{"id":6393,"date":"2024-06-10T08:00:37","date_gmt":"2024-06-10T08:00:37","guid":{"rendered":"https:\/\/www.process.st\/help\/docs\/scim-azure-ad\/"},"modified":"2026-01-21T16:57:47","modified_gmt":"2026-01-21T16:57:47","slug":"scim-azure-ad","status":"publish","type":"ht_kb","link":"https:\/\/www.process.st\/help\/docs\/scim-azure-ad\/","title":{"rendered":"SCIM User &#038; Group Provisioning With Microsoft Entra ID"},"content":{"rendered":"<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/fundamentals\/sync-scim\">SCIM<\/a> (System for Cross-Domain Identity Management)\u00a0 allows you to add and remove users or teams of users that you have set up in <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/fundamentals\/sync-scim\">Microsoft Entra ID<\/a> <em>(Previously Azure AD).<\/em><\/p>\n<p>You can securely set up and manage user roles and their access to <a href=\"https:\/\/www.process.st\/\">Process Street<\/a> with SCIM via Microsoft Entra ID.<\/p>\n<p><em><strong>Users: To create an API key you must be an Administrator.<\/strong><\/em><\/p>\n<p><strong><i><em>Note:<\/em><\/i><\/strong><i><em>This feature is only available in our <\/em><\/i><i><em><a href=\"https:\/\/www.process.st\/pricing\/\">Enterprise<\/a>\u00a0plan. Please reach out to your\u00a0Customer Success Manager or our <a href=\"mailto:support@mail.process-street.com\">support<\/a> team if you\u2019re interested in accessing it.<\/em><\/i><\/p>\n<h2>Preparations for this configuration<\/h2>\n<p>For this configuration, you must have SCIM enabled in your Process Street account and an SSO integration that supports SCIM provisioning.<\/p>\n<h2>SCIM Configuration for Microsoft Entra ID<\/h2>\n<p>To set up SCIM user provisioning with Microsoft Entra ID, you first need to configure SCIM for your Microsoft Entra ID account, create application roles and enable provisioning through it.<\/p>\n<h3>Create\/Connect the Process Street SCIM Application<\/h3>\n<p>Log in to your Microsoft Entra ID account and from the menu on the left, click <strong>Applications<\/strong> and select <strong>Enterprise Applications.\u00a0<\/strong><\/p>\n<p>On the <em>Browse Microsoft Entra ID Gallery<\/em>\u00a0page, click <strong>Create your own application. <\/strong>Name this application as <strong>Process Street<\/strong>.<\/p>\n<p>From the options below, choose the option to <em>integrate any other application you don\u2019t find in the gallery<\/em> and click <strong>Create<\/strong>.<\/p>\n<h3>Create Application Roles<\/h3>\n<p>Once the application is created, go to the left menu and click <strong>Applications\u00a0<\/strong>then select <strong>App Registrations<\/strong>. Select the <strong>All Applications<\/strong> tab and select <strong>Process Street<\/strong> (the app you created).<\/p>\n<p>In the app, from the menu on the left, click <strong>App roles<\/strong>. Then click <strong>+ Create app role<\/strong> in the top-center of your screen.<\/p>\n<p>Set the <strong>Display name<\/strong> of this user to <em>Builder<\/em>. <\/p>\n<p>Set <strong>Allowed member types<\/strong> to <em>Users\/Groups<\/em>. <\/p>\n<p>Set the <strong>Value<\/strong> to <em>Builder<\/em> and add a description.<\/p>\n<p>Leave the option to <strong>enable this role<\/strong> as <em>checked<\/em> and click <strong>Apply<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-8074\" src=\"https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300.png\" alt=\"\" width=\"100%\" srcset=\"https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300.png 17008w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300-300x100.png 300w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300-1024x341.png 1024w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300-768x256.png 768w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300-1536x511.png 1536w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/06\/scim300-2048x681.png 2048w\" sizes=\"(max-width: 17008px) 100vw, 17008px\" \/><\/p>\n<p>Repeat the above process for each Process Street user type you want to add. For each user type you add, enter the value as shown below (the case doesn&#8217;t matter so ADMIN, Admin and admin are all equivalent):<\/p>\n<ul>\n<li>Admin<\/li>\n<li>Builder<\/li>\n<li>User<\/li>\n<li>Guest<\/li>\n<\/ul>\n<p><em><strong>Note:<\/strong> If you don&#8217;t enter a user type, your users will be created as <strong>User<\/strong> by default.<\/em><\/p>\n<h3>Enable Provisioning<\/h3>\n<p>Navigate back to Enterprise applications from the left menu, then search and select the app you created, Process Street.<\/p>\n<p>From the app menu on the left, click <strong>Provisioning <\/strong>and click <strong>Get started.<\/strong><\/p>\n<p>Set the <strong>provisioning mode<\/strong> to <em>automatic.<\/em><\/p>\n<p>When prompted to enter the <strong>URL<\/strong>, use https:\/\/public-api.process.st\/api\/scim<\/p>\n<p>For the <strong>secret token<\/strong>, enter the value (not label) of your Process Street API key. If you don&#8217;t have an API key, <a href=\"https:\/\/www.process.st\/help\/docs\/process-street-api\/#generating-an-api-key\">generate<\/a> one first.<\/p>\n<p>Click <strong>Test Connection<\/strong> to verify your details were entered correctly and click <strong>Save<\/strong>, as shown below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-15114 size-full\" src=\"https:\/\/www.process.st\/help\/wp-content\/uploads\/2024\/02\/enable-provisioning.png\" alt=\"\" width=\"1737\" height=\"899\" \/><\/p>\n<h3>Assign users to Process Street<\/h3>\n<p>Go to the app you created, Process Street. From the app menu on the left, click <strong>Users and Groups<\/strong>. Click <strong>+ Add users\/group<\/strong>. Under <strong>Add Assignments<\/strong>, select <em>Users and Groups<\/em>.<\/p>\n<p>Select a <em>user<\/em> to add, select a <em>role <\/em>as their user type, and click <strong>Assign<\/strong> at the bottom.<\/p>\n<h3>Set up provisioning for users<\/h3>\n<p>Go to the app you created, Process Street. From the app menu on the left, click <strong>Provisioning<\/strong>. Switch to the <strong>Provision on Demand <\/strong>tab, select the user you assigned above, and click <strong>Provision<\/strong> at the bottom.<\/p>\n<p>Once done, go to your Process Street organization and go to <strong>Members &amp; Guests<\/strong> in your organization settings to check that the users have been added correctly to your organization.<\/p>\n<h3>Set up groups<\/h3>\n<p>Navigate to the menu on the left and click Groups then select All groups. Click New Group in the top-center of your screen.<\/p>\n<p>Select the <strong>Group type<\/strong> as <em>Security<\/em>, then enter the group name and description. Select the option for <strong>Microsoft Entra ID\u00a0roles can be assigned to the group<\/strong> as <em>No<\/em> and click <strong>Create<\/strong>.<\/p>\n<p>Once your group has been selected, go to <strong>All groups<\/strong> and select your group. In this group, from the left menu, select <strong>Members<\/strong> and click <strong>+Add Members<\/strong> in the top-center of your screen.<\/p>\n<p>Search and select the members you want to add to this group.<\/p>\n<h3>Assign members to groups<\/h3>\n<p>Go to <strong>Enterprise Applications<\/strong> then search and select the app you created, Process Street.<\/p>\n<p>From the app menu on the left, click <strong>Users and groups<\/strong> then select <strong>+Add\/Group<\/strong> in the top-center of your screen.<\/p>\n<p>Under <strong>Users and groups<\/strong>, select the group you created, select the roles, and click <strong>Assign<\/strong>.<\/p>\n<h3>Set up provisioning for groups<\/h3>\n<p>Go to the app you created, Process Street. From the app menu on the left, click <strong>Provisioning<\/strong>. Switch to the <strong>Provision on Demand <\/strong>tab, and select the group you created above.<\/p>\n<p>Select Members only, then choose all the members you added to this group, and click <strong>Provision<\/strong> at the bottom.<\/p>\n<p>Once done, go to your Process Street organization and go to <strong>Members &amp; Guests<\/strong> in your organization settings to check that the users have been added correctly to your organization. Go to <strong>Groups<\/strong> to check that the group has been added as well.<\/p>\n<h2>FAQ<\/h2>\n<p><em><strong>What happens if I add a group of users from Microsoft Entra ID?<br \/>\n<\/strong><\/em>All users in that group will be added to Process Street with the user role you have selected for that group.<\/p>\n<p><em><strong>Do I need our domain set up in Process Street to enable SCIM?<br \/>\n<\/strong><\/em>Yes, to add your domain(s) into Process Street please reach out to our support team who can set this up for you.<\/p>\n<p><em><strong>Can I change a user&#8217;s email address via SCIM?<br \/>\n<\/strong><\/em>Yes but only if you have a domain set up in Process Street (see above).<\/p>\n<p><em><strong>Can I change a user&#8217;s password via SCIM?<br \/>\n<\/strong><\/em>No, only a user can update their own password.<br \/>\n<strong>Note:<\/strong> SCIM works best with SSO which allows you to control passwords.<\/p>\n<p><em><strong>What if a user is part of more than one organization\u00a0in Process Street, can I change their email address?<br \/>\n<\/strong><\/em>It&#8217;s only possible to change the email addresses that have the same domain as your organization&#8217;s domain.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SCIM (System for Cross-Domain Identity Management)\u00a0 allows you to add and remove users or teams of users that you have set up in Microsoft Entra ID (Previously Azure AD). You can securely set up and manage user roles and their access to Process Street with SCIM via Microsoft Entra ID. Users: To create an API [&hellip;]<\/p>\n","protected":false},"author":11,"template":"","meta":{"_acf_changed":false,"available_plan":"Enterprise","available_product":"Settings","footnotes":""},"ht_kb_category":[239],"ht_kb_tag":[204,458],"class_list":["post-6393","ht_kb","type-ht_kb","status-publish","hentry","ht_kb_category-security","ht_kb_tag-organization-management","ht_kb_tag-user-management"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/6393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb"}],"about":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/users\/11"}],"version-history":[{"count":19,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/6393\/revisions"}],"predecessor-version":[{"id":9557,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/6393\/revisions\/9557"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/media?parent=6393"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_category?post=6393"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_tag?post=6393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}