SCIM with Microsoft Entra
Create API Key in Vertesia
Create an API Key in Vertesia.
- Go to "Settings" → "API Keys"
- Name:
Microsoft Entra - Role:
admin(required)
Create App in Microsoft Entra
Create an “Enterprise Application” in Microsoft Entra:
- Select "New application"
- Select "Create your own application" from Microsoft Entra Gallery
- Name the app e.g. "Vertesia"
- Select "Integrate any other application you don't find in the gallery (Non-gallery)"
Add user/groups:→
- Go to "Users and groups" → "Add user/group"
Provision User and Groups
Provisioning
- Go to "Manage" → "Provisioning" → "New configuration"
- Tenant URL: https://api.vertesia.io/api/v1/iam/scim/v2/
- Token:
VERTESIA_API_KEY
Provision on demand or as a job
- "Get Started" → "Map attributes (optional) or "Manage" → "Attribute mapping"
- Remove all except below for users
- Consider disabling delete
- Remove all except below for groups
- "Provision on demand" or "Start provisioning"
After users are provisioned as Vertesia org and group members, the group can be:
- assigned a role on a project
- assigned to an application
Additional Information
- Use the consumer role for custom apps with end users.
- Existing non-SCIM users provisioned through SCIM will be updated to SCIM users.
- User org role will be set to member.
Avoid lockout: org owner/admin users converted to SCIM users become org memebers. Ensure there is more than one org admin before running a SCIM sync**.
Troubleshooting in Micrsoft Entra
Access the SCIM log in Microsoft Entra:
- Go to “Monitor” → “Provisioning logs”
- Go to “Monitor” → “Audit logs”
