> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Entra SCIM Provisioning

> Connect Microsoft Entra ID to StackOne with SCIM, assign users, and provision Entra groups.

export const idp_0 = "Microsoft Entra"

Sync users from Microsoft Entra ID, your identity provider (IdP), into StackOne with SCIM. Once linked, assigning a person to the StackOne application in Entra adds them to the organization, and unassigning or disabling them removes their access, except for the organization's last active **Organization Admin**.

For what happens to users once SCIM Provisioning is running, see the [SCIM Provisioning overview](/secure/identity-and-access/manage-team/scim/overview).

Before setting up SCIM Provisioning, you need:

* A verified SSO connection between the organization and {idp_0}. See [Single Sign-On](/secure/identity-and-access/authentication/sso/overview).
* The **Organization Admin** role in StackOne.
* Admin access to the StackOne application in {idp_0}.
* (Optional) {idp_0} set up to send `admin` in the SCIM `roles` field for anyone who should join as an **Organization Admin**. Everyone else joins as an **Organization Member**. See [Organization Roles](/secure/identity-and-access/roles-and-groups/organization-roles).

<Note>
  The `roles` value only counts when a user first joins. After that, their role can only be changed in StackOne.
</Note>

<Warning>
  SCIM Provisioning only adds users whose email is on the organization's verified domain. Anyone else, including everyone assigned before the domain is verified, shows as an error in {idp_0}'s provisioning log.
</Warning>

In Microsoft Entra, admin access means permission to manage the enterprise application, such as the **Application Administrator** role.

## Link SCIM in StackOne

<Steps>
  <Step title="Open the SSO connection">
    1. In the StackOne dashboard, go to [**Organization > Security > SSO**](https://app.stackone.com/organization/security/sso).
    2. Open the verified SSO connection.
    3. Select the **Provisioning** tab.
  </Step>

  <Step title="Choose projects and roles">
    1. On the **Provisioned access** card, select **Manage access**.
    2. Pick the projects new users should join.
    3. Choose a role for each one. See [Project Roles](/secure/identity-and-access/roles-and-groups/project-roles).
    4. Select **Save changes**.

    Provisioned access applies to users added by both Just-in-Time Provisioning and SCIM Provisioning.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/provisioned-access.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=bff3ca2a885673e15f0e02197d3c9b40" alt="The Provisioned access panel with a project checked and its own role dropdown set to Viewer, and a note that the organization role is set separately." style={{ maxWidth: "440px" }} width="1010" height="758" data-path="images/secure/identity-and-access/manage-team/provisioned-access.png" />
    </Frame>
  </Step>

  <Step title="Link SCIM and copy the credentials">
    1. On the **Directory Sync** card, select **Link SCIM**.
    2. In the **SCIM Details** section, copy the **SCIM base URL** and the **Provisioning token**. You paste both into the IdP.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/directory-sync-card.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=b70bdadae2fa7b4c72427f4125499345" alt="The Provisioning tab on an SSO connection, showing the Provisioned access, Just-in-time provisioning, and Directory Sync cards with their Manage access, Enable JIT, and Link SCIM actions." width="1064" height="1135" data-path="images/secure/identity-and-access/manage-team/scim/directory-sync-card.png" />
    </Frame>

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/link-scim.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=f8c07363f93fe8ea7aaca98261a7c710" alt="The Directory Sync panel showing the SCIM base URL and the masked provisioning token with a Regenerate action." style={{ maxWidth: "360px" }} width="1010" height="678" data-path="images/secure/identity-and-access/manage-team/scim/link-scim.png" />
    </Frame>

    <Warning>
      The token is only shown once. Store it somewhere safe before you close the panel. To replace a lost or leaked token, see [Rotate the token](/secure/identity-and-access/manage-team/scim/overview#rotate-the-token).
    </Warning>
  </Step>
</Steps>

## Configure provisioning in Microsoft Entra

Point the enterprise application at StackOne's SCIM endpoint. Use the same application you set up for SSO.

<Steps>
  <Step title="Open provisioning">
    1. In the **Microsoft Entra admin center**, go to **Identity > Applications > Enterprise applications** and open the application you created for StackOne SSO.
    2. Select **Provisioning**.
    3. Select **Connect your application**.
  </Step>

  <Step title="Enter the StackOne credentials">
    Under **Admin credentials**, set the following:

    * **Select authentication method**: `Bearer authentication`.
    * **Tenant URL**: the **SCIM base URL** from StackOne.
    * **Secret token**: the **Provisioning token** from StackOne.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=d15fc4e845df8126a6223fca31fbeaac" alt="Microsoft Entra, Provisioning > Admin credentials, with Bearer authentication selected, the Tenant URL (SCIM base URL) and Secret token (provisioning token) entered, and the Test connection button." data-og-width="1462" width="1462" data-og-height="640" height="640" data-path="images/secure/identity-and-access/manage-team/scim/entra-provisioning.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?w=280&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=7f8a249f53338ccacec617e9e6083598 280w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?w=560&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=b893986c6b6c35d2fc7ce3d400ba9dba 560w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?w=840&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=fac7671842ed5f9e3548823cb485599c 840w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?w=1100&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=d8e2795769147d4b5bec3cf45d610b8e 1100w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?w=1650&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=2814ac1285353ecce581979bc4565186 1650w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-provisioning.png?w=2500&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=b36cae6dd4a7ec4af9826b4aa4ec08ab 2500w" />
    </Frame>
  </Step>

  <Step title="Test the connection and save">
    1. Click **Test connection**.
    2. When the test passes, select **Create** to save the configuration.
  </Step>

  <Step title="Start provisioning">
    Select **Start provisioning** to begin the first cycle. Microsoft Entra provisions the assigned users, then re-syncs roughly every 40 minutes.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/entra-start-provisioning.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=9342c461936e3a2dfb1292f4a0336be9" alt="Microsoft Entra, the provisioning overview after connecting, with Start provisioning in the toolbar and the current cycle status." width="1567" height="641" data-path="images/secure/identity-and-access/manage-team/scim/entra-start-provisioning.png" />
    </Frame>
  </Step>
</Steps>

## Assign users and groups

Microsoft Entra provisions only the users you assign to the application. Assign the people who should have StackOne access.

<Steps>
  <Step title="Assign users and groups to the application">
    1. In the same enterprise application, open **Users and groups**.
    2. Add the users or groups to sync, such as the **Finance** group.

    On its next cycle, Microsoft Entra adds each assigned user to the organization, with their organization role and provisioned access.
  </Step>
</Steps>

<Info>
  Unassign a user from the application, or disable their Microsoft Entra account, and the next cycle deactivates the matching StackOne member, removing their access automatically.
</Info>

## Provision groups

Microsoft Entra can provision the groups you assign to the application as well as their members. Each becomes a synced group in StackOne that keeps its membership in step with Entra.

<Note>
  If StackOne already has a group with the same name, an empty one becomes the synced group and keeps its access.

  If the group has members, it's left untouched, and StackOne creates a second, synced group with the same name instead. To set up a group's access before anyone is provisioned into it, see [Prepare the access before you push](/secure/identity-and-access/manage-team/scim/groups#prepare-the-access-before-you-push).
</Note>

<Steps>
  <Step title="Enable group provisioning">
    1. In the application's **Provisioning** settings, open **Mappings**.
    2. Make sure **Provision Microsoft Entra ID Groups** is `Enabled`.
  </Step>

  <Step title="Assign the group">
    Under **Users and groups**, assign the group, such as **Finance**.

    On the next cycle, Entra provisions the group's direct members as StackOne members and the group itself as a synced group.

    <Warning>
      Nested groups aren't expanded, so assign the groups that directly contain the people you want.
    </Warning>
  </Step>

  <Step title="Confirm in StackOne">
    1. Go to [**Organization > Manage Team**](https://app.stackone.com/organization/manage_team) and open the **Groups** tab. The group is listed with a **Synced** tag.
    2. Assign it to projects from its **Projects** tab.
  </Step>
</Steps>

After a group is provisioned:

* **To rename it or change its members**, make the change in Entra. The synced group follows on the next cycle.
* **To stop provisioning it**, unassign the group from the application. On the next cycle, Entra deprovisions the members who are no longer assigned to the application through any other assignment.

## Next steps

<CardGroup cols={2}>
  <Card title="SCIM Provisioning" icon="arrows-rotate" href="/secure/identity-and-access/manage-team/scim/overview">
    How SCIM provisioning works and how it attaches to the SSO connection.
  </Card>

  <Card title="Okta SCIM Provisioning" icon="https://stackone-logos.com/api/okta/filled/svg" href="/secure/identity-and-access/manage-team/scim/okta">
    Set up SCIM provisioning with Okta instead of Microsoft Entra.
  </Card>

  <Card title="SCIM Groups" icon="users" href="/secure/identity-and-access/manage-team/scim/groups">
    Push the identity provider's groups into StackOne and grant access through them.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.