---
title: Set up SCIM provisioning with Microsoft Entra ID
description: SCIM
---

[Skip to content](https://support.iventis.com/set-up-scim-provisioning-with-microsoft-entra-id#main-content)

English

Show submenu for translations

[Contact us](https://support.iventis.com/kb-tickets/new?hsLang=en) [Customer portal](https://customer-portal.iventis.com/tickets-view?hsLang=en)

![Iventis\_Pos\_CMYK-1.jpg\]](https://support.iventis.com/hs-fs/hubfs/Iventis_Pos_CMYK-1.jpg?height=50&name=Iventis_Pos_CMYK-1.jpg)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact us](https://support.iventis.com/kb-tickets/new)
- [Customer portal](https://customer-portal.iventis.com/tickets-view)
- Go to www.iventis.com

 Go to www.iventis.com

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.iventis.com/?hsLang=en)
2. [Account & Billing](https://support.iventis.com/account-billing?hsLang=en)

# Set up SCIM provisioning with Microsoft Entra ID

## SCIM provisioning lets Microsoft Entra ID add, update and remove people in your Iventis project automatically, based on who is assigned to the Iventis app in Entra.

### Before you begin

You need all of the following before starting:

- **SCIM on your plan**: SCIM is only available to customers who have opted for self-hosting of Iventis.
- **Single sign-on already working**: SSO must be set up and enabled on the project first, because every user SCIM provisions signs in through SSO. See *Set up OpenID Connect single sign-on with Microsoft Entra ID*.
- **An Iventis project administrator** to enable SCIM and generate the token.
- **A Microsoft Entra administrator** with at least the **Application Administrator** role, to configure provisioning on the Iventis enterprise app.

### Step 1: Enable SCIM and generate a token in Iventis

1. In Iventis, open **Project settings** and select **SCIM**.

![](https://support.iventis.com/hs-fs/hubfs/image-png-Oct-06-2026-10-33-34-9859-AM.png?width=213&height=555&name=image-png-Oct-06-2026-10-33-34-9859-AM.png)

1. Copy the **Tenant URL** shown at the top of the page. It has the form `https://<your-project>.<iventis-domain>/permissions/scim/v2`.
2. Select **Generate token**, then **Copy token**. The token is shown once only, so paste it somewhere safe until Step 2 is done.
3. Turn on **SCIM enabled** and confirm.

![](https://support.iventis.com/hs-fs/hubfs/image-png-Oct-06-2026-10-35-40-9848-AM.png?width=629&height=250&name=image-png-Oct-06-2026-10-35-40-9848-AM.png)

If **SCIM enabled** cannot be switched on, single sign-on is not yet enabled for the project. Set up SSO first.

After SCIM is enabled, people it provisions can only be added, updated and removed in Entra, not in Iventis.

### Step 2: Connect provisioning in Microsoft Entra ID

Provisioning needs its own enterprise application. Entra does not support automatic provisioning on the app registration used for OpenID Connect sign-in, so create a second app for SCIM ([Microsoft's known issues](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/known-issues)).

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
2. Go to **Entra ID** \> **Enterprise apps** and select **New application** \> **Create your own application**. Name it, for example *Iventis provisioning*, choose **Integrate any other application you don't find in the gallery (Non-gallery)**, and select **Create**.
3. In the new app, select **Provisioning**, then **New configuration** (or **Get started**).
4. Set **Provisioning mode** to **Automatic**.
5. Under **Admin credentials**, enter: 
     - **Tenant URL**: the Tenant URL from Step 1
     - **Secret token**: the token from Step 1
6. Select **Test connection**. A success message confirms Entra can reach Iventis.
7. Select **Save**.

Do not turn provisioning on yet. Configure the attribute mappings first, because changing them later makes Entra re-evaluate every user.

 

### Step 3: Configure attribute mappings

Two of Entra's default mappings must be changed: **externalId** must come from **objectId** and be the matching attribute, and **userName** must come from the expression `Coalesce([mail], [userPrincipalName])`.

Iventis needs an email address for every user because sign-in starts with the user typing their email address, which Iventis uses to find their project. The expression uses the user's mail address, and falls back to their user principal name for users without a mailbox, which is what they sign in to Microsoft with.

1. On the **Provisioning** page, expand **Mappings** and select **Provision Microsoft Entra ID Users**.
2. Edit the **externalId** row (select its pencil icon): 
     - **Mapping type**: Direct
     - **Source attribute**: `objectId`
     - **Match objects using this attribute**: Yes
     - **Matching precedence**: 1
     - **Apply this mapping**: Always
3. Edit the **userName** row: 
     - **Mapping type**: Expression
     - **Expression**: `Coalesce([mail], [userPrincipalName])`
     - **Match objects using this attribute**: No
     - **Apply this mapping**: Always
4. Check that no other row has **Match objects using this attribute** set to Yes.
5. Select **Save**.
6. Go back to **Mappings**, select **Provision Microsoft Entra ID Groups**, set **Enabled** to **No**, and select **Save**. Iventis does not provision groups.

The mappings Iventis uses:

| Iventis attribute | Entra source attribute | Matching |
| --- | --- | --- |
| `externalId` | `objectId` | Yes, precedence 1 |
| `userName` | `Coalesce([mail], [userPrincipalName])` (expression) | No |
| `emails[type eq "work"].value` | `mail` | No |
| `name.givenName` | `givenName` | No |
| `name.familyName` | `surname` | No |
| `active` | `IsSoftDeleted` (default) | No |

Leave **emails** mapped directly from `mail`. For a user without a mailbox Entra sends no email, and Iventis uses userName instead. The other default mappings, such as `displayName` and `title`, can stay. Iventis ignores attributes it does not use.

 

### Step 4: Test with one user, then turn provisioning on

1. In the provisioning app, select **Users and groups** and assign the people or groups who should have access to the Iventis project. If your sign-in app requires assignment, assign the same people or groups there too, or they will be provisioned but unable to sign in.
2. On the **Provisioning** page, under **Settings**, set **Scope** to **Sync only assigned users and groups**.
3. Select **Provision on demand**, choose one assigned user, and select **Provision**. Check that every step succeeds, then confirm the user appears in the Iventis project within the People's section. The user with a shield icon indicates the user was provisioned by SCIM's.

![](https://support.iventis.com/hs-fs/hubfs/image-png-Oct-06-2026-10-49-34-7660-AM.png?width=642&height=182&name=image-png-Oct-06-2026-10-49-34-7660-AM.png)

      4. Set **Provisioning Status** to **On** and select **Save**.

Entra then provisions everyone assigned. The first cycle can take some time for large tenants, and later changes are picked up roughly every 40 minutes.

### Managing the token

The SCIM page in Iventis shows the last four characters of the current token and when it was created.

- **To replace the token**, select **Regenerate token** in Iventis, then paste the new token into **Secret token** on the Entra **Provisioning** page and select **Save**. The old token stops working immediately, so provisioning fails until Entra has the new one.
- **To stop provisioning straight away**, select **Revoke token**. Entra's requests are rejected until a new token is generated and entered.

Replace the token if it may have been exposed, and when the administrator who set it up leaves.

- [Getting started](https://support.iventis.com/getting-started?hsLang=en)
- [Using Iventis](https://support.iventis.com/using-iventis?hsLang=en#main-content)

    - [Create: How to build an event site or operational plan](https://support.iventis.com/using-iventis?hsLang=en#create-how-to-build-an-event-site-or-operational-plan)
    - [Share: How to share your event site and venue plans](https://support.iventis.com/using-iventis?hsLang=en#share-how-to-share-your-event-site-and-venue-plans)
    - [Analysis: How to analyse costs, bill of quantities, and more!](https://support.iventis.com/using-iventis?hsLang=en#analysis-how-to-analyse-costs-bill-of-quantities-and-more)
    - [3D Line Models](https://support.iventis.com/using-iventis?hsLang=en#3d-line-models)
    - [Digital Twin](https://support.iventis.com/using-iventis?hsLang=en#digital-twin)
- [Account & Billing](https://support.iventis.com/account-billing?hsLang=en)
- [Tips & Tricks](https://support.iventis.com/tips-tricks?hsLang=en)
- [FAQs](https://support.iventis.com/faqs?hsLang=en#main-content)

    - [Permissions](https://support.iventis.com/faqs?hsLang=en#permissions)

# Iventis

Tel: + 44 (0) 203 443 9030

<https://www.linkedin.com/company/iventis-ltd/> <https://twitter.com/IventisSoftware> <https://www.instagram.com/iventis_software/> <https://www.facebook.com/iventis.software>

Copyright © 2026, Iventis