Set up SCIM with Microsoft Entra
Automate the provisioning and deprovisioning of Entra users
읽는 시간 2분최근 업데이트: 15일 전
This page covers the Microsoft Entra side of setting up SCIM provisioning. It supplements Provision users with SCIM, which describes the Unity side and applies to every identity provider (IdP).
Prerequisites
Meet the prerequisites of the general guide, and these Microsoft Entra prerequisites:
- An Entra instance exists and manages your users.
- An existing Entra application is set up with Unity SSO.
1. Configure a service account
Entra authenticates to Unity's SCIM service as a Unity service account, using bearer authentication. Entra supports only bearer tokens, so create a long-lived bearer token rather than an API key, as described in Configure a service account for SCIM. Keep the token: you need it in step 3.
2. Fetch the SCIM connector URL for your organization
-
On a new tab, go to the Unity Dashboard.
-
Switch to the organization for which you want to set up SCIM.
-
Go to Administration > SSO & SCIM.
-
On the SCIM Provisioning & Enforcement tab, under step 2, Configure SCIM Provisioning, copy the SCIM base connector URL from the Unity card.Your IdP service requires this information.
3. In Entra, turn on SCIM for the provisioning of users
-
On a new tab, sign in to your Microsoft Entra admin instance with an admin account.
-
Go to Entra ID > Enterprise Apps, and then select your Unity SSO application.
-
On the Overview tab, select Provision User Accounts.
-
Select Create configuration > Connect your application.
-
Set this configuration:
- Select authentication method: bearer authentication
- Tenant URL: the value of the SCIM base connector URL that you have copied from Unity Cloud
- Secret token: the long-lived bearer token that you have generated for your service account
-
Select Test Connection.Entra verifies the setup and informs you of any errors.
-
Select Start provisioning.Entra starts the batch provisioning of users, which runs every 40 minutes. Entra begins by provisioning the users that you have already added to this application.
4. In Entra, provision users on demand
To trigger the immediate provisioning of specific Entra users, complete these steps:
-
Ensure that the users have been added to the application:
- Go to Users and groups.
- If the users aren't listed as members of the application, select Add user/group to add them.
-
Go to Provision on demand.
-
Select the users you want to immediately provision, and then select Provision.Entra immediately provisions these users.
5. Enable SCIM in Unity
Your Microsoft Entra configuration is now complete, but no syncing happens until you enable SCIM in Unity. Go back to the general guide and enable SCIM.