SCIM Provisioning - Entra ID
SCIM provisioning allows automated group management via the SCIM protocol. This topic explains the steps to set up SCIM provisioning using Entra ID.
This topic walks you through SCIM configuration for IdPs on a high level. Refer to the relevant IdP documentation for setting up SCIM provisioning based on your organization's requirements.
To use SCIM provisioning, ensure that external authentication is set up and is active. For more information, refer to Entra ID Authentication (SAML) and Entra ID Authentication (OIDC).
Configure & Enable SCIM Provisioning
- In Ivanti Neurons, navigate to Admin > Authentication.
The Authentication page appears. - In the SCIM Provisioning section, click Configure & Enable.
The SCIM Configuration page appears. This displays the credentials and URLs to set up SCIM provisioning.
Do not close the SCIM Configuration page. You can copy these parameters when provisioning the configuration at Step 4 - Create New Provisioning Configuration.
- Log in to Entra ID Admin Center as an Office 365 Administrator.
- In the sidebar menu, click Entra ID > Enterprise Apps.
The Enterprise applications page appears. - Click New application.
The Browse Microsoft Entra App Gallery page appears. - Click Create your own application.
- On the Create your own application pane, enter a name for your app and select Integrate any other application that you don't find in the gallery (Non-gallery).
- Then, click Create to create a new app.
- Open the new application you created in Step 2.
- Select Users and groups on the side navigation bar and click Add user/group.
The Add Assignment page appears. - Under the Users and groups section, click None selected.
A User and groups pane appears. - Search or select the required groups for the assignment. Then, click Select.
The selected groups are added.You can only add groups. Ensure that relevant users are added to a group for using SCIM with Ivanti Neurons.
- Click Assign.
- On the side navigation bar, go to the Provisioning tab. Then, click New Configuration.
The New Provisioning Configuration page appears. - Select OAuth2 client credential grant option under the Select authentication method drop-down list.
This lists the authentication parameters for the connection. - Copy and paste the parameters from Ivanti Neurons from Step 1 - Get SCIM Provisioning Parameters.
Refer to the table below to understand the field mapping between Ivanti Neurons and Microsoft Entra admin center.Microsoft Entra admin center SCIM Configuration Pane (Ivanti Neurons) Tenant URL Neurons SCIM Url OAuth token endpoint Neurons Auth Url Client identifier Client ID Client secret Client Secret - Click Test connection to perform a connection test.
- Click Create to establish a connection between Ivanti Neurons and Microsoft Entra admin center for provisioning.
- Once the provisioning is created, click Start provisioning.
Then, click Yes to continue.
After a successful provisioning, you can see the list of groups provisioned to the Ivanti Neurons tenant under the Overview tab.
If a group contains another group (with users), it will not be provisioned. Add the groups separately to provision the users within the group.
For an existing tenant, if users are part of a group being provisioned for SCIM, those users will inherit the group's roles and permissions along with their existing roles.
To assign roles, follow these steps:
- Navigate to Admin > Access Control.
- Go to the Groups tab.
This displays the list of existing and newly added groups.The Member column shows the number of users who have logged in from a group with roles and the number of directly invited members in that group.
The Population column indicates the number of users in that group, irrespective of whether the group has been assigned a role.Ensure you note the following information to interpret the count under the Member column:
A group has a non-zero member count only if the group is assigned a role and the users in that group have logged in.
When a directly invited member (including an unaccepted invite) is a user of a group with roles, they are included in the member count.
- On the Groups tab, you can do the following:
- To assign role-based access control (RBAC): Select the required group, then click Assign Role to Group option, select roles that you want to assign, and click Save.
- To authenticate member login via Ivanti Neurons: Enable the check-box under the Can Authenticate column for a group, and click Save Authentication Settings.
- To deny access to all members in a group: Disable the check-box under the Can Authenticate column for the group.
Once the changes are saved, the users can log in based on:
Users from groups with the Can Authenticate option enabled can authenticate via Ivanti Neurons and log in.
If the group has roles assigned, the Can Authenticate option will be enabled automatically. Users in groups with roles can log in and access Ivanti Neurons with those roles.
If a group has the Can Authenticate option enabled but no roles assigned, users in that group can log in, but their access to Ivanti Neurons content is restricted.
If the group has the Can Authenticate option disabled, users from that group will not have access to Ivanti Neurons.
After users log in with assigned roles, the Members page will list users from groups with roles.