Set up SCIM with Microsoft Entra ID
Step-by-step Entra ID provisioning setup for Joring, including group provisioning and roles on synced groups.
This walkthrough connects Microsoft Entra ID (formerly Azure AD) provisioning to Joring. You need Entra admin access and the Base URL and a bearer token from Settings → SCIM in Joring (see SCIM provisioning).
1. Create the enterprise application
- In the Microsoft Entra admin center, go to Identity → Applications → Enterprise applications and select your existing Joring app, or create one with New application → Create your own application (non-gallery).
- Open the app's Provisioning page and select New configuration.
2. Point Entra at Joring
| Entra field | Value |
|---|---|
| Provisioning Mode | Automatic |
| Tenant URL | Your Joring Base URL (https://api.joring.ai/scim/v2/{connection_id}) |
| Secret Token | Your jor_scim_ token |
Click Test Connection. Entra queries the endpoint and validates the credentials. Then click Create to save the configuration.
3. Review attribute mappings
The default mappings work with Joring. The ones that matter:
| Entra attribute | SCIM attribute |
|---|---|
userPrincipalName | userName |
objectId | externalId |
mail (or userPrincipalName) | emails[type eq "work"].value |
givenName / surname | name.givenName / name.familyName |
Switch([IsSoftDeleted], , "False", "True", "True", "False") | active |
Enterprise extension attributes such as department and employeeNumber are
accepted and stored. The enterprise manager attribute additionally builds
the reporting chart — see
reporting lines from your directory.
You can remove mappings Joring does not use, or leave them in place; unused
attributes are stored and echoed back.
4. Assign users and groups
- Under Users and groups, assign the people or groups who should have Joring accounts.
- Set Provisioning Status to On. Entra provisions on a roughly 40-minute interval; use Provision on demand to push a single user immediately while testing.
- Assigned groups are created in Joring with their membership and appear under People → Groups, marked as synced from Entra. If a group managed in Joring already has the same name, the push takes it over: Entra's membership replaces the group's members, and the group keeps its description, roles, and managers. See link by name.
5. Assign roles on the groups (optional)
In Joring, open People → Groups, open a provisioned group, and assign roles on it. From then on, group membership in Entra grants and removes those roles on each sync cycle. See roles through groups.
Verify
- Use Provision on demand for a test user and confirm they appear in Settings → SCIM → Directory as Active.
- Soft-delete or unassign the user; the next cycle deactivates them in Joring, freeing their seat and ending their sessions.
- Permanently deleting the user sends a SCIM delete; the record disappears from the Directory tab while their Joring account and data are retained.
Sync timing
Entra runs provisioning on a fixed cycle rather than instantly. If a change has not appeared, check the provisioning logs in Entra before debugging on the Joring side. Provision on demand pushes a single user immediately.
Capability reference, lifecycle behavior, and troubleshooting.