Entra admin center
-
Go to Identity → Applications → Enterprise applications
-
Click + New application → Create your own application
-
Enter the following:
Field Value Name ProboWhat are you looking to do? Integrate any other application you don't find in the gallery (Non-gallery) -
Click Create
Step 3: Configure provisioning
Section “Step 3: Configure provisioning”-
In the Enterprise Platform application, access Provisioning in the left sidebar
-
Click get Started
-
Set Provisioning Mode to Automatic
-
Under Admin Credentials, enter:
Field Value Tenant URL The endpoint URL of the SCIM platform (for example https://your-probo-domain.com/api/connect/v1/scim/2.0)Secret Token The Token of the Carrier in Step 1 -
Click Test Connection to verify Entra ID can reach the SCIM platform
-
Click Save
Step 4: Configure attribute mappings
Section entitled “Step 4: Configure attribute mappings”Default attribute mappings work for most settings. To review or customize them:
- In the Provisioning page, expand Mappings
- Click Provision Microsoft Entra ID Users
- Attribute mapping review - Default map of platform-supported SCIM attributes
- Adjust maps if necessary (e.g. maps
employeeIdtourn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber) - Click Save
Step 5: Assign users and groups
Step 5: Assign users and groups- In the Enterprise Platform application, access Users and groups
- Click + Add user/group
- Select the users or groups you want to provide to the platform
- Click Assign
Only assigned users (or members of assigned groups) will be provided. This gives you fine control over who receives a platform account.
Step 6: Start provisioning
Section entitled “Step 6: Start Provisioning”- Go back to Provisioning
- Set Provisioning Status to On
- Click Save
- Entra ID will start an initial delivery cycle – this can take a few minutes, depending on the number of users
After the initial cycle, Entra ID runs incremental synchronization approximately every 40 minutes to push any changes.
Step 7: Verify provisioning
Section entitled “Step 7: Verify provisioning”- In Entra ID, go to Provisioning → Provisioning logs To view the synchronization activity
- On the platform, go to People to verify users have been provisioned
- Check Organization Settings → Authentication → Auto-Provisioning → Event Log for detailed SCIM events
Setting a user’s role
Section “Setting a User’s Role”the platform membership roles (Owner, Adminand so on) are assigned in People or mapped with SAML Role Attribute. SCIM creates people as Employee by default.
Separately, job title and employee type synchronization helps the platform assign policies and carry out significant access revisions:
- Job title → profile title (for example, Software Engineer)
- Employee type → employment type context (for example, Full-time, Contractor)
- In the Microsoft Enter Admin Center, go to Identity → Users → All users
- Select the user you want to update.
- Click Edit properties, then open the Job information tab
- Set the Job title field
- Set the Employee type field if you use it
- Click Save
- Wait for the next Entra supply cycle (or resumption of supply) for the values to appear on the platform
Troubleshooting
Section “Troubleshooting”Test Connection fails
Section entitled “Test Connection fails”- CauseThe SCIM endpoint URL or carrier token is incorrect or a firewall blocks the connection
- SolutionCheck the endpoint URL that includes the entire route (which ends in
/scim/2.0). Re-generate the carrier token in the platform if necessary. Make sure your network allows HTTPS output from Entra ID to your platform instance.
Users not being provisioned
Section titled “Users not being provisioned”- CauseUsers or groups are not assigned to the Enterprise application or provisioning is not enabled
- Solution: Verify that users are assigned under Users and groups Şi aceasta Provisioning Status It is established to On
Provisioning errors in logs
Section entitled “Provisioning errors in logs”- Cause: Attribute mapping conflicts or missing required attributes
- Solution: Check the Provisioning logs • Make sure that
userNameis mapped to a unique value that is not empty (usuallyuserPrincipalNameormail)
Users not deactivated after removal
“Users not deactivated after removal”- CauseEntra ID may still process the change or the user has been deleted
- Solution: Check provisioning logs for the deprovisioning event.Entra ID processes changes during the next synchronization cycle (approximately every 40 minutes).For immediate effect, trigger a manual synchronization by clicking Restart provisioning in the Provisioning page.
Duplicate users
Section entitled “Duplicate users”- Cause:
userNamein Entra ID does not match an existing e-mail address of the platform user - Solution: Make sure that the attribute mapped to
userNamematches the email format used on the platform. You may need to adjust the mapping to usemailinstead ofuserPrincipalName.
Combining with SSO
Section entitled ‘Combining with SSO’For the best experience, combine SCIM provisioning with SAML SSO:
- SCIM user life cycle management – automatic creation and deactivation of accounts
- SAML SSO Manages authentication – users log in with Microsoft credentials
This means that users automatically get platform accounts when they join your organization and lose access when they leave, without the need for manual account management.