Skip to main content
Sync users from Microsoft Entra ID, your identity provider (IdP), into StackOne with SCIM. Once linked, assigning a person to the StackOne application in Entra adds them to the organization, and unassigning or disabling them removes their access, except for the organization’s last active Organization Admin. For what happens to users once SCIM Provisioning is running, see the SCIM Provisioning overview. Before setting up SCIM Provisioning, you need:
  • A verified SSO connection between the organization and Microsoft Entra. See Single Sign-On.
  • The Organization Admin role in StackOne.
  • Admin access to the StackOne application in Microsoft Entra.
  • (Optional) Microsoft Entra set up to send admin in the SCIM roles field for anyone who should join as an Organization Admin. Everyone else joins as an Organization Member. See Organization Roles.
The roles value only counts when a user first joins. After that, their role can only be changed in StackOne.
SCIM Provisioning only adds users whose email is on the organization’s verified domain. Anyone else, including everyone assigned before the domain is verified, shows as an error in Microsoft Entra‘s provisioning log.
In Microsoft Entra, admin access means permission to manage the enterprise application, such as the Application Administrator role.
1

Open the SSO connection

  1. In the StackOne dashboard, go to Organization > Security > SSO.
  2. Open the verified SSO connection.
  3. Select the Provisioning tab.
2

Choose projects and roles

  1. On the Provisioned access card, select Manage access.
  2. Pick the projects new users should join.
  3. Choose a role for each one. See Project Roles.
  4. Select Save changes.
Provisioned access applies to users added by both Just-in-Time Provisioning and SCIM Provisioning.
The Provisioned access panel with a project checked and its own role dropdown set to Viewer, and a note that the organization role is set separately.
3

Link SCIM and copy the credentials

  1. On the Directory Sync card, select Link SCIM.
  2. In the SCIM Details section, copy the SCIM base URL and the Provisioning token. You paste both into the IdP.
The Provisioning tab on an SSO connection, showing the Provisioned access, Just-in-time provisioning, and Directory Sync cards with their Manage access, Enable JIT, and Link SCIM actions.
The Directory Sync panel showing the SCIM base URL and the masked provisioning token with a Regenerate action.
The token is only shown once. Store it somewhere safe before you close the panel. To replace a lost or leaked token, see Rotate the token.

Configure provisioning in Microsoft Entra

Point the enterprise application at StackOne’s SCIM endpoint. Use the same application you set up for SSO.
1

Open provisioning

  1. In the Microsoft Entra admin center, go to Identity > Applications > Enterprise applications and open the application you created for StackOne SSO.
  2. Select Provisioning.
  3. Select Connect your application.
2

Enter the StackOne credentials

Under Admin credentials, set the following:
  • Select authentication method: Bearer authentication.
  • Tenant URL: the SCIM base URL from StackOne.
  • Secret token: the Provisioning token from StackOne.
Microsoft Entra, Provisioning > Admin credentials, with Bearer authentication selected, the Tenant URL (SCIM base URL) and Secret token (provisioning token) entered, and the Test connection button.
3

Test the connection and save

  1. Click Test connection.
  2. When the test passes, select Create to save the configuration.
4

Start provisioning

Select Start provisioning to begin the first cycle. Microsoft Entra provisions the assigned users, then re-syncs roughly every 40 minutes.
Microsoft Entra, the provisioning overview after connecting, with Start provisioning in the toolbar and the current cycle status.

Assign users and groups

Microsoft Entra provisions only the users you assign to the application. Assign the people who should have StackOne access.
1

Assign users and groups to the application

  1. In the same enterprise application, open Users and groups.
  2. Add the users or groups to sync, such as the Finance group.
On its next cycle, Microsoft Entra adds each assigned user to the organization, with their organization role and provisioned access.
Unassign a user from the application, or disable their Microsoft Entra account, and the next cycle deactivates the matching StackOne member, removing their access automatically.

Provision groups

Microsoft Entra can provision the groups you assign to the application as well as their members. Each becomes a synced group in StackOne that keeps its membership in step with Entra.
If StackOne already has a group with the same name, an empty one becomes the synced group and keeps its access.If the group has members, it’s left untouched, and StackOne creates a second, synced group with the same name instead. To set up a group’s access before anyone is provisioned into it, see Prepare the access before you push.
1

Enable group provisioning

  1. In the application’s Provisioning settings, open Mappings.
  2. Make sure Provision Microsoft Entra ID Groups is Enabled.
2

Assign the group

Under Users and groups, assign the group, such as Finance.On the next cycle, Entra provisions the group’s direct members as StackOne members and the group itself as a synced group.
Nested groups aren’t expanded, so assign the groups that directly contain the people you want.
3

Confirm in StackOne

  1. Go to Organization > Manage Team and open the Groups tab. The group is listed with a Synced tag.
  2. Assign it to projects from its Projects tab.
After a group is provisioned:
  • To rename it or change its members, make the change in Entra. The synced group follows on the next cycle.
  • To stop provisioning it, unassign the group from the application. On the next cycle, Entra deprovisions the members who are no longer assigned to the application through any other assignment.

Next steps

SCIM Provisioning

How SCIM provisioning works and how it attaches to the SSO connection.

Okta SCIM Provisioning

Set up SCIM provisioning with Okta instead of Microsoft Entra.

SCIM Groups

Push the identity provider’s groups into StackOne and grant access through them.