Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SCIM Source with Microsoft Azure AD/Entra ID #9682

Open
Gunsmithy opened this issue May 10, 2024 · 1 comment
Open

SCIM Source with Microsoft Azure AD/Entra ID #9682

Gunsmithy opened this issue May 10, 2024 · 1 comment
Labels
question Further information is requested

Comments

@Gunsmithy
Copy link
Contributor

Describe your question/
Hi there,

I want to set up SCIM between Entra ID and my authentik instance. The limited SCIM Source documentation suggests this should be supported, but I don't know how.

When I click on "Provisioning" on my Enterprise Application in Azure I already configured successfully as an OAuth Source, I get the following message that can be seen in screenshots below.

It seems like, at least with this flow in the Azure console, it is expected that the application is a SaaS app from their gallery that you must register: https://learn.microsoft.com/en-us/entra/identity/saas-apps/tutorial-list

However, based on their docs, it seems like any "Applications that support SCIM 2.0" should work: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/user-provisioning#what-applications-and-systems-can-i-use-with-microsoft-entra-automatic-user-provisioning

If this should work, even in technical preview, some basic instructions would be nice so I can serve as a tester!

Relevant info
I manage a small Entra deployment I can use for testing before integration with my organization in production.
Happy to go back and forth on this!

Screenshots
image

Logs
N/A

Version and Deployment (please complete the following information):

  • authentik version: 2024.4.2
  • Deployment: helm

Additional context
N/A

@Gunsmithy Gunsmithy added the question Further information is requested label May 10, 2024
@rknightion
Copy link

When doing an app registration for Authentik I was able to create a provisioning config by manually creating an additional -scim app in Enterprise Applications (Entra seems to somewhat limit oauth app registrations from having automatic provisioning eligibility).
Admittedly I have larger issues with users from scim being matched against their user account in authentik post scim setup but that's a different issue I think

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants