Configure SCIM provisioning in Entra
This procedure explains how to configure System for Cross-domain Identity Management (SCIM) provisioning between Entra and DigiCert® account.
SCIM provisioning allows Entra to automatically create, update, and deactivate users and groups in DigiCert® account. User access is managed through Entra groups and synchronized using the SCIM protocol.
SCIM provisioning and single sign-on (SSO) are configured using separate Entra applications. If you are also using SSO, you must configure the SSO and SCIM applications independently.
Before you begin
To finish this setup, you need administrative access in both DigiCert and Microsoft Entra:
Account admin user group required in DigiCert account.
Application Administrator or equivalent role required in Entra.
Step 1: Enable SCIM provisioning in DigiCert® account
Before configuring Entra, you must enable SCIM provisioning in DigiCert® account and generate the connection details required by Entra.
DigiCert® account で、[アカウント]アイコンから[Sign-in methods]を選択します。
In the User lifecycle section, select Automated user provisioning with SCIM.
In the Enable users and group sync section, switch to enable SCIM provisioning.
Under SCIM base URL, select Copy.
Select Generate token.
Select how long the token should remain valid.
Select Generate token.
Under Token, select Copy.
Select Done.
ヒント
Keep the SCIM base URL and token available. You will use them when configuring SCIM in Entra.
Step 2: Create and configure a SCIM application in Entra
Your SSO application in Entra cannot be used to configure SCIM, you must create a separate application for SCIM:
Sign in to the Microsoft Entra admin center.
In the left pane, select Microsoft Entra ID.
In the left pane of Microsoft Entra ID, select Manage > Enterprise apps.
Select + New application.
Select Create your own application.
In the What's the name of your app? field, enter an app name that specifies SCIM. Example: Example, Inc (SCIM)
Select Create.
Select the Provisioning tab.
Select + New configuration.
In the Select authentication method field, select Bearer authentication.
Complete the following fields:
Tenant URL
Paste the SCIM base URL copied from DigiCert® account in Step 1.4.
Secret token
Paste the token generated in DigiCert® account in Step 1.5.c.
Select Test connection.
Expected message: Connection test for 'app name' was successful.
Select Create.
Step 3: Enable provisioning actions
Once the SCIM application for DigiCert® account is saved, enable the following provisioning actions to allow Entra to manage the full user lifecycle in DigiCert® account.
In the left pane of the SCIM app you just created, select the Provisioning tab.
Select + New configuration.
In the Select authentication method field, select Bearer authentication.
Complete the following fields:
Tenant URL
Paste the SCIM base URL copied from DigiCert® account in Step 1.4.
Secret token
Paste the token generated in DigiCert® account in Step 1.5.c.
Select Test connection.
Expected message: Connection test for 'app name' was successful.
Select Create.
Step 4 : Assign groups to the SCIM application
User access in DigiCert® account is managed using Entra groups.
In the left pane of the SCIM app you just created, select the Users and groups tab.
Select +Add user/group.
Select the Users and groups tab.
Select checkbox next to the groups you want to provision.
Select Select.
Verify that you have selected the correct groups.
Select Assign.
ヒント
If SSO is enabled for DigiCert® account, assign the same user groups to both the SSO application and the SCIM application in Entra to keep access consistent.
Step 5: Start provisioning
To start provisioning:
In the left pane of the SCIM app you just created, select Overview (Preview).
Select Start provisioning.
In the confirmation pop-up, select Yes.
Step 6: Verify provisioning in DigiCert® account
The people and groups you have identified in step 4 should also show in your DigiCert account, provided that the SCIM application in Entra is active.
DigiCert® account で、[アクセス]アイコンを選択します。
Select Users to view a consolidated list of all your users, this includes manually created users and users provisioned through SCIM.
Select Groups to view a consolidated list of groups:
The Source column displays
Platformfor default DigiCert groups.The Source column displays
SCIMfor groups provided by your IdP.
Step 7: Assign roles to groups in DigiCert® account
Users in the IdP group will be assigned the roles that you define in DigiCert account.
注意
If the user was previously assigned user roles manually, these roles will still be present in addition to the roles assigned to the group, unless you manually remove them to prevent breaking existing workflows. See Update user role manually.
In DigiCert® account, select Access ().
Select Groups to assign user roles:
Select the name of a SCIM group.
The Source column displays
SCIMfor groups provided by your IdP.Select Group access.
Select Update group access.
In the Services field, select the checkbox next to all the DigiCert Service this user group should have access to.
In the User roles section of each service, select the check box of the user roles that this user group should have.
Select Assign access.
Review Entra logs
In the left pane of the SCIM app, select Provisioning logs to see activities that Entra did, and information was requested and sent to your DigiCert account: